Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [
"backend",
"comments",
"community",
"drizzle-orm",
"moderation",
"nodejs",
"open-source",
"pgvector",
"postgres",
"realtime",
"replyke",
"self-hosted",
"semantic-search",
"social-network",
"socketio",
"supabase",
"typescript",
"replyke-sdk",
"replyke-server",
"sublay"
],
"is_fork": false,
"size_kb": 6269,
"has_wiki": true,
"homepage": "https://demo.agora-oss.org",
"languages": {
"CSS": 1728,
"HTML": 806,
"Shell": 11404,
"Python": 181778,
"PLpgSQL": 78532,
"Dockerfile": 9610,
"JavaScript": 247642,
"TypeScript": 2181533
},
"pushed_at": "2026-07-21T09:32:13Z",
"created_at": "2026-05-23T01:41:21Z",
"owner_type": "Organization",
"updated_at": "2026-07-21T09:32:58Z",
"description": "Self-hosted open-source backend for community & social apps (posts, comments, reactions, follows, spaces, realtime chat, semantic search). API-compatible with the Replyke SDK. Built on Supabase.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "AGPL-3.0",
"default_branch": "root",
"license_spdx_raw": "AGPL-3.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": "Agora OSS Org",
"type": "Organization",
"login": "agora-oss-org",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/296750678?v=4",
"created_at": "2026-06-25T03:22:31Z",
"is_verified": null,
"public_repos": 5,
"account_age_days": 30
},
"license": {
"state": "standard",
"spdx_id": "AGPL-3.0",
"raw_spdx": "AGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.22.0",
"kind": "minor",
"published_at": "2026-07-19T06:04:45Z"
},
{
"tag": "v0.21.0",
"kind": "minor",
"published_at": "2026-07-18T04:31:02Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2026-07-18T02:21:31Z"
},
{
"tag": "v0.19.0",
"kind": "minor",
"published_at": "2026-07-08T03:12:18Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2026-07-07T06:45:08Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2026-07-05T11:12:32Z"
},
{
"tag": "v0.16.5",
"kind": "patch",
"published_at": "2026-07-04T11:06:32Z"
},
{
"tag": "v0.16.4",
"kind": "patch",
"published_at": "2026-07-04T05:37:09Z"
},
{
"tag": "v0.16.3",
"kind": "patch",
"published_at": "2026-07-03T08:42:19Z"
},
{
"tag": "v0.16.2",
"kind": "patch",
"published_at": "2026-07-03T02:24:51Z"
},
{
"tag": "v0.16.1",
"kind": "patch",
"published_at": "2026-07-03T01:26:15Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-07-02T02:34:59Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-06-16T18:44:09Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-06-08T08:16:22Z"
},
{
"tag": "v0.9.2",
"kind": "patch",
"published_at": "2026-06-08T08:22:20Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-06-07T02:32:19Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-06-07T00:58:47Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-06-05T07:21:56Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-06-03T08:15:54Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-05-31T08:59:26Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-05-31T05:27:22Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-06-07T01:07:52Z"
},
{
"tag": "v0.2.3",
"kind": "patch",
"published_at": "2026-05-28T04:09:31Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-05-28T01:20:58Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-05-27T05:33:38Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-05-24T09:02:26Z"
}
],
"recent_commits": [
{
"oid": "9ceb3fe8edb50190e2ebfe988f07bfbe6aa3230a",
"body": null,
"is_bot": false,
"headline": "cheat-sheet",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T09:32:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97a4397590accd5e14e9b4891b162a35a7bed3bc",
"body": "Events (migration 0053) had been invisible to every search surface since\nthey shipped: nothing embedded an event, and match_content had no branch\nthat could return one. Adds \"event\" as a fourth source type.\n\nEvents embed on create and re-embed on update (title, description, venue\nname, address — ven\n[…]\nunit.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_011DQQwcpFWHJWyQEdmfTCgP\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "✨ feat(search): make events searchable via /search/content",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T09:31:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "759b614cd1b6036bd62be2c0c47be703322a17f8",
"body": "Propagate the widened seam into every mirror, and correct the claims the\nfirst pass made that this change falsifies.\n\n- apps/admin/README.md: full table of all eight keys with the type each is\n validated as, the boolean spellings, and two subsections on the settings\n that look like security contro\n[…]\nat runtime\" and framed the VITE_* flags as\nruntime-unreachable. Both were true when written and are now wrong — every\nadmin setting is runtime-resolved.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "📝 docs: document the AGORA_ADMIN_* runtime settings",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T04:37:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d46120d7217660e4d5441d9e13f7d44094b006e5",
"body": "Wire the container side of the admin's fully runtime-resolved config, so a\npulled image can be retargeted without a rebuild.\n\n- Emit all seven new keys from the proxy entrypoint alongside publicAppUrl;\n each is optional, and an unset var is omitted so the SPA keeps its\n build-time default\n- Relay \n[…]\n comments that this makes false: the build args are\nnow only DEFAULTS, not the sole way to set these, and the admin SPA does\nhave a runtime config seam.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "🚀 deploy(proxy): relay the AGORA_ADMIN_* settings into /config.js",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T04:37:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "25c60fd11e99bf86582317a1cb0e64d63b832b1f",
"body": "The seam landed with one key; move the rest of the admin's config onto it\nso a PULLED agora-proxy image has no build-time-only setting left. One\npublished image can now serve a different project, API origin, or feature\nset with no rebuild.\n\nMigrated: projectId, apiBaseUrl, moderatorBaseUrl, socialGr\n[…]\nuard, NOT a boundary. It disables Save\n controls but the API still authorizes by token. Real enforcement is the\n server's OPERATOR_RO_EMAILS allowlist\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "✨ feat(admin): resolve every setting through the runtime config seam",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T04:37:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a7f922237e03df21b192268d20dbe3f830b75ca4",
"body": "Propagate the new runtime setting into every mirror the propagation map\nflags for a deploy-surface change, so an operator can discover it from\nwhichever entry point they start at:\n\n- apps/admin/README.md: new \"Runtime configuration\" section with the\n precedence rule, the env-to-key table, the retar\n[…]\n seam\n\nEach spells out why it matters: unset, the admin's \"Open in app\" links\npoint at the local demo dev server, which is wrong on any real deployment.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "📝 docs: document AGORA_PUBLIC_APP_URL and the /config.js seam",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T02:26:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0e98975504364a14e654d53f28116028481d061c",
"body": "Wire the setting the admin's new /config.js seam consumes, so the \"Open in\napp\" deep links land on a deployment's real community front end instead of\nthe local demo dev server they silently defaulted to.\n\nAGORA_PUBLIC_APP_URL was reachable from nowhere before this: it lived only\nas VITE_DEMO_URL ins\n[…]\n proxy\n\nNote it is inert in docker-compose.dev.yml, where the admin is served from\nthe host vite server; host-side dev uses VITE_PUBLIC_APP_URL instead.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "🚀 deploy(proxy): relay AGORA_PUBLIC_APP_URL into the admin at runtime",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T02:26:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a34735487de9584a3ce08fc834a528999071d42",
"body": "The admin SPA is a static Vite build baked into the agora-proxy image, so\nevery VITE_* var is inlined at BUILD time. A deployment that PULLS the\npublished image (docker-compose.prod.yml) could never change them, which\nleft the \"Open in app\" deep links on reports, AI flags, and steward cases\npermanen\n[…]\n existing builds are unaffected\n\nFirst key is publicAppUrl, fed by AGORA_PUBLIC_APP_URL (wired up in the\nproxy image and compose in a following commit).\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
"is_bot": false,
"headline": "✨ feat(admin): add /config.js runtime config seam and PUBLIC_APP_URL",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-21T02:26:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5fcb1bd2b4a8f93606fc23cb018f6d50f3dc7902",
"body": null,
"is_bot": false,
"headline": "chore(release): v0.22.0",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T06:04:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bec1b0b09f0d9da6dce9146e6be2896695e126d",
"body": "04-seed-homepage-comments now rewrites the anchor's copy to explain the\nmechanism to both its audiences — a signed-out homepage visitor reading the\nthread, and an operator finding it in the admin panel as an ordinary entity.\nThe seeded thread follows suit, discussing how the surface works rather tha\n[…]\no it\nworks regardless of env config. Only if both fail does it warn and leave the\nanchor unpublished rather than failing the seed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(seeds): self-explaining public anchor + two-route publish authority",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T06:02:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c9b1c380366b9d0821ee3d8d600b14f0c42e279d",
"body": "…rface guide\n\nThree strands of the same thread — making the internet-public surface actually\nusable by an embed — landed together because their CHANGELOG entries interleave.\n\n1. GET /v7/:projectId/public/entities/by-foreign-id\n\nThe anonymous mirror of the walled by-foreign-id lookup, so an embed can\n[…]\nolicy matching the uuid route. Full suites green (576 unit, 619\nintegration).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(public): anonymous by-foreign-id lookup, seed coverage, and a su…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T04:27:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "76f135e5eff683a7136fc844ca70c9ed3f621224",
"body": "…ated\n\n/public/* exists to be embedded by third-party sites, but shipped uncacheable,\nso every embed impression hit the origin.\n\nSuccess responses now carry `public, max-age=0, s-maxage=300, must-revalidate`\nplus an ETag (lib/public-cache.ts); a matching If-None-Match returns a bodyless\n304. Orderin\n[…]\naking onto the walled\nsurface. Full suites green (576 unit, 611 integration).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "perf(public): make the anonymous surface CDN-cacheable + ETag-revalid…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T03:25:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bf8afea4f2f29f20a37b45ed1ffc623ce252e58b",
"body": "The internet-public-entities work landed migration 0065_entity_internet_public,\nso both parked plans' 0065 targets are stale.\n\nRenumber space-scoped-stewards and store-phase1 to 0066 throughout (file paths,\njournal entries, DDL headers, git commands, and the store plan's journal-append\nscript). Both\n[…]\nmes doesn't have to hunt for it.\n\nDocs only — neither plan has been executed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "📝 docs(plans): renumber parked migrations to 0066 (0065 is taken)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T03:24:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "14b7bc953200cd5dc10f13f147d081b93bc29870",
"body": "…ic/* read surface\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: internet-public entities — visibility ladder + anonymous /publ…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T01:40:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "01d944271c085dd07edf8dea9a8ffc5471e2224c",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix(api): redact anonymous user PII on the public comment routes too",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T01:34:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc65dc864c8afb555b08ddccf9cab154d1957fbc",
"body": "…ty route\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix(api): final-review hardening for the /public/* surface + visibili…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T01:24:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eb36105bbd4cedb61451a33493c6b8e5fd199f41",
"body": "…gelog)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs: internet-public entities contract (§public, Entity.public, chan…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:57:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a704c260cc8155d89ba5801823b1ffa50c7f933e",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(api): anonymous /public/* internet-public read surface",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:42:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b67fc571b1872f8731ba0a0a330b01bdd70035b",
"body": "… ladder)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(api): privileged PATCH /entities/:id/visibility (internet-public…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:27:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52ce0bf824140f5912f5b441911abab4ced8eb26",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(api): internet-public ladder gate (lib/public-access)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:18:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0192357af2bda57181bbf28a9cb67e6f142febab",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(contract): Entity.public field + entityVisibilitySchema",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:13:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4836a3af4c526298e57cf075ecceeeb71714b762",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(db): entities.is_public internet-visibility flag (0065)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:06:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3d56dd9985acea1789018f605693ebc54ca299e",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs: internet-public entities spec + implementation plan",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-19T00:04:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02925ff71981b6378de0ddfbddfca0f1879ec119",
"body": "The admin login's one-click \"Log in as admin\" button is gated on\nVITE_DEMO_EMAIL + VITE_DEMO_PASSWORD, inlined at `vite build` time (the\nadmin SPA has no runtime config seam). The proxy Dockerfile never declared\nthese ARGs and the deploy workflow never passed them, so production builds\nbaked them em\n[…]\nred\nas a Secret (so it silently resolved empty) — source it from secrets too.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "ci(admin): bake demo operator credentials into the admin build",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T07:42:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4a8e184b257b4735595a83eabf0098f741ebc9ad",
"body": "Rework the admin LoginPage to match the demo login: a welcome blurb, an\n\"or\" divider, and a one-click \"🛠️ Log in as admin\" button that signs in\nwith the seeded operator credentials. Drop the credential prefill (the\none-click button covers it now, so the form is unambiguously \"your own\naccount\"). No \n[…]\no\nreal deployments that leave those unset see only the ordinary sign-in form.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(admin): restyle login to mirror the demo screen",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T06:58:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "adfc55cacce9a95d0d4344690ad4b9879bdf0d39",
"body": "…designs)",
"is_bot": false,
"headline": "merge: store marketplace spec + phase 1 plan + ROADMAP index (parked …",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T06:09:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "39075de6682f8117692a1e2d106bcf0b79a3466e",
"body": "Introduce the living roadmap and index the two parked initiatives:\n\n- ROADMAP.md (repo root): pointers + status only — ready-to-execute\n spec+plan pairs (space-scoped stewards, store Phase 1), committed\n follow-ons (store Phase 2, store admin-SPA/SDK surfaces, stewardship\n Watch, secure-chat diag\n[…]\n landing\n\nNothing here changes runtime behavior; both initiatives await a future\nexecution session.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "📝 docs: add ROADMAP index, space-scoped-stewards plan, changelog entry",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T05:45:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab76ccaffe847cff911b557a1c1b83282372877b",
"body": "Executable TDD plan for the approved marketplace spec's Phase 1\n(coins + digital cosmetics), parked for a later session:\n\n- 13 tasks: contract types/zod, core schema, migration 0065 (ledger\n trigger + serialized purchase/gift/earn/stipend SQL fns), settings,\n shapers, store router, purchase/equip/\n[…]\nase 2 (Stripe + merch), and SDK/demo surfaces are\n explicitly out of scope (tracked in ROADMAP.md)\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "📝 docs(store): store Phase 1 implementation plan",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T05:45:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46c2dcabd8445f9c8c640043b82144375de5d14c",
"body": "…ed merch)\n\nApproved brainstorm output: per-project store domain (Approach A — in-core\nrouter + append-only coin ledger), Phase 1 digital cosmetics / Phase 2\nStripe + fulfilled merch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01G5F4pcgLie2XF5HS9rzp2w\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs(store): marketplace design spec (coins + digital cosmetics, phas…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T04:57:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "605c0ba8e25ffd1c358d3e908dfb3089e78fdc6a",
"body": null,
"is_bot": false,
"headline": "chore(release): v0.21.0",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T04:27:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "300792063f21fadf46038b1ac1c2afd1af39bb8a",
"body": "Resolve the admin email+password once (shared resolve-admin-creds.mjs) and\npropagate via child env so a typed password reaches every post-seeder.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_0176Aqcz3FiTyL2cDrLWzzZA",
"is_bot": false,
"headline": "merge: seed admin-credential propagation to post-seeders",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T04:25:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "16c00e90c7edbd867812d62ac9e6dc4ff96e88cf",
"body": null,
"is_bot": false,
"headline": "Seed: a custom admin password now propagates to the post-seeders.",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T04:24:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8af30553979bb7821b6ff615ce7d78ed54c2c77e",
"body": null,
"is_bot": false,
"headline": "spec",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T04:23:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "537c175056dc2e69120ecec6ce83209064e711ee",
"body": "PATCH /admin/social/read-receipts/spaces/:spaceId mutates settings\n(spaces.readReceiptsEnabled) but lacked assertSettingsWritable, so a\nsettings-read-only principal holding the operator claim could flip it.\nAdd the guard after the operator check; it now 403s settings/read-only\nlike the other five se\n[…]\nd the scope/handler\ncomments were updated to match. No behavior change there.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix(settings): gate read-receipts toggle behind settings-read-only cap",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T03:16:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "aec88c05bd45d04cee5c376f9c6c3f1923e25427",
"body": null,
"is_bot": false,
"headline": "agora admin rename",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T03:03:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c8e7543819754055eb490d0752b5030efeced7a8",
"body": null,
"is_bot": false,
"headline": "chore(release): v0.20.0",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T02:20:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8a6101d363d49af439498d452826b832811012c",
"body": "Adds SETTINGS_READONLY_EMAILS — a shared demo login (demo-admin@agora-oss.org) gets\nthe full operator view but is server-blocked (403 settings/read-only) from the five\nsettings-save endpoints (PATCH /settings/feed|moderator|steward|social, /webhooks/config).\nNon-destructive actions and ordinary memb\n[…]\n each reviewed clean; whole-branch review (Opus) verified no bypass path,\nclaim on every mint path, fail-closed, correctly scoped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: settings-read-only demo operator + default admin email rename",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T02:17:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "91927b885e86d9642d6e05d6843c58d62a2aa6c9",
"body": "…ngsReadonly in token JSDoc (review follow-up)",
"is_bot": false,
"headline": "test(settings): valid steward notifyPolicy for a true 200; note setti…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T02:04:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd6fa7bbbfbba7e9dabcb50d0b6249edda393bcd",
"body": "… admin email",
"is_bot": false,
"headline": "chore(demo): enable settings-read-only demo operator + rename default…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T01:52:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a2344dfe6c57b62f0805f3a51752edd9b0831342",
"body": "… endpoints",
"is_bot": false,
"headline": "feat(settings): block settings-read-only principal from the five save…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T01:37:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0270c341340d3cb66d5ec6aba84e21f6e525020",
"body": null,
"is_bot": false,
"headline": "feat(auth): settingsReadonly allowlist → JWT claim → c.var.auth pipeline",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T01:23:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d2c02de3a4a8ebe3c4863a04add9896b3001977",
"body": null,
"is_bot": false,
"headline": "docs: demo read-only admin — spec + implementation plan",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-18T01:17:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "606b7b953449f1044c7d8d0558f266988994f3c7",
"body": "Every /v7/:projectId/* request now requires an authenticated account. authWall\n(packages/core) replaces optionalAuth at the project-group mount; AUTH_WALL_ALLOWLIST\nis the API's entire anonymous surface. Migration 0064 revokes the 0008 anon\npublic-read RLS so the DB states the same posture. Tokens are bound to their project\nat the wall. Ships in 0.20.0.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: auth wall — private by default (BREAKING)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T09:21:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2ca3a1e4c919d3e05a2507cefab0ebf28aade7a4",
"body": "…lock skew\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix(auth): bind tokens to their project at the wall; fix suspension c…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T09:10:58Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4654707c7e680b156f13d9504631f943894f461f",
"body": null,
"is_bot": false,
"headline": "PENTEST.md",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T08:34:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8b7b364441b4346be3f9d2f59d1c71a8c241b11",
"body": "…wrap SECURITY bullet\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "test(api): pin STORAGE_PROVIDER in the integration hermetic block; re…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T08:33:48Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8aae1110a45988c47583b57bbf4a6d27ec5a3732",
"body": "\"Ships in the next MAJOR version.\" was written while the entry sat under\n[Unreleased]. Stamped into a dated 0.20.0 section it reads as \"not this\nrelease\" — the opposite of the truth. Pre-1.0 the minor bump is the\nbreaking vehicle (SemVer §4), so say so plainly.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): the auth wall lands in 0.20.0, not a later major",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T08:13:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "905fab654e2374720f91b59617ed9ad17da49beb",
"body": "…rences\n\nDocument demo-admin@agora-oss.org / DemoAdmin123! alongside the existing\nagora-admin@gmail.com login, since the two come from different layers and are\neasy to confuse:\n\n • agora-admin@gmail.com — 00-seed-auth-admin, ALWAYS seeded (runs before the\n gate), privileged only if added to OPE\n[…]\nSWORD compose defaults),\nwhich should keep pointing at the always-seeded account rather than one that\nonly exists behind the gate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(seed): document the two seeded admins; fix stale seed:graph refe…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T07:58:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ef3b4ce35ddaa77d164c50d7a5ac9ebe006a49ea",
"body": "Declare demo-admin@agora-oss.org (DemoAdmin123!) in the seed manifest, granted\n`owner` on the seed project.\n\nTwo new manifest fields drive it:\n • per-user `password` — overrides meta.defaultPassword\n • `roles` array (owner|admin|steward)\n\nA new `roles` phase in 03-seed-engine.mjs applies them. It \n[…]\n clean; unit suite 540 passed.\n\nAlso carries a pre-existing untracked change: the `migrate` script alias in\napps/api/package.json.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(seed): seed a demo admin as project owner via manifest role grants",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T07:54:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cc9b6d31a1f4bc635166745f76f4dcde18b4c828",
"body": "… + supersede search spec\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs: private-by-default posture — MANIFEST/MODELS/SECURITY/CHANGELOG…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T07:07:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b059ddd20e7d59b3f847fc2d98fe580aa55e386a",
"body": "…the auth wall\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(db): revoke 0008 anon public-read policies — DB posture matches …",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:59:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c551f812bf8b7e3553fe572166509002975f93dd",
"body": "…y tokens\n\nEvery existing integration test that exercised a project-scoped read\nanonymously now mints/passes a fixture user's token, per the wall mounted in\nTask 2. Tests that asserted anonymous access as the behavior under test were\ninverted (anonymous -> 401, authed -> the previous expectation), n\n[…]\nRAGE_PROVIDER=s3 in dev .env routing through an unreachable MinIO) and\nwere left untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "test(api): sweep integration suite for the auth wall — reads now carr…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:50:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "68b320c11b69a9cc0bb5187f48f82142cd627cb4",
"body": null,
"is_bot": false,
"headline": "#5 match docs",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:48:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bd046ed350c261fb132c4ac788a46ce8ef95952",
"body": "…ALLOWLIST\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(api): mount the auth wall — private by default behind AUTH_WALL_…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:15:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8098f17d9675e30ca2370ebf2ed822e0b442cb9d",
"body": "…gn-in allowlist\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(core): authWall middleware — private-by-default gate with pre-si…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:03:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1450b647012d794fe951af9b64b3cc2bf49463b8",
"body": "Also tracks the 2026-07-16 search-auth spec it supersedes, so Task 5's\nsupersession lands as a one-line diff rather than a new file.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs(specs): auth wall — private-by-default design + implementation plan",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T06:00:16Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0721b68ecde88b74fa43db2f0514fd2b51cfd66d",
"body": "Enforce the space `visibility` axis (public/unlisted/private, migration 0060,\npreviously persist-only) on discovery reads: filter listings/search/children,\n404 hidden private spaces on direct fetch, truncate breadcrumb ancestors, and\ngate sub-resource reads. Closes a hole where private spaces were f\n[…]\nstranger.\n\nOpus whole-branch review: READY TO MERGE. No migration/contract change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n# Conflicts:\n#\tCHANGELOG.md\n#\tdocs/MANIFEST.md",
"is_bot": false,
"headline": "merge: space-visibility discovery filtering (SDK v7.8.2 #3)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T05:41:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "723f7d32c5b7837c8274c0b9aea0502fa33cdd38",
"body": "…space (M1)\n\nThe Thorough visibility gate 404'd /membership/me for a PENDING applicant on a\nprivate space, so \"apply -> can't check status\" was a dead end. Exempt the\ncaller's own row: a caller who already holds a membership row (pending/rejected/\nbanned) knows the space exists, so they may read the\n[…]\nsed];\nreleased sections are immutable history).\n\nIntegration 24/24 (2 new: pending reads own row; exemption unlocks nothing else).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(spaces): let a member read their OWN membership row on a private …",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T05:39:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "516dcca6f2788174b211132f6c1bff8f608c46d2",
"body": null,
"is_bot": false,
"headline": "plans & specs",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-17T02:47:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "648cc2cf37173368c907fe3e2451acb0fd3e437e",
"body": "Activate chat-message push notifications: fan out dispatchChatMessagePush to\nother active conversation members after the socket emit (sender excluded),\nhonoring per-conversation mute and the global chat-push opt-out. Row-less,\nPII-free, fire-and-forget (message still 201). No contract/model/migratio\n[…]\nange. Opus whole-branch review: READY, 0 blocking.\n\nGate: typecheck clean (5 pkgs), unit 525/525, integration affected-area 17/17.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: chat-message push fan-out (SDK v7.8.2 #2)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-10T03:55:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3aaefb6680e65decb7b7e3720049e3b04fa4093a",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs(spaces): document the space-visibility discovery gate",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-10T03:51:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "643468578a2b9f9eb32960767863e8e43cae20be",
"body": "…am/rules/membership)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(spaces): gate space sub-resource reads by visibility (members/te…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T10:00:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b0f840bc2f49d8323ce81f18a2fded790a31715",
"body": "…adcrumb ancestors\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(spaces): 404 hidden private spaces on direct fetch; truncate bre…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T09:55:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3871f875285ac212c7fb83c95137d87ab25d239e",
"body": "…nd children\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(spaces): filter unlisted/private spaces from listings, search, a…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T09:50:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "75d96f7d3a9ee7740deb79cf00b5a45590a3f4a3",
"body": "…view follow-up)",
"is_bot": false,
"headline": "test(chat): assert cleanup status in chat-message-push beforeEach (re…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T09:43:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f503a9816e118e2f4609b0e41045a2c44a355ae",
"body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(spaces): add space-visibility discovery authority + unit tests",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T09:02:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f7aa7f85a5aa14933011a01415e09355ed806afc",
"body": null,
"is_bot": false,
"headline": "docs: chat-message push fan-out (CHANGELOG + MANIFEST)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T08:55:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b8e2576b409c4cb3bc64c0ba3edbf0bfd183397",
"body": "…ors mute + opt-out)\n\nExtract awaitable sendChatMessagePush (decision testable at the webpush\nboundary); dispatchChatMessagePush stays fire-and-forget. Wire the per-member\nfan-out after the socket emit in POST /conversations/:id/messages, excluding\nthe sender. Integration-tested: dispatch when clear, suppressed on\nforever-mute, future timed-mute, and global opt-out; route smoke 201.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(chat): fan out push to conversation members on message send (hon…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T08:51:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "156ad45bdfc8132a8afd2356dfe061b2087b2721",
"body": null,
"is_bot": false,
"headline": "feat(push): register 'message' as a push-worthy type (New message)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T08:45:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "339c826002b1dadd5b056ab38fcb048d7371e739",
"body": "… #2)\n\nThree bite-sized TDD tasks: register the \"message\" push title; extract an\nawaitable sendChatMessagePush + wire the per-member fan-out after the socket\nemit; docs. Gates = mute + global opt-out; row-less; PII-free; no\ncontract/model/migration change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(plan): chat-message push fan-out implementation plan (SDK v7.8.2…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T08:44:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7d89faf86240e372f320e05248d68d869a777c7a",
"body": "Activate the unreachable chat-message push path: register the \"message\"\npush title and fan out dispatchChatMessagePush to other conversation\nmembers after the socket emit. Row-less (honors per-conversation mute),\ngates = mute + global opt-out only. No contract/model/migration change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(spec): chat-message push fan-out design (SDK v7.8.2 #2)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-09T08:38:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3ffa3a3fa57b59827bfde06fc63d9ebb6ede01af",
"body": "Emit a space-scoped spaceReputation on returned/embedded users when the SDK requests it\n(spaceReputationId uuid|none + spaceReputationDescendants), via a per-router spaceRepGate\nmiddleware + a centralized post-shape enrichSpaceReputation pass. Covers users, entities,\ncomments, chat, spaces (team/mem\n[…]\nn store). Additive/backward-compatible.\nVerified: typecheck clean (5 pkgs), unit 524/524, full integration 506 pass/7 skip/0 fail.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: space-reputation enrichment (SDK v7.8.2 #6)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T07:10:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e6a1a53090858beee668532c2989399dc9fd6973",
"body": "…intent)\n\nAdds logger.debug({ err }, …) in enrichSpaceReputation's space-read-gate catch so a\ntransient gate error is distinguishable from an expected members-only denial. Debug-level\nkeeps the common denial out of info/error noise. Behavior-preserving (still fails closed).\n\nPer final whole-branch review follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(space-rep): debug-log the fail-closed read-gate skip (log-with-…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T07:08:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6c8a16a8b1b1ad9cc4e47f112e80111008ecfde1",
"body": null,
"is_bot": false,
"headline": "plans and specs",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T07:03:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b899ff5f475121399cbcbbb9f0337f151136e07",
"body": "… and access gate",
"is_bot": false,
"headline": "docs(space-rep): document spaceReputation enrichment param, coverage,…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:51:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e7fdf68466bf8b6ced26a473d718fba3edcdb8f",
"body": null,
"is_bot": false,
"headline": "feat(space-rep): enrich embedded users on follows + connections",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:38:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91935e279931806e4670064bc7c8db433e2684ac",
"body": null,
"is_bot": false,
"headline": "feat(space-rep): enrich embedded users on spaces/search/reports",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:28:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80820b5300b4b6df2063511d5382c2fb1ee77a0c",
"body": "…iews)",
"is_bot": false,
"headline": "feat(space-rep): enrich embedded users on chat (members/messages/prev…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:16:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f047be0c62f3083325fbc6ec98a273f92e2b229",
"body": null,
"is_bot": false,
"headline": "feat(space-rep): enrich embedded users on entities + comments",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:09:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47e9e3158084ed45b3ed4abe2262ced2bc0fb49b",
"body": "…n (private-space oracle)",
"is_bot": false,
"headline": "fix(space-rep): fail-closed space-read gate on space-scoped reputatio…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T06:01:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "716085ab2c624af05d43560cb150052f6abb3fd0",
"body": "…nd-to-end",
"is_bot": false,
"headline": "feat(space-rep): spaceRepGate middleware + wire users (user-direct) e…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T05:43:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d82d33ce9ddb278e52fa6cabb39c435520420f86",
"body": "…ollect/resolve/stamp)",
"is_bot": false,
"headline": "feat(space-rep): contract field + Variables + pure enrichment core (c…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T05:32:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3de2910528bc166714acaa16a693270187e3665a",
"body": null,
"is_bot": false,
"headline": "chore(release): v0.19.0",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T03:11:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c6f71fcfff2e9777e72335b6d14c0867334c30f",
"body": null,
"is_bot": false,
"headline": "merge: map unreachable tenant DB to a retryable 503 (api + secure-chat)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T03:10:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea15350104a31c725b1acb0c523ac8d4381b89d3",
"body": "A per-tenant request routing to a well-formed but unreachable Postgres DSN\n(host down, connection refused, DNS failure, connect timeout, dropped socket)\nsurfaced as 500 common/internal — mislabelling a transient infra outage as an\napplication bug, paging the app team and telling clients not to retry\n[…]\nan app-level wire test per service asserting\nconnection→503 and FK-error→500.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix: map unreachable tenant DB to a retryable 503, not 500",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T03:00:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "af3134e8f5f0f6335043674de8d4609152b3385b",
"body": "… visibility, follows/connections search, search includeChildSpaces (+ match/space-rep scaffolds)\n\nSecond merge after the space-scoped reputation engine. This branch's four migrations were renumbered 0058-0061 -> 0060-0063 (journal when 658-661, strictly above root's max 657) to clear the collision \n[…]\n.muted_forever + match_content(9-arg); full integration suite green (exit 0).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "merge: v7.8.2 SDK sync — notification prefs, conversation mute, space…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T01:20:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2e9ab2488e80b1e663eeca217511c531ab84709f",
"body": "…ith root space_reputation 0058/0059)\n\nRoot merged the space-scoped reputation engine (0058_space_reputation, 0059_space_reputation_trigger) first. This branch is the second merge, so its four migrations are renumbered to 0060-0063 with journal when 1781934611658-661 (strictly above root's max 657).\n[…]\nents + journal entries + CHANGELOG number refs; no SQL body or schema change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "chore(migrations): renumber 0058-0061 -> 0060-0063 (avoid collision w…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T01:11:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8e84a3ed96ca0093e83a722529e950c45a1f833a",
"body": "Cleanup pass on feat/sdk-v7.8.2-sync from the final review: escape\n%/_/\\ in the follows/users search query so it can't act as a SQL LIKE\nwildcard, dedup disabledTypes on PUT /preferences before persisting and\nechoing it, add missing boundary-case unit tests (mute exact-expiry,\nspace-reputation absen\n[…]\nfor space-reputation\nvalidation to match the handlers it's actually wired on.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "fix: harden user-search LIKE escaping, dedup push prefs, close test gaps",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T00:52:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "565b8780487f3c5e0c716362977d6b8b9439faef",
"body": "…endant CTE rollup\n\nTrigger-maintained per-(user,space) reputation (the space-partitioned twin of profiles.reputation) plus loadSpaceReputations read batcher with recursive-CTE subtree rollup. Migrations 0058/0059. Forward-only; feed-level & message reactions contribute to no space. The storage/read\n[…]\n.2 space-reputation enrichment (wire contract owned by feat/sdk-v7.8.2-sync).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "merge: space-scoped reputation engine — space_reputation store + desc…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-08T00:48:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "349dd146e6850c296b24cd2daf9055f7f1744de5",
"body": "… CTE with CYCLE guard\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "test(reputation): pin content_space_id message branch; harden subtree…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T14:00:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "231ee8f6e925e2f694bcc8190441e3d91897da07",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(reputation): descendant rollup via recursive CTE + changelog",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T13:48:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fee3d42cbbcf515560592e0473da7b2dbf391a05",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(reputation): loadSpaceReputations single-space read + map-fill",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T13:36:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9c4fbbc42b54dbf2d22647518da30fa43b17f260",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(reputation): maintain space_reputation from the reaction trigger",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:55:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9c5c757773889bfebbce518d19efe8bb4cdd6ab8",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(reputation): add space_reputation table + RLS",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:49:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1d87cbc9b3b4ff5a3379aade3e13aea21b4db04c",
"body": "Documents the seven v7.8.2 server-side features against the shipped code:\nnotification preferences, conversation mute (with the not-yet-wired\nmessage-push suppression noted), space visibility (persist+emit only, no\ndiscovery filtering), follows/connections text search (post-pagination\nfilter caveat)\n[…]\n surfaces (match,\npush-notification preferences) per the propagation checker.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "docs: MANIFEST/MODELS/CHANGELOG for v7.8.2 SDK sync",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:47:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b4e8728b40ffa9094b560e39d54608e2402b5b07",
"body": "…n user-direct)\n\nAdd validateSpaceReputationParams as a pure, unit-tested guard for the\nspaceReputationId/spaceReputationDescendants SDK params, and wire it onto\nevery user-direct (/users/*) handler so a spaceReputationId=context there\n400s (space-reputation/context-not-allowed) instead of silently \n[…]\nrollup) is a\nfuture spec — this cycle only ships the shared validation shape.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(users): space-reputation param validator scaffold (context 400 o…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:35:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "091f52dd976e3ae6c95e8d9695054ac00201bf77",
"body": "Ships the v7.8.2 useMatchUsers request contract only; the facet/embedding\nengine is a separate future spec. requireAuth-gated, body validated by\nmatchUsersSchema (directed mode without a non-empty query -> 400), always\nresolves { results: [] } so the SDK hook settles cleanly.\n\nMounted in routes/inde\n[…]\n wires createApp() plumbing\nand mounts the whole /v7 tree via mountRoutes()).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(match): POST /match/users stub (validated, returns empty results)",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:28:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e6e9525af67593bb1c95da93733b97f894851037",
"body": "match_content gains p_space_ids uuid[] (default null) so a resolved\n{self ∪ descendants} space set can scope semantic search, instead of\njust a single space. retrieveContent (routes/search.ts) resolves the\nsubtree via lib/space-tree.ts resolveSpaceSubtree when the caller\npasses includeChildSpaces al\n[…]\ne-set arg through.\nNull p_space_ids preserves today's behavior byte-for-byte.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(search): includeChildSpaces via match_content space-set arg",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:16:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ab858b72c2efdfeefc7acc9df5edf11852c3ea0e",
"body": "Adds resolveSpaceSubtree(projectId, spaceId), a recursive CTE over\nspaces.parent_space_id returning the space id plus all live descendant\nids (self included). Scoped by project_id and deleted_at is null at\nboth the anchor and recursive steps; fully parameterized (::uuid\ncasts, no string interpolation). Consumed by the upcoming search\nincludeChildSpaces support (Task 11).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(spaces): recursive space-subtree resolver",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:06:59Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c28f9f75d801dbb2f2beaa93f1bb8506e68bfa40",
"body": "…ession\n\nAdds POST /conversations/:id/mute (self-scoped mutedUntil/mutedForever\nupdate via muteDurationToState) and isConversationMutedForUser /\ndispatchChatMessagePush push-layer helpers that gate a chat \"message\"\npush on the recipient's per-conversation mute, after the existing\nglobal opt-out. No \n[…]\nMessagePush is\nready for a future task to wire into the message-send fan-out.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
"is_bot": false,
"headline": "feat(chat): POST conversations/:id/mute + per-conversation push suppr…",
"author_name": "Jenova Marie",
"author_login": "jenova-marie",
"committed_at": "2026-07-07T12:00:56Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 26,
"commits_last_year": 827,
"latest_release_at": "2026-07-19T06:04:45Z",
"latest_release_tag": "v0.22.0",
"releases_from_tags": false,
"days_since_last_push": 3,
"active_weeks_last_year": 9,
"days_since_latest_release": 5,
"mean_days_between_releases": 1.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@agora-server/contract",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@agora-server/contract",
"is_deprecated": false,
"latest_version": "0.22.0",
"repository_url": "https://github.com/agora-oss-org/agora-server",
"versions_count": 19,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 3465,
"first_published_at": "2026-06-07T09:07:42.467000Z",
"latest_published_at": "2026-07-19T06:04:56.746000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 4,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"apps/admin/tsconfig.json",
"apps/api/tsconfig.json",
"apps/secure-chat/tsconfig.json",
"packages/contract/tsconfig.json",
"packages/core/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 38991,
"source_files_sampled": 542,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 45604
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 1,
"malicious_count": 0,
"assessed_package": "npm:@agora-server/contract@0.22.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@agora-server/contract",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@radix-ui/react-avatar",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.12"
},
{
"name": "@radix-ui/react-dialog",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.16"
},
{
"name": "@radix-ui/react-dropdown-menu",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.17"
},
{
"name": "@radix-ui/react-separator",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.9"
},
{
"name": "@radix-ui/react-slot",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.2.5"
},
{
"name": "@radix-ui/react-tabs",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.14"
},
{
"name": "@radix-ui/react-toast",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.2.16"
},
{
"name": "@radix-ui/react-tooltip",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.2.9"
},
{
"name": "@tanstack/react-query",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^5.101.0"
},
{
"name": "class-variance-authority",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.7.1"
},
{
"name": "clsx",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.1"
},
{
"name": "lucide-react",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.17.0"
},
{
"name": "react",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.1"
},
{
"name": "react-dom",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.1"
},
{
"name": "react-router-dom",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^7.17.0"
},
{
"name": "tailwind-merge",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^3.6.0"
},
{
"name": "zod",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.76"
},
{
"name": "@agora-server/contract",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@agora/core",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@aws-sdk/client-s3",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^3.901.0"
},
{
"name": "@hono/node-server",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^1.19.14"
},
{
"name": "@jenova-marie/wonder-logger",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.4"
},
{
"name": "@node-rs/argon2",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.2"
},
{
"name": "@opentelemetry/api",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^1.9.0"
},
{
"name": "@socket.io/redis-adapter",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^8.3.0"
},
{
"name": "@supabase/supabase-js",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^2.107.0"
},
{
"name": "dotenv",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "drizzle-orm",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^0.45.2"
},
{
"name": "hono",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.23"
},
{
"name": "ioredis",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^5.11.1"
},
{
"name": "jose",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^5.10.0"
},
{
"name": "neo4j-driver",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^6.1.0"
},
{
"name": "postgres",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^3.4.9"
},
{
"name": "sharp",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^0.34.5"
},
{
"name": "socket.io",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^4.8.3"
},
{
"name": "web-push",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^3.6.7"
},
{
"name": "zod",
"manifest": "apps/api/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.76"
},
{
"name": "@agora-server/contract",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@agora/core",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@hono/node-server",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^1.19.14"
},
{
"name": "@jenova-marie/wonder-logger",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.0"
},
{
"name": "dotenv",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "drizzle-orm",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^0.45.2"
},
{
"name": "hono",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.23"
},
{
"name": "ioredis",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^5.11.1"
},
{
"name": "jose",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^5.10.0"
},
{
"name": "postgres",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^3.4.9"
},
{
"name": "socket.io",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^4.8.3"
},
{
"name": "zod",
"manifest": "apps/secure-chat/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.76"
},
{
"name": "zod",
"manifest": "packages/contract/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.76"
},
{
"name": "@agora-server/contract",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@jenova-marie/wonder-logger",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.0"
},
{
"name": "drizzle-orm",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^0.45.2"
},
{
"name": "hono",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.23"
},
{
"name": "ioredis",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^5.11.1"
},
{
"name": "jose",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^5.10.0"
},
{
"name": "postgres",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^3.4.9"
},
{
"name": "zod",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.76"
},
{
"name": "fastapi",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.110"
},
{
"name": "uvicorn",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.29"
},
{
"name": "pydantic",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.6"
},
{
"name": "httpx",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.27"
},
{
"name": "asyncpg",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.29"
},
{
"name": "pyjwt",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.8"
},
{
"name": "neo4j",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.19"
},
{
"name": "opentelemetry-sdk",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.27.0"
},
{
"name": "opentelemetry-exporter-otlp-proto-http",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.27.0"
},
{
"name": "opentelemetry-exporter-prometheus",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.48b0"
},
{
"name": "opentelemetry-instrumentation-fastapi",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.48b0"
},
{
"name": "opentelemetry-instrumentation-asyncpg",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.48b0"
},
{
"name": "opentelemetry-instrumentation-httpx",
"manifest": "services/scorer/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.48b0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 2,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "jenova-marie",
"commits": 827,
"avatar_url": "https://avatars.githubusercontent.com/u/202562814?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"dco.yml",
"docker-publish.yml",
"npm-publish.yml",
"release.yml",
"wiki-sync.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "23 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "9ceb3fe8edb50190e2ebfe988f07bfbe6aa3230a",
"ran_at": "2026-07-25T03:29:13Z",
"aggregate_score": 3.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T09:37:20Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-06-10T08:13:20Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/agora-oss-org/agora-server",
"host": "github.com",
"name": "agora-server",
"owner": "agora-oss-org"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"security": 46,
"vitality": 76,
"community": 42,
"governance": 50,
"engineering": 76
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 76,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"commits_last_year": 827,
"human_commit_share": 1,
"days_since_last_push": 3,
"active_weeks_last_year": 9
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "9/52 weeks with commits",
"points": 6.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 9
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "827 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 827
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 26,
"latest_release_tag": "v0.22.0",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 1.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "26 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 26
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 42,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 8,
"inputs": {
"forks": 0,
"stars": 4,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "4 stars",
"points": 7.7,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 4
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (AGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "AGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 59,
"inputs": {
"packages": [
"@agora-server/contract"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 3465
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "3,465 downloads/month across npm",
"points": 47.2,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 3465,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 50,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 2,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2/2 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2,
"decided": 2
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 36,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "agora-oss-org",
"public_repos": 5,
"account_age_days": 30
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of agora-oss-org",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "agora-oss-org"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "5 public repos, account ~0 yr old",
"points": 5.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 5
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@agora-server/contract"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "19 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 19
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 76,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"backend",
"comments",
"community",
"drizzle-orm",
"moderation",
"nodejs",
"open-source",
"pgvector",
"postgres",
"realtime",
"replyke",
"self-hosted",
"semantic-search",
"social-network",
"socketio",
"supabase",
"typescript",
"replyke-sdk",
"replyke-server",
"sublay"
],
"has_wiki": true,
"homepage": "https://demo.agora-oss.org",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://demo.agora-oss.org",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "20 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 20
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 46,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 32,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "23 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@agora-server/contract@0.22.0 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@agora-server/contract@0.22.0",
"assessed": 1
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 1,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 1,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 73,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.93,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 45604
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "93 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 93,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 53,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"apps/admin/tsconfig.json",
"apps/api/tsconfig.json",
"apps/secure-chat/tsconfig.json",
"packages/contract/tsconfig.json",
"packages/core/tsconfig.json"
],
"agent_commit_share": 0.48,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "apps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "apps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "48 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 48,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 38991,
"source_files_sampled": 542,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/542 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 542,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch pypi package 'agora-scorer' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T03:29:23.774832Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agora-oss-org/agora-server.svg",
"full_name": "agora-oss-org/agora-server",
"license_state": "standard",
"license_spdx": "AGPL-3.0"
}