Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-23 12:46 UTC

ai-setting / ai-agent-bounty

AI Agent Bounty System - Task publishing, grabbing, credits escrow and mail communication

TypeScriptЛіцензію не виявлено★ 0 зірок⑂ 0 форківз квіт. 2026 р.Переглянути на GitHub ↗

ai-setting/ai-agent-bounty має індекс здоров’я 49 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Vitality (78/100), найнижчий — Community & Adoption (24/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

49
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

49
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

ai-settingОрганізація
0 підписників5 публічних репозиторіївз лют. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npm@ai-setting/agent-bounty0.14.21 523135 днів томуai-agentbountytaskrewardmailcommunicationescrowsmtptoken-toggle
npm@ai-setting/agent-bounty-standalone0.14.22 039195 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

78Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
7.6/36Ритм комітів — 11/52 тижнів із комітами
18/18Обсяг комітів — 321 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year321
human_commit_share1
days_since_last_push5
active_weeks_last_year11
Як обчислюється оцінка
16.2/27Випускає релізи — 11 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~0,9 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count11
latest_release_tagv0.14.2
releases_from_tagsтак
days_since_latest_release5
mean_days_between_releases0,9
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

24Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
0/22.5Ліцензія — файлу ліцензії не виявлено
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseні
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
47.4/80Щомісячні завантаження — 3 562 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@ai-setting/agent-bounty, @ai-setting/agent-bounty-standalone
dependents
ecosystemsnpm
total_downloads
monthly_downloads3 562
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

32У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, Прийняття PR. Залишкові ваги перенормовано.

Власність та опіка

37У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
0/25Охоплення власника — 0 підписників у ai-setting
6.6/25Послужний список — 5 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers0
owner_typeOrganization
is_verified
owner_loginai-setting
public_repos5
account_age_days168

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 2 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 19 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@ai-setting/agent-bounty, @ai-setting/agent-bounty-standalone
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

66Помірний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 1 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

41У зоні ризику · 16% загального індексу

Стан безпеки

36У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Ліцензія — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — немає даних
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 14 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate3,6
Виключено з оцінювання (немає даних або не застосовно): ci_tests, packaging, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
11.9/35Прямі залежності без відомих сповіщень — уражено 2: nodemailer 8.0.11 (high 7.1), uuid 9.0.1 (high 7.5)
13.2/25Непрямі залежності без відомих сповіщень — уражено 1: @hono/node-server 1.19.14 (moderate 5.9)
33.7/40Немає задавнених сповіщень — 1 пакет(ів) зі сповіщеннями без реакції понад 90 дн.; найдавніше опубліковано 91 дн. тому
Використані вхідні дані
sourceosv
advisories3
affected_packages3
assessed_packages330
unassessed_packages0
affected_by_severityhigh 2, moderate 1
direct_affected_packages2
Звірено з runtime-замиканням залежностей npm:@ai-setting/agent-bounty@0.14.2 — тим, що тягне за собою встановлення опублікованого пакета, — 330 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

52Помірний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 98 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,98
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — tsconfig.json, web/tsconfig.json
10/10Відтворюване середовище — Dockerfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileтак
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configstsconfig.json, web/tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
55/55Керовані розміри файлів — 0/283 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes27 647
source_files_sampled283
oversized_source_files0

Ключові факти

0зірок GitHub
1контриб'юторів
321комітів за останні 12 місяців
5днів від останнього пушу
11релізів
1бас-фактор
0відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 3.6 / 10
3.6сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-23 12:46 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
н/дPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities14 existing vulnerabilities detected
Прямі залежності 14
РеєстрПакетОбмеження версіїМаніфест
npm@ai-setting/roy-agent-cli^1.5.110package.json
npm@ai-setting/roy-agent-coder-harness^1.5.50package.json
npm@ai-setting/roy-agent-core^1.5.102package.json
npm@types/ws^8.18.1package.json
npmchalk^5.3.0package.json
npmdotenv^17.4.2package.json
npmjose^6.2.3package.json
npmnodemailer^8.0.7package.json
npmuuid^9.0.0package.json
npmyargs^17.7.2package.json
npmzod^3.22.4package.json
npmreact^18.3.1web/package.json
npmreact-dom^18.3.1web/package.json
npmreact-router-dom^6.26.2web/package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Сповіщення про залежності 3

Встановлення npm:@ai-setting/agent-bounty@0.14.2 тягне 330 пакетів, прямих і транзитивних: 3 мають відомі сповіщення, з них 2 — прямі залежності.

ПакетВерсіяЗв'язокКритичністьСповіщеньВиправлено в
nodemailer8.0.11прямависока19.0.1
uuid9.0.1прямависока113.0.1
@hono/node-server1.19.14непрямапомірна12.0.5

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1235,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "CSS": 10018,
        "HTML": 2482,
        "Shell": 6998,
        "Dockerfile": 2592,
        "JavaScript": 9349,
        "TypeScript": 1364900
      },
      "pushed_at": "2026-07-18T04:04:29Z",
      "created_at": "2026-04-02T10:24:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-18T04:04:15Z",
      "description": "AI Agent Bounty System - Task publishing, grabbing, credits escrow and mail communication",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "ai-setting",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/259477808?v=4",
      "created_at": "2026-02-05T02:13:19Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 168
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-07-18T04:04:08Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-07-18T01:30:13Z"
        },
        {
          "tag": "v0.13.4",
          "kind": "patch",
          "published_at": "2026-07-17T11:19:38Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2026-07-17T10:53:04Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-07-17T10:30:34Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-17T08:41:53Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-17T08:21:48Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-07-12T02:49:23Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-12T02:39:22Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-09T16:29:44Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-09T06:48:41Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e64a45c5b7314f675c907a18838136c9a253e8c7",
          "body": null,
          "is_bot": false,
          "headline": "docs(reports): v0.14.2 release pipeline report (Task #2137)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T04:04:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2c9fc45046d5c54f735844507ae55cd70c6085d",
          "body": null,
          "is_bot": false,
          "headline": "chore(standalone): bump standalone version 0.14.1 → 0.14.2",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T04:02:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83378ae78e7321500c4b84e497c3c69efd849a26",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server + bounty-web images to v0.14.2",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T03:56:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dab4e105602675453c1eba3bbc156d350d921067",
          "body": null,
          "is_bot": false,
          "headline": "merge: bring v0.14.2 hotfix into main (no-self-echo)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T03:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab821a7a62a8bd929d8313b31fbc0e961d3fb419",
          "body": "…k #2137)\n\nPlan doc updated with final DoD checklist (all ✓) and commit history.\nBranch ready for user review.",
          "is_bot": false,
          "headline": "docs(reports): v0.14.2 self-echo server-side plan — final status (Tas…",
          "author_name": "Task #2137",
          "author_login": null,
          "committed_at": "2026-07-18T03:41:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0595a1132ed1b43f4ac444cf35c9d902fbfb4cd7",
          "body": "- package.json: 0.14.1 → 0.14.2 (PATCH, server-side root-cause fix)\n- CHANGELOG.md: Added v0.14.2 entry covering:\n  - SELF_MESSAGE_NOT_ALLOWED (HTTP 400)\n  - RECIPIENT_NOT_FOUND (HTTP 404)\n  - WS push defense-in-depth\n  - handleWsMessage 'message' case refactor\n  - Compatibility note for self-send break\n  - Test counts (1043 → 1048)\n\nBranch: hotfix/v0.14.2-no-self-echo (not merged, not published)\nTask: #2137",
          "is_bot": false,
          "headline": "chore(version): bump 0.14.1 → 0.14.2 + CHANGELOG entry",
          "author_name": "Task #2137",
          "author_login": null,
          "committed_at": "2026-07-18T03:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57e59404fdf7915b61eb08719672069130f4c37c",
          "body": "…depth)\n\nTwo-pronged defense so self-echo cannot leak through either push path:\n\n1. `BountyHTTPServer.pushMessage` — compares the connection's registered\n   UUID against the message sender's UUID. Match → return false without\n   sending the WS frame. Catches any caller that routes through this\n   si\n[…]\n-sender-identity tests 1, 3, 4 — register recipient\n- ws-push-v0.14.1-email-display T3 — separate recipient (self rejected)\n\nBranch: hotfix/v0.14.2-no-self-echo (not merged, not published)\nTask: #2137",
          "is_bot": false,
          "headline": "feat(server): skip WS push to sender on outbound message (defense-in-…",
          "author_name": "Task #2137",
          "author_login": null,
          "committed_at": "2026-07-18T03:39:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7684f37e22a3f345d78171d88df4e69719638c75",
          "body": "…404)\n\nTwo API-level defenses in IMRoutes.sendMessage:\n\n1. SELF_MESSAGE_NOT_ALLOWED (HTTP 400)\n   - When the resolved recipient's UUID matches the authenticated sender's\n     UUID (or the body.from UUID in legacy mode), return 400.\n   - Closes the v0.14.1 observable bug where `bounty com send -F X -\n[…]\nted requests.\n\nT2 + T3 of messages-no-self-echo.test.ts now GREEN.\nT1 + T5 were already GREEN; T4 still RED (next commit).\n\nBranch: hotfix/v0.14.2-no-self-echo (not merged, not published)\n\nTask: #2137",
          "is_bot": false,
          "headline": "feat(server): reject self-message + unregistered recipient (HTTP 400/…",
          "author_name": "Task #2137",
          "author_login": null,
          "committed_at": "2026-07-18T03:30:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c3805b907699092172352bf223d2e372dedd010",
          "body": "…4.2)\n\n5 tests covering:\n- T1: sender != recipient → sender WS does not get push (already green)\n- T2: POST to self → 400 SELF_MESSAGE_NOT_ALLOWED\n- T3: POST to unregistered email → 404 RECIPIENT_NOT_FOUND\n- T4: WS message event self-send → push skipped (defense-in-depth)\n- T5: v0.14.1 enrichment pr\n[…]\n\n\nTests 2, 3, 4 fail (RED); will be made GREEN by subsequent feat commits.\n\nPlan: reports/2137-v0.14.2-self-echo-server.md\n\nBranch: hotfix/v0.14.2-no-self-echo (not merged, not published)\n\nTask: #2137",
          "is_bot": false,
          "headline": "test(server): RED tests for no-self-echo + recipient validation (v0.1…",
          "author_name": "Task #2137",
          "author_login": null,
          "committed_at": "2026-07-18T03:27:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "842977e9ada18ac631a3322a0764b672ef0d6c25",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server + bounty-web images to v0.14.1",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:30:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae1a71f70114f0a09fb5369b47ac2bca38a1bf38",
          "body": "5 commits ahead of main:\n- 70263b3 feat(server): POST /api/messages response includes from_email / to_email\n- ea8bb25 feat(cli): com send + com inbox display registered emails\n- 57faa96 feat(server): WS push payload includes fromEmail / toEmail\n- 088623a chore(release): v0.14.1 bump\n- ec9b194 chore(standalone): bump standalone version 0.14.0 → 0.14.1\n\n1043 tests pass, typecheck + build clean.",
          "is_bot": false,
          "headline": "merge: hotfix/v0.14.1-email-display → main (v0.14.1 release)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:27:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec9b1947dc91a59deeacc5e9303be50a9fcfb0ff",
          "body": "Matching @ai-setting/agent-bounty main package bump.",
          "is_bot": false,
          "headline": "chore(standalone): bump standalone version 0.14.0 → 0.14.1",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "088623a6a1f214b1ab39f921dfc71b310ba7757b",
          "body": "…→ 0.14.1\n\nDisplay-only patch — no API contract changes. See CHANGELOG for details.",
          "is_bot": false,
          "headline": "chore(release): v0.14.1 bump — CHANGELOG entry + package.json 0.14.0 …",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:15:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57faa96adb2c98d8cfb9ee102578e87c54c6008f",
          "body": "- BountyHTTPServer.pushMessage enriches outgoing WS payload with\n  fromEmail / toEmail (resolved via bountyDb, same resolver as HTTP response)\n- Handle <uuid>@authenticated by id lookup (sender side)\n- Handle <uuid>@<host> by address/email lookup (recipient side)\n- Fallback to canonical value on miss (preserves message shape)\n- RED tests: 3 / GREEN: 3\n- Baseline 922 → 930 pass (+8), 0 regressions",
          "is_bot": false,
          "headline": "feat(server): WS push payload includes fromEmail / toEmail (v0.14.1)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea8bb25686490ca41017c836e478faa1e860f3f7",
          "body": "- com send: From / To use message.from_email / to_email (fallback to canonical)\n- com inbox: same, on each inbox item (msg.from_email / to_email → fallback)\n- RED tests: 5 / GREEN: 5\n- Backward compat: v0.14.0 servers (no enrichment) still display canonical\n\nBaseline 922 → 927 pass (+5), 0 regressions.",
          "is_bot": false,
          "headline": "feat(cli): com send + com inbox display registered emails (v0.14.1)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:10:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70263b33701df2928764c9d4cd42e7cacc3090dd",
          "body": "…ail (v0.14.1)\n\n- Add ResolveEmailFn callback type (parallel to ResolveIdentifierFn)\n- Add IMRoutes.setResolveEmail + constructor option\n- Wire bountyDb-based email resolver in BountyHTTPServer (handles\n  <uuid>@authenticated via id lookup, fallback to findAgentByEmailOrAddress)\n- sendMessage() resp\n[…]\nngside canonical\n  from / to (backward compat preserved)\n- getMessages() inbox items also enriched with from_email / to_email\n- RED tests: 5 / GREEN: 5 (T1-T5)\n\nBaseline 917 → 922 pass, 0 regressions.",
          "is_bot": false,
          "headline": "feat(server): POST /api/messages response includes from_email / to_em…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-18T01:08:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be34f1700e7b07dc87b2e55d7c5e5fdecb43925c",
          "body": "Matches @ai-setting/agent-bounty@0.14.0 release. Standalone binaries\nwere rebuilt with v0.14.0 source via scripts/build-standalone.ts --all\nand published as @ai-setting/agent-bounty-standalone@0.14.0.",
          "is_bot": false,
          "headline": "chore(release): bump bounty-standalone package.json 0.12.0 → 0.14.0",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T23:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4441ca56ef85ff1936f4e4d872e840fc8e938bc9",
          "body": "Match bounty-server:v0.14.0 release. The web app release is independent\nof the strict-email-only server refactor (no breaking UI changes), but\nkeeping web + server at the same version simplifies release tracking.",
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-web image to v0.14.0",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T23:11:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fb807a879fded1fc70faf984fd2b7bd3f338504",
          "body": "- Strict email-only CLI + HTTP API contract\n- BOUNTY_IM_ADDRESS removed\n- Legacy *Address body fields + ?address= query rejected with 400\n- 1030/1030 tests pass\n- k8s image already bumped to v0.14.0\n- 19 commits squashed into single merge commit",
          "is_bot": false,
          "headline": "merge: refactor/bounty-email-only → main (v0.14.0 release)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T23:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e4cb4eee952b59714bdbdda34fc58835e641a27",
          "body": null,
          "is_bot": false,
          "headline": "Finalize Task 2119 pipeline evidence",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T16:19:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c39e8c8c2922b0bd0584c2bb39ef29829648b80",
          "body": "…..RC-3 resolved)",
          "is_bot": false,
          "headline": "docs(reports): phase-5 resume-modified (1030/1030 pass, all FB-1+RC-1…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T15:36:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c02161078d181540f04b3e44fea34fe0a856824",
          "body": "…ress body fields + ?address= query rejected with 400)",
          "is_bot": false,
          "headline": "fix(server): RC-2/RC-3 + FB-1 strict email-only contract (legacy *Add…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T15:36:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ecffa447b3c38dd36a305224bd2b4d4f9cff4cf",
          "body": "…pe complete)",
          "is_bot": false,
          "headline": "docs(reports): final phase-4 resume-modified schema (1024/0 pass, sco…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T15:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a2151f3ce46f36776241d3cd6347cd879116523",
          "body": "…pdate CHANGELOG + README + k8s image",
          "is_bot": false,
          "headline": "refactor: v0.14.0 release — delete BOUNTY_IM_ADDRESS, bump version, u…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T15:06:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51d22393e8e2bea74fc60a41f6383c024ab0a9da",
          "body": "…only contract (606/606 pass)",
          "is_bot": false,
          "headline": "refactor(cli): migrate remaining CLI commands + tests to v0.14 email-…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T15:02:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2057d7baae946e5e734f76d93bd5ca3d1aef5eb8",
          "body": "…EAKING)",
          "is_bot": false,
          "headline": "refactor(cli): R-7#5 auth/register-agent/profile email-only (v0.14 BR…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T14:48:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b07dda5a221fc0267dbc572aba0f17e2dd4f36cf",
          "body": "…as + R-6 requireEmailFlag (v0.14)",
          "is_bot": false,
          "headline": "refactor(cli): R-2 board publisher-email filter + R-3 com-send -u ali…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T14:34:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5584e86f979098ccbc3e81cc80ca17308688663",
          "body": "…ds (v0.14 BREAKING)",
          "is_bot": false,
          "headline": "refactor(cli): R-1 requireEmailFlag helper + apply to 5 bounty comman…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T14:30:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "200055c9bba9d720f1267c5e0acac1af5ba3c60a",
          "body": "Machine-readable companion to docs/superpowers/plans/2026-07-17-bounty-email-only-\nrefactor.md (commit f7304f3). Captures the final decision record (Q1-Q6),\nthe 7 code-review blockers, and the ordered TDD repair plan (R-1..R-7)\nplus exit criteria. Used for downstream pipeline agents (strict-task-agent\nv5.1, bench-agent-host) to resume Phase 4 Execute without re-reading the\nfull markdown plan.\n\nRefs: Task #2119.",
          "is_bot": false,
          "headline": "docs(plan): submit Phase 3 RESUME schema JSON referencing amended plan",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T14:16:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7304f3917e8aa6de598d7182580b1bbf0ee7136",
          "body": "…plan\n\nPer Phase 3 RESUME user message (2026-07-17 14:12 UTC):\n\n- Decision Record (final answers, all confirmed):\n  - Q1: KEEP agents.address (internal canonical id only)\n  - Q2: KEEP /api/agents/by-email (unchanged from v0.13)\n  - Q3: 404 for valid-format unregistered email; 400 for malformed\n  - Q\n[…]\ns Tasks 9-18/20-27 + version bump + docs.\n\n- auto_merge=false preserved; final stop remains\n  refactor/bounty-email-only awaiting user merge approval.\n\nRefs: Task #2119, parent #2103, review op 15735.",
          "is_bot": false,
          "headline": "docs(plan): record Phase 3 RESUME decisions Q1-Q6 + 7 blocker repair …",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T14:15:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31b607df31b51c2938b84d452c8251231a1c1b23",
          "body": "Tasks 6 + 8 of the v0.14 strict email-only CLI refactor.\n\nboard.ts (Task 6) — no-op guarantee:\n  - Verified no legacy --agent-address/--agent-id/--publisher-address flags\n  - Verified no BOUNTY_IM_ADDRESS env fallback\n  - Verified no resolveCurrentAgentAddress / resolveAddressOption imports\n  - Veri\n[…]\ntoEmail', 'cli')\n  - Body uses {from_email, to_email} ONLY (no  /  keys)\n\nTests: 9/9 new contract tests pass (4 board + 5 com/send).\nServer regression sweep: 190/190 server tests pass, 0 new failures.",
          "is_bot": false,
          "headline": "refactor(cli): board + com send strict email-only (v0.14 BREAKING)",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T13:34:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2186209abf38fef031964a71442de9e77825afb4",
          "body": "…email (v0.14)\n\nTasks 4 + 5 of the v0.14 strict email-only CLI refactor.\n\nBoth commands follow the same BREAKING pattern:\n  - --publisher-address / -p option REMOVED (renamed to --publisher-email / -e)\n  - resolveCurrentAgentAddress + resolveAddressOption imports REMOVED\n  - BOUNTY_IM_ADDRESS env fa\n[…]\nses publisherEmail ONLY\n  T5: bare UUID in --publisher-email exits 1 + --publisher-email hint\n\nTests: 10/10 new contract tests pass.\nServer regression sweep: 190/190 server tests pass, 0 new failures.",
          "is_bot": false,
          "headline": "refactor(cli): bounty-task complete + cancel accept only --publisher-…",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T13:30:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd6423138dea67d95f1f9bb26e31302d9642ab4d",
          "body": "….14 BREAKING)\n\nTask 3 of the v0.14 strict email-only CLI refactor.\n\nThis is the most interesting refactor: --publisher-address / -p is\nRENAMED to --publisher-email / -e (alias swap).\n\nBREAKING changes to src/cli/commands/bounty-task/publish.ts:\n  - REMOVE --publisher-address / -p option\n  - ADD --p\n[…]\n6: body uses publisherEmail ONLY\n  T7: bare UUID in --publisher-email exits 1 + --publisher-email hint\n\nTests: 7/7 new contract tests pass.\nRegression sweep: 210/210 tests pass (27 files), 0 failures.",
          "is_bot": false,
          "headline": "refactor(cli): bounty-task publish accepts only --publisher-email (v0…",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T13:21:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8cf2dee1cb5147a69193c730358590fd553083bb",
          "body": "Task 2 of the v0.14 strict email-only CLI refactor.\n\nSame BREAKING changes pattern as Task 1 (grab):\n  - REMOVE --agent-address / -a option\n  - REMOVE resolveCurrentAgentAddress import + usage\n  - VALIDATE --email via parseEmail(input, 'email', 'cli')\n  - Use {agentEmail: parsed.value} body field\n\nR\n[…]\n      no legacy env fallback, etc.)\n  T6: integration — bare UUID in --email exits 1 with --email hint\n\nTests: 6/6 new contract tests pass.\nServer regression sweep: 190/190 still pass, 0 new failures.",
          "is_bot": false,
          "headline": "refactor(cli): bounty-task submit accepts only --email (v0.14 BREAKING)",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T13:16:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce50202e5a179c3aef112d2a02de633f6a92d656",
          "body": "Task 1 of the v0.14 strict email-only CLI refactor.\n\nBREAKING changes to src/cli/commands/bounty-task/grab.ts:\n  - REMOVE --agent-address / -a option from CLI surface\n  - REMOVE resolveCurrentAgentAddress import + usage (BOUNTY_IM_ADDRESS fallback)\n  - REPLACE body.agentAddress with body.agentEmail \n[…]\n, 0 new failures.\nExisting 6 v0.13-era legacy contract tests in tests/cli/ now fail —\nthese are the LEGACY tests the v0.14 plan explicitly removes in\nTask 23 (Delete legacy resolver + parser modules).",
          "is_bot": false,
          "headline": "refactor(cli): bounty-task grab accepts only --email (v0.14 BREAKING)",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T13:07:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfbed289d279646f4efaf1038f1f0db2f212fa75",
          "body": "Plan authored in Phase 3 (task operation #15670). Persisted here so the\nv0.14 design is reviewable alongside its implementation commits on the\nrefactor/bounty-email-only branch.",
          "is_bot": false,
          "headline": "docs(plan): persist v0.14 strict email-only refactor plan",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T12:52:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53f7b8ffbf595b1fd518e1eb6af4a7e1ca7732f9",
          "body": "Code review (operation #15687) flagged three blocking correctness issues\nin the v0.14 email-resolver:\n\n1. parseEmail was implicitly trimming input via input.trim() before\n   validation, so ' alice@example.com ' was accepted and normalized.\n   v0.14 strict boundary must reject — no implicit normaliza\n[…]\nvering the boundary cases above plus the\n  HTTP-surface hint contract.\n\nTests: 19/19 pass via bun test --parallel 4 (was 12/16 before fix).\nRegression sweep: 190/190 server tests pass, 0 new failures.",
          "is_bot": false,
          "headline": "fix(lib): tighten parseEmail boundary per code review",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T12:52:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69254d41367f9904a72d433dbbaf7a050987ce30",
          "body": "Foundation of v0.14 BREAKING refactor: introduces src/lib/email-resolver.ts\nas the single source of truth for actor identity at server / CLI boundary.\n\nparseEmail rejects:\n  - <uuid>@<host> (legacy address form — UUID local part)\n  - bare UUIDs (no @ in input)\n  - empty/whitespace/null/undefined/non\n[…]\nputs (no silent fallback).\n\nformatCanonicalAddress retained as internal IM helper.\n\nTests: 12/12 pass via bun test --parallel 4. Regression sweep: 183/183\nserver tests pass with 0 failures introduced.",
          "is_bot": false,
          "headline": "feat(lib): add strict email-only resolver for v0.14 actor identity",
          "author_name": "Roy",
          "author_login": null,
          "committed_at": "2026-07-17T12:34:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e0fd4b026e648573d60db00b6f23dd441b291cd",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server image to v0.13.4",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T11:21:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7316fe9b37a8859233dcc6816c4083dbd548b655",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 0.13.4",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T11:19:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0260526013c7454af970b991c3b58ff5c20f715d",
          "body": "Fix: IM sendMessage stores canonical <uuid>@<host> for to_address.\n\nPreviously, when callers POSTed /api/messages with to_email='alice@x.com',\nthe IM DB row's to_address column was set to the raw email string. This\ncaused com inbox to return empty results because the inbox handler\nalready resolves ?\n[…]\nalls back to raw input if resolver is not configured or returns null\n(preserves pre-v0.13 behavior of accepting arbitrary recipient strings).\n\nTests: 5 new T1-T5, 300 total server tests pass / 0 fail.",
          "is_bot": false,
          "headline": "Merge branch 'fix/v0.13.4-im-send-canonical' (v0.13.4)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T11:19:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82cfca6547fb4f95eb7517cd9507fb2c101b0394",
          "body": "…ress (v0.13.4)\n\nPreviously, when callers POSTed /api/messages with to_email='alice@x.com',\nthe IM DB row's to_address column was set to the raw email string. This\ncaused com inbox to return empty results because the inbox handler\n(v0.13.2) already resolves ?email= to canonical <uuid>@<host> via\nfin\n[…]\n.\n\nBackward compatible: callers using to=<uuid>@<host> are unaffected;\nunknown recipients still store the raw input so we don't silently drop\nmessages addressed to external / unregistered identifiers.",
          "is_bot": false,
          "headline": "fix(server): im sendMessage stores canonical <uuid>@<host> for to_add…",
          "author_name": "v0.13.4-fix",
          "author_login": null,
          "committed_at": "2026-07-17T11:18:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "172bf945ac6d60ddd8e4e35fa846b145ea0d3c00",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server image to v0.13.3",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:55:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9c3e3405de396eb336c8398c4e85e1ac30f8c9f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 0.13.3",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:53:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6da5e136f1a00eb91ed6eb57a848c8db59840e5",
          "body": "Fix: com inbox URL prepended /api prefix.\nThe com inbox handler was hitting <baseUrl>/messages?email=... which\nfalls back to k8s ingress SPA HTML on production hostname, causing\n'Failed to parse JSON' errors. Now matches com send's /api/messages path.\n\nTests: 4 new (522 total pass), 1 line URL change in inbox.ts.",
          "is_bot": false,
          "headline": "Merge branch 'fix/v0.13.3-inbox-api-path' (v0.13.3)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:52:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb6bca070f2323acc2448d90e8870f2bbe69591d",
          "body": "The com inbox handler was calling <baseUrl>/messages?email=... which,\nwhen baseUrl resolves to the production hostname (e.g.\nhttps://bounty.tongagents.example.com via profile.api_base), gets\nrouted by k8s nginx ingress to the SPA HTML fallback, returning a\n200 OK with text/html body. The CLI then fa\n[…]\ntruction. The send.ts branch only runs when no profile and\nno --server-url is provided; for production usage callers will use\n--server-url or profile.api_base, both of which already use /api/messages.",
          "is_bot": false,
          "headline": "fix(cli): com inbox URL path uses /api/messages (v0.13.3)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:49:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "946edc68b16f0fc6efca2815d241b3e5dae97085",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server image to v0.13.2",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:32:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ce02e6e1f25dcb153d279c17b9dfda0908bd6e3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 0.13.2",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:30:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af5bdcdf3ecef3b924480ace8c556ba7791857ad",
          "body": "Fixes 2 inbox bugs discovered during v0.13.1 onboarding:\n1. server: im-routes inbox resolves ?email= via findAgentByEmailOrAddress\n   (was returning 403 because ownership check compared email local part\n   to JWT.sub directly, never resolving email to canonical <uuid>@<host>).\n2. cli: com inbox atta\n[…]\nrofileContext\n   (was calling bountyFetch without Bearer token, causing 401).\n\nTests: 919 pass (7 new), typecheck 0 errors, 4 bundles build OK.\nBackward compatible: ?address=<uuid>@<host> still works.",
          "is_bot": false,
          "headline": "Merge branch 'fix/v0.13.2-inbox-email-and-auth' (v0.13.2)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:30:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e097de3a16624094c84e45a70b15b10716409071",
          "body": "The com inbox handler was calling bountyFetch without including the\nJWT from ProfileContext / ~/.config/bounty/profiles/<active>.json (or\nthe legacy ~/.config/bounty/token file). With v0.13's default-on\ntoken check, the server returned 401 and 'bounty com inbox --email X'\ncould not read the inbox. C\n[…]\n profile.access_token, fetch receives Authorization: Bearer <token>\n  T6: without any token, fetch returns 200 and no process.exit(1)\n  Source: readAuthToken + Authorization wiring present in inbox.ts",
          "is_bot": false,
          "headline": "fix(cli): com inbox attaches Authorization header (v0.13.2)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:19:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac7bf4d5db85e1e1f1967a722f63537e19e1001f",
          "body": "The getMessages handler previously returned 403 Forbidden when callers\npassed ?email=<email> because the ownership check compared the email's\nlocal part against the JWT's agentId directly. The two never matched\n(email local part is 'alice' vs JWT sub is a UUID), so every\nauthenticated ?email= reques\n[…]\nes-inbox-email.test.ts (T1-T4):\n  T1: GET ?email=<own-email> → 200 + messages\n  T2: GET ?email=<other-email> → 403\n  T3: GET ?email=<email> no JWT → 401\n  T4: GET ?address=<uuid>@<host> (legacy) → 200",
          "is_bot": false,
          "headline": "fix(server): im inbox resolves email to canonical address (v0.13.2)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T10:19:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67772e5e3bfc651e9cb4c69c93ea8a86b42f7304",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 0.13.1",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T08:41:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8001800e8423115509e29e48be38c38b81a10611",
          "body": "Fix: com/* CLI commands now read profile.api_base when --server-url is absent.\n\nResolves v0.13.0 regression where users had to manually pass --server-url\neven when a profile with api_base was active. This brings com/* into\nalignment with auth/*, register-agent/*, and bounty-task/* commands.",
          "is_bot": false,
          "headline": "Merge branch 'fix/v0.13.1-com-read-profile-api-base' (v0.13.1)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T08:40:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b27ce6d83d7987d6c55c2af53f93f47abb13733",
          "body": "… (v0.13.1)",
          "is_bot": false,
          "headline": "fix(cli): com commands read profile.api_base when --server-url absent…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T08:40:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c10beaed8403a447c5362a8fb0262dfc317928ad",
          "body": "# Conflicts:\n#\tpackage.json",
          "is_bot": false,
          "headline": "Merge branch 'feat/v0.13-email-instead-of-uuid'",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T08:21:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db475d070663f898648722524d73d1e1654bc4ef",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server image to v0.13.0",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:53:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e83e9413a85350126718cc674c19936674febb34",
          "body": "- bounty-task-default-agent.test.ts: error message now mentions --email\n  (the v0.13 primary lookup key) in addition to --agent-address\n- bounty-task-address-flags.test.ts: X-Agent-Id header is no longer set\n  in v0.13 (server resolves identity via body.agentEmail/agentAddress\n  directly via findAgentByEmailOrAddress)\n- address-resolver.ts: reword a comment to avoid the no-deps-import\n  test's false-positive match on the literal string \"from \\\"...\\\"\"",
          "is_bot": false,
          "headline": "test: update legacy tests for v0.13 email-first contract",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:50:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fa948abdf480dcbb6d25825cfd82ff3426a52c6",
          "body": "- package.json: 0.10.0 → 0.13.0 (the worktree branched from a 0.10.x commit)\n- CHANGELOG.md: new [v0.13.0] section documenting the email-first API\n  contract, all 14 CLI flag additions, the new server helpers, and the\n  soft-breaking migration guide.",
          "is_bot": false,
          "headline": "chore(release): bump version to 0.13.0",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a546fd07e5a5133369597cdbd92405172430e528",
          "body": "21 new tests verify that:\n- All 8 changed CLI commands declare --email/-e flag\n- com/send.ts accepts --from-email/-F and --to-email/-T\n- com/inbox.ts prefers --email over --address in request URL\n- com/connect.ts WS probe uses ?email=\n- register-agent/credits/get/delete hit the new server endpoints\n- bounty-task/grab/submit send agentEmail in request body\n- com/send.ts handler forwards --from-email / --to-email via fetch",
          "is_bot": false,
          "headline": "test(cli): add v0.13 email-flag tests across all changed commands",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:43:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4b966631eaed7be69c6c12729e04c15c8a29599",
          "body": "…(v0.13)\n\n- com/send.ts: --from-email/-F, --to-email/-T (primary); --from/-f, --to/-t\n  remain as legacy address fallbacks\n- com/inbox.ts: --email/-e (primary); --address/-a legacy\n- com/connect.ts / disconnect.ts / addresses.ts: --email added\n- register-agent/{credits,get,delete}.ts: --email added \n[…]\nhe server resolves via findAgentByEmailOrAddress.\n- auth-routes: new GET /api/agents/by-email and DELETE /api/agents/by-email\n  endpoints so register-agent get/delete can resolve by email server-side.",
          "is_bot": false,
          "headline": "feat(cli): accept --email in com/register-agent/bounty-task commands …",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:41:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6624daa94381f1e75a8a7b65cd59e0132bf4bd9b",
          "body": "- bounty-routes: resolveActor accepts publisherEmail/agentEmail (primary)\n  with publisherAddress/agentAddress as fallback (v0.10 legacy)\n- im-routes: sendMessage accepts from_email/to_email (primary) and\n  normalises agent identifiers via the new helper\n- WS upgrade: accepts ?email= and resolves to\n[…]\ns added:\n- tests/server/bounty-routes-email-first.test.ts (9 tests)\n- tests/server/im-routes-email-first.test.ts (8 tests)\n- tests/server/ws-email-upgrade.test.ts (4 tests)\n\n162/162 server tests pass.",
          "is_bot": false,
          "headline": "feat(server): accept email as primary lookup (v0.13)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:25:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "450ef57cac8ed0e03c4591469ac43dadcf41466b",
          "body": null,
          "is_bot": false,
          "headline": "feat(server): add findAgentByEmail resolver (v0.13 email-first)",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T07:18:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d429efe267860a7768f31f52fba775907d4cd251",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 0.12.0",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T05:51:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2b824f2c5c79990c6aa3bb2d67b80eebafa060a",
          "body": null,
          "is_bot": false,
          "headline": "chore(deploy): bump bounty-server image to v0.12.0",
          "author_name": "roy-agent deploy",
          "author_login": null,
          "committed_at": "2026-07-17T03:30:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d232f4c02047c612fc18e16ebd2397aa0969fa04",
          "body": "两个修复:\n1. PVC ReadWriteOnce 卡死:strategy.type=Recreate\n2. 移除 BOUNTY_TOKEN_CHECK_ENABLED=false env(让 PR4 默认 ON 生效)\n\nCommit: f801200",
          "is_bot": false,
          "headline": "merge: deployment config fix (PVC + token env) into main",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T03:26:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c03711cfd436ed68d1b3b2f395fdb0dfc42ef0e",
          "body": "6 个 bounty-task 命令改造为使用 ProfileContext:\n- publish/grab/submit/complete/cancel/board\n- 用 ProfileContext.getApiBase() 获取 base URL\n- 用 ProfileContext.getAccessToken() 获取 token\n- 仍支持 --server-url / --auth-token 显式覆盖\n\n合并后 profile 机制对 bounty-task 命令族完整集成:\n- --profile <name> bounty-task board\n- BOUNTY_PROFILE=<name> bounty-task board\n- 都能正确使用 profile 的 api_base + token\n\nCommit: 971e159",
          "is_bot": false,
          "headline": "merge: bounty-task ProfileContext integration (PR7) into main",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T03:26:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "971e159e715d27adb9a012a91b632edac7ee2d67",
          "body": "PR7 of the profile mechanism (PR1-PR6 already in main). Bounty-task\ncommands (publish, grab, submit, complete, cancel, board) still used\nbountyConfig.apiUrl + resolveServerUrl, leaving ProfileContext\n\"half-integrated\" — `--profile noauth bounty-task board` would hit\nhttp://localhost:4000 instead of \n[…]\nase, NOT localhost:4000)\n  - --profile staging bounty-task board --server-url http://127.0.0.1:46666\n    → URL wins on --server-url (46666). Override precedence preserved.\n\nRefs: design doc / context.",
          "is_bot": false,
          "headline": "feat(bounty-task): adapt to ProfileContext for API base + token",
          "author_name": "roy-agent execute",
          "author_login": null,
          "committed_at": "2026-07-17T03:18:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8012006624bdd58e227b0301e386d2f37616b92",
          "body": "两个修复:\n1. PVC ReadWriteOnce 卡死:\n   - deployment 改 strategy.type=Recreate\n   - 单 replica 时无 maxSurge 仍可挂载新 PVC\n   - 解决 0 unavailable 限制\n2. 移除 BOUNTY_TOKEN_CHECK_ENABLED=false:\n   - PR4 默认已改为 ON\n   - 显式 false 干扰默认 ON 生效\n   - 清理冗余配置\n\n合并后:\n- bounty-server 重启时不会卡 PVC\n- 默认开启 token 鉴权(更安全)",
          "is_bot": false,
          "headline": "fix(deploy): PVC Recreate strategy + remove tokenCheck env override",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T03:02:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0664abe5169c43987bc976d8155687aa76a92676",
          "body": "PR3: auth commands adapted to ProfileContext + token migration\nPR4: HTTP token check default ON + BOUNTY_WS_AUTH_REQUIRED feature flag\nPR5: --help grouping (Quickstart / Bounty / General) + --all fallback\nPR6: docs (README + profile-guide.md + CHANGELOG)\n\n7 commits on feat/profile-mechanism-pr3-6\nTotal: ~1080 insertions across all PRs",
          "is_bot": false,
          "headline": "merge: profile mechanism completion (PR3-PR6) into main",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84fdd0b28c2703e92653303aee2dcc33341cd146",
          "body": "PR2: bounty profile * command group\n- add / list / show / use / remove / rename\n- 48/48 profile tests pass\n- 7 new test files\n- integration test (add → list/show → use → rename → remove)\n\n~10 commits on feat/profile-commands-pr2",
          "is_bot": false,
          "headline": "merge: profile commands (PR2) into main",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bcea80b2fcf189c006176cf0006e6049bfab6e6",
          "body": "PR1: --profile global flag + Profile file storage + Context\n- ProfileManager (atomic write, legacy token migration)\n- ProfileResolver (4-level priority chain)\n- ProfileContext (in-memory)\n- ProfileMiddleware (yargs middleware)\n- auth-token.ts adapted to read ProfileContext first\n- BOUNTY_TOKEN env var removed\n\n8 commits on feat/profile-mechanism-pr1:\n- ProfileManager / Resolver / Context / Middleware\n- 3 lib helpers (paths/types/schema/store/resolver/context)\n- +389 insertions, 8 deletions",
          "is_bot": false,
          "headline": "merge: profile mechanism (PR1) into main",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed5734ad88bddc9e4ee5f25eafbe855a4671b46e",
          "body": "PR6: Documentation for profile mechanism (PR1-PR6)\n\n新增:\n- docs/profile-guide.md (200 行完整指南)\n  - 概览 + 快速开始\n  - 配置文件详解\n  - 命令速查表\n  - 优先级链\n  - Token 迁移\n  - 安全性最佳实践\n  - 故障排查\n  - 与环境变量关系\n  - 备份和迁移\n  - 附录(默认值)\n\n修改:\n- README.md: 新增「用户身份(Profile)」章节 + Profile 命令示例 + 优先级链\n- CHANGELOG.md: [Unreleased] 段记录 Pro\n[…]\n  - Changed: 3 个改进\n  - Breaking Changes: BOUNTY_TOKEN env 移除 + Server 默认鉴权开启\n  - Migration: 从 v0.10 升级步骤\n\n完整 PR1+PR2+PR3+PR4+PR5+PR6 落地:\n- 48 个 profile 测试通过\n- typecheck green\n- main HEAD 未改变 (502261f)",
          "is_bot": false,
          "headline": "docs: add profile guide + README profile section + CHANGELOG entry",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:34:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "64802544ace2f2f99bd767c002001861d7011305",
          "body": "PR5: --help grouping with --all fallback\n- 5 PR5 tests pass (help-groups.test.ts)\n- typecheck green\n- main HEAD unchanged",
          "is_bot": false,
          "headline": "feat(cli): group --help output with Quickstart/Bounty/General sections",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:32:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea6742b37284b9658cb2bac3891495615efd07da",
          "body": "…UIRED feature flag\n\nPR4 security posture change:\n\n- HTTP token check now defaults to ON (was: OFF). Production deployments get\n  minimum-access control without extra env configuration. Dev/test scenarios\n  opt out with BOUNTY_TOKEN_CHECK_ENABLED=false (or constructor DI override).\n- WebSocket auth \n[…]\ntests covering flag defaults +\n  WS upgrade 401 paths (missing header, bad token) under flag=true\n\nVerification:\n- bun run typecheck → 0 errors\n- bun test tests/server --parallel 4 → 130 pass / 0 fail",
          "is_bot": false,
          "headline": "feat(server): flip token check default to ON + add BOUNTY_WS_AUTH_REQ…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:23:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fb20a5ed807cb6a0b25ffcef213d3bd8dba9a62",
          "body": "…eOptions\n\n- Add __storeOptions pass-through so profile writes target temp dirs in tests\n- Add tests/cli/auth/{login,logout,refresh}.test.ts covering happy path + edge cases\n- Keep PR3 invariant: no BOUNTY_TOKEN env reads; api_base resolves via resolveProfileApiBase",
          "is_bot": false,
          "headline": "feat(auth): wire login/logout/refresh through ProfileContext + __stor…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:09:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d57a7ca0d3658920befa350e53b517288b899ca",
          "body": null,
          "is_bot": false,
          "headline": "fix(auth): minor login.ts profile integration tweak",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T02:00:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df29e38b9af9e8849a7fb75df1f5679c67bb1ce6",
          "body": "PR3 续 commit:\n- refresh.ts: 完整实现(含 http 请求 + 写回 profile)\n- 4 个 auth server-url 测试更新(适配 ProfileContext)\n- 2 个 lib 辅助测试(profile-api-base / profile-auth-writer)\n\n测试:typecheck green",
          "is_bot": false,
          "headline": "feat(auth): complete auth command profile integration + tests",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52c96e9ce5bcddaa41a26d8f7bbab9921f6f6671",
          "body": "…eGlobalConfig catch)",
          "is_bot": false,
          "headline": "fix(profile): complete verify feedback (rename IO + existsSync + writ…",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:57:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1e9cef4fafafda14c0c176a66aa42be3b213125",
          "body": "PR3 of bounty profile mechanism (continuation of PR1+PR2):\n\n改造 6 个 auth/* 命令使用 ProfileContext:\n- login.ts: 读 profile.api_base + 写回 access_token\n- logout.ts: 清空 profile.auth 中的 token\n- status.ts: 显示当前 profile + token 状态\n- register.ts / send-code.ts: 使用 profile.api_base\n- refresh.ts (new): 用 refresh_t\n[…]\ns (3/3 pass)\n\n附带清理:\n- 移除 remove.ts 的旧测试(在 v2 设计变更后失效)\n\n设计原则:\n- Profile 仅 client-side 抽象\n- 不读 BOUNTY_TOKEN env(沿用 PR1)\n- token 迁移保留 legacy 文件作为兜底\n- Linux/macOS only\n\n测试:typecheck green, auth + lib 测试通过",
          "is_bot": false,
          "headline": "feat(auth): adapt auth commands to ProfileContext + token migration",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:54:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4024787bae7811f4fe97be63db69ec25268464fd",
          "body": null,
          "is_bot": false,
          "headline": "fix(profile): surface IO failures during profile delete",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:44:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19d2f3a0822fec55c0b4fa6842f00db466e3347a",
          "body": null,
          "is_bot": false,
          "headline": "fix(profile): drop email from list --json summary",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:42:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84d918a6d3b58f6a6421c53b4af2357531f191c1",
          "body": null,
          "is_bot": false,
          "headline": "fix(profile): honour global --profile override in list/show/remove",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:41:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b5ae26977a71135859d34d6c0949ce9f50e9eae",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): register profile command group",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:27:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f63178b57f7bae55559a5213e4ede55b8439eb5",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile command group parent and integration test",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:26:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8afa8bd25fc0a2b534379276833c2de2577602a1",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile rename command",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:23:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6e2def296b41a056dd4ebdbe245f3ff83a77d38",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile rename command",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:23:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739520b3480affe7b0b9fd5137419aaa8e4f698f",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile use command",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:20:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73dc09f50f035187bae3e217d6908302aaeed717",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile use command",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:19:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc4ebea69eb4120fcce43880b7d7aa391fa5a5f6",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile show command",
          "author_name": "roy-agent",
          "author_login": null,
          "committed_at": "2026-07-17T01:18:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dce1899202a266b94c5f54842b3587bfa725a0f",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile list command",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:16:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf086954301b8ec9f883812439292908990f0861",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile <name> command",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T01:14:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dae006ee0b50fc471d1f617a981fbccd713291eb",
          "body": null,
          "is_bot": false,
          "headline": "feat(auth-token): prefer ProfileContext and remove token env fallback",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:41:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ccf36278721d73b738180d9d33cd712e9840fde",
          "body": "… env\n\nPR1 implements the profile mechanism so the CLI no longer relies on\nprocess.env.BOUNTY_TOKEN as a primary auth source. Instead, every command\nruns through profileMiddleware (yargs middleware) which sets\nProfileContext, and readAuthToken() now:\n\n  1. Returns ProfileContext.getAccessToken() if \n[…]\nstill works (back-compat for bounty-http / soft-auth)\n\nFiles:\n  - src/cli/lib/auth-token.ts: ProfileContext import + priority check\n  - tests/cli/auth-token-read.test.ts: 4 new cases (9 total in file)",
          "is_bot": false,
          "headline": "feat(auth): read token from ProfileContext first, remove BOUNTY_TOKEN…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:40:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "421e237cc59add13c1eaacdd3b7ad21947a4356e",
          "body": "- Add global --profile / -P string option (requiresArg: true)\n- Wire profileMiddleware into the yargs middleware chain so every\n  command runs through the profile resolver before its handler runs\n- Tests live in tests/cli/profile-option.test.ts (2 cases) and assert\n  cli.ts wires the option, alias, global flag, and middleware",
          "is_bot": false,
          "headline": "feat(cli): register --profile/-P global option and middleware",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:38:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6855162edfad77dc9abe8ef364d6fe3e7f874ef",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add global profile middleware",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:35:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94bd60984077910df82402cafa1df70fc73fd967",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add in-memory profile context",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:33:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c380f5d11162c7028190975c02c554e3c07230b",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add four-level profile resolver",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9b75ca53026918ecaa9a669957b91230701ca6a",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add profile file store with atomic writes",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:29:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5754438a6be713271f71faaab318d48765f14430",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): add paths types and Zod schemas",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-17T00:26:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "502261f90cacd5f6e43dc9511e969f34e10dae05",
          "body": "…10.0 npm release)\n\n@ai-setting/agent-bounty-standalone@0.10.0 was published with binaries\nbuilt BEFORE v0.10.0 commit (cdd4714). The binaries lacked all BREAKING\naddress-unification flag changes — --publisher-id / --agent-id were\nstill accepted, --*-address was rejected.\n\n0.10.0 standalone deprecat\n[…]\nected (invalid UUID)\n\nRoot package @ai-setting/agent-bounty@0.10.0 unaffected (TypeScript source\npublishes dist/*.js built at 7月 12 10:40 post-merge — verified\npublisherAddress references in tarball).",
          "is_bot": false,
          "headline": "chore(release): standalone 0.10.1 rebuild (fix stale binaries from 0.…",
          "author_name": "dongzhaokun",
          "author_login": "gddzhaokun-arch",
          "committed_at": "2026-07-12T02:49:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 11,
      "commits_last_year": 321,
      "latest_release_at": "2026-07-18T04:04:08Z",
      "latest_release_tag": "v0.14.2",
      "releases_from_tags": true,
      "days_since_last_push": 5,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.9
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@ai-setting/agent-bounty",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "ai-agent",
            "bounty",
            "task",
            "reward",
            "mail",
            "communication",
            "escrow",
            "smtp",
            "token-toggle"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@ai-setting/agent-bounty",
          "is_deprecated": false,
          "latest_version": "0.14.2",
          "repository_url": "https://github.com/ai-setting/ai-agent-bounty",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1523,
          "first_published_at": "2026-06-06T07:43:58.904000Z",
          "latest_published_at": "2026-07-18T03:57:01.661000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@ai-setting/agent-bounty-standalone",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@ai-setting/agent-bounty-standalone",
          "is_deprecated": false,
          "latest_version": "0.14.2",
          "repository_url": "https://github.com/ai-setting/ai-agent-bounty",
          "versions_count": 19,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2039,
          "first_published_at": "2026-07-09T02:48:28.311000Z",
          "latest_published_at": "2026-07-18T03:58:00.891000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json",
        "web/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 27647,
      "source_files_sampled": 283,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "bounty-standalone/package.json",
        "package.json",
        "web/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "nodemailer",
            "direct": true,
            "version": "8.0.11",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.1,
            "advisory_ids": [
              "GHSA-p6gq-j5cr-w38f"
            ],
            "fixed_version": "9.0.1",
            "advisory_count": 1,
            "oldest_advisory_days": 34
          },
          {
            "name": "uuid",
            "direct": true,
            "version": "9.0.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-w5hq-g745-h8pq"
            ],
            "fixed_version": "13.0.1",
            "advisory_count": 1,
            "oldest_advisory_days": 91
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2,
          "moderate": 1
        },
        "advisory_count": 3,
        "affected_count": 3,
        "assessed_count": 330,
        "malicious_count": 0,
        "assessed_package": "npm:@ai-setting/agent-bounty@0.14.2",
        "unassessed_count": 0,
        "direct_affected_count": 2
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@ai-setting/roy-agent-cli",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.110"
        },
        {
          "name": "@ai-setting/roy-agent-coder-harness",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.50"
        },
        {
          "name": "@ai-setting/roy-agent-core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.102"
        },
        {
          "name": "@types/ws",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.18.1"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.3.0"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "nodemailer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.7"
        },
        {
          "name": "uuid",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "yargs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.7.2"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.22.4"
        },
        {
          "name": "react",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "react-dom",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "react-router-dom",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.26.2"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "gddzhaokun-arch",
          "commits": 282,
          "avatar_url": "https://avatars.githubusercontent.com/u/240827957?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "14 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e64a45c5b7314f675c907a18838136c9a253e8c7",
        "ran_at": "2026-07-23T12:46:23Z",
        "aggregate_score": 3.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T04:04:25Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ai-setting/ai-agent-bounty",
    "host": "github.com",
    "name": "ai-agent-bounty",
    "owner": "ai-setting"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 41,
        "vitality": 78,
        "community": 24,
        "governance": 32,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 78,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 321,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "321 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 321
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 11,
              "latest_release_tag": "v0.14.2",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "11 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "@ai-setting/agent-bounty",
                "@ai-setting/agent-bounty-standalone"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3562
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,562 downloads/month across npm",
                "points": 47.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3562,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 32,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "ai-setting",
              "public_repos": 5,
              "account_age_days": 168
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of ai-setting",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "ai-setting"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 6.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@ai-setting/agent-bounty",
                "@ai-setting/agent-bounty-standalone"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "19 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 3.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "14 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Matched the npm:@ai-setting/agent-bounty@0.14.2 runtime dependency closure — what installing the published package pulls in — 330 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@ai-setting/agent-bounty@0.14.2",
                  "assessed": 330
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "source": "osv",
              "advisories": 3,
              "affected_packages": 3,
              "assessed_packages": 330,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2, moderate 1",
              "direct_affected_packages": 2
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "2 affected: nodemailer 8.0.11 (high 7.1), uuid 9.0.1 (high 7.5)",
                "points": 11.9,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "nodemailer 8.0.11 (high 7.1), uuid 9.0.1 (high 7.5)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.14 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.14 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 91 days ago",
                "points": 33.7,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 91
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 330,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 52,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json",
                "web/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json, web/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json, web/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 27647,
              "source_files_sampled": 283,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/283 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 283,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T12:46:28.490169Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/ai-setting/ai-agent-bounty.svg",
  "full_name": "ai-setting/ai-agent-bounty",
  "license_state": "absent",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.