Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-23 17:47 UTC

alex60217101990 / qdf

Quick Data Format — fast, compact binary serialization for Go. encoding/json-style API, columnar per-column codecs, up to 68% smaller than Protobuf.

GoMIT★ 26 зірок⑂ 0 форківз трав. 2026 р.Переглянути на GitHub ↗

alex60217101990/qdf має індекс здоров’я 65 зі 100, що відповідає смузі «Помірний». Найвищий показник — Engineering Quality (84/100), найнижчий — Community & Adoption (39/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

65
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

65
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

alex60217101990Особистий обліковий запис
4 підписники44 публічні репозиторіїз лист. 2017 р.

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/alex60217101990/qdfv0.1.2-125 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

76Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
6.2/36Ритм комітів — 9/52 тижнів із комітами
18/18Обсяг комітів — 822 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year822
human_commit_share0,96
days_since_last_push5
active_weeks_last_year9
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 12 релізів
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~4,7 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count12
latest_release_tagv0.1.2
releases_from_tagsні
days_since_latest_release5
mean_days_between_releases4,7
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

39У зоні ризику · 18% загального індексу
Як обчислюється оцінка
22.7/60Зірки — 26 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 1 спостерігачів
Використані вхідні дані
forks0
stars26
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateтак

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

53Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
37.8/38.3Прийняття PR — злито 162/164 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/3 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs162
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs2
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue. Залишкові ваги перенормовано.

Власність та опіка

49У зоні ризику
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
5/25Охоплення власника — 4 підписників у alex60217101990
24/25Послужний список — 44 публічних репозиторіїв, вік облікового запису ~8 р.
Використані вхідні дані
followers4
owner_typeUser
is_verified
owner_loginalex60217101990
public_repos44
account_age_days3 178
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 12 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/alex60217101990/qdf
ecosystemsgo
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

84Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 13 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — .golangci.yml
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 3 out of 3 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні

Документація

85Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
10/10Теми — 12 тем
10/10Wiki
Використані вхідні дані
topicsbinary-serialization, codec, columnar, compression, data-format, encoding, go, golang, messagepack, protobuf, serialization, serialization-library
has_wikiтак
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

72Добрий · 16% загального індексу

Стан безпеки

65Помірний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
6/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 3 out of 3 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/3 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6,5
Виключено з оцінювання (немає даних або не застосовно): packaging, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
0/25Непрямі залежності без відомих сповіщень — транзитивний набір не відокремлюється від залежностей розробки й тестування в цьому обсязі
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages9
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Непрямі залежності без відомих сповіщень, Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено 9 резолвлених залежностей із OSV. Цей репозиторій не публікує пакета, який резолвить індекс, тож натомість оцінено граф залежностей репозиторію. Цей граф змішує закріплені версії для розробки й тестування зі справді постачаними залежностями, тож оцінюються лише задекларовані runtime-залежності; транзитивні знахідки подаються як контекст і в оцінку не входять. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

73Добрий · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 95 з 96 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
12.6/18Розгортання однією командою — bench/go.mod, cmd/qdf-bench/go.mod, cmd/qdf-vecbench/go.mod (домовленість інструментарію, без раннера задач)
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — .golangci.yml
11/11Статична перевірка типів — Go (статично типізована)
10/10Відтворюване середовище — lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
8/8Автоматизоване супроводження — 2 з останніх 100 комітів — автоматичні оновлення залежностей
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configs
agent_commit_share0
toolchain_manifestsbench/go.mod, cmd/qdf-bench/go.mod, cmd/qdf-vecbench/go.mod, cmd/qdfgen/go.mod, go.mod, internal/codegen_test/go.mod
dependency_bot_commit_share0,02
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
54.5/55Керовані розміри файлів — 4/409 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes101 562
source_files_sampled409
oversized_source_files4
Як обчислюється оцінка
40/40Схема API (OpenAPI/GraphQL/proto) — bench/pb/bench.proto
0/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalні
api_schema_filesbench/pb/bench.proto

Ключові факти

26зірок GitHub
1контриб'юторів
822комітів за останні 12 місяців
5днів від останнього пушу
12релізів
1бас-фактор
0відкритих issue
Goпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

OpenSSF Scorecard 6.5 / 10
6.5сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-23 17:47 UTC

10Binary-Artifactsno binaries found in the repo
8Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests3 out of 3 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/3 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackagingpackaging workflow not detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Прямі залежності 6
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/alex60217101990/qdfv0.0.0bench/go.mod
Gogithub.com/google/flatbuffersv25.12.19+incompatiblebench/go.mod
Gogithub.com/vmihailenco/msgpack/v5v5.4.1bench/go.mod
Gogoogle.golang.org/protobufv1.36.11bench/go.mod
Gogithub.com/modern-go/reflect2v1.0.2go.mod
Gogolang.org/x/sysv0.47.0go.mod
Усі залежності 9

Повний розв'язаний набір залежностей із графа залежностей GitHub: 5 прямих і 4 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
Gogithub.com/google/flatbuffersv25.12.19+incompatibleпряма
Gogithub.com/modern-go/reflect2v1.0.2пряма
Gogithub.com/vmihailenco/msgpack/v5v5.4.1пряма
Gogolang.org/x/sysv0.47.0пряма
Gogoogle.golang.org/protobufv1.36.11пряма
Gogithub.com/vmihailenco/tagparser/v2v2.0.0непряма
Gogolang.org/x/modv0.38.0непряма
Gogolang.org/x/syncv0.22.0непряма
Gogolang.org/x/toolsv0.48.0непряма
Сповіщення про залежності 0

Цей репозиторій не публікує пакета, який розпізнає індекс, тож оцінено його власний граф залежностей — 9 пакетів, серед яких є й піниї розробки та тестування, що ніколи не постачаються: 0 мають відомі сповіщення, з них 0 прямі.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "binary-serialization",
        "codec",
        "columnar",
        "compression",
        "data-format",
        "encoding",
        "go",
        "golang",
        "messagepack",
        "protobuf",
        "serialization",
        "serialization-library"
      ],
      "is_fork": false,
      "size_kb": 23603,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 2651270,
        "Shell": 10847,
        "Assembly": 46871
      },
      "pushed_at": "2026-07-18T07:36:49Z",
      "created_at": "2026-05-24T17:16:30Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T07:20:14Z",
      "description": "Quick Data Format — fast, compact binary serialization for Go. encoding/json-style API, columnar per-column codecs, up to 68% smaller than Protobuf.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "alex60217101990",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/33520849?v=4",
      "created_at": "2017-11-09T14:39:20Z",
      "is_verified": null,
      "public_repos": 44,
      "account_age_days": 3178
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-07-18T07:23:37Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-07-02T08:44:09Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-02T06:38:30Z"
        },
        {
          "tag": "v0.0.9",
          "kind": "patch",
          "published_at": "2026-06-22T14:08:01Z"
        },
        {
          "tag": "v0.0.8",
          "kind": "patch",
          "published_at": "2026-06-20T22:03:59Z"
        },
        {
          "tag": "v0.0.7",
          "kind": "patch",
          "published_at": "2026-06-15T05:43:31Z"
        },
        {
          "tag": "v0.0.6",
          "kind": "patch",
          "published_at": "2026-06-14T14:49:30Z"
        },
        {
          "tag": "v0.0.5",
          "kind": "patch",
          "published_at": "2026-06-11T12:34:01Z"
        },
        {
          "tag": "v0.0.4",
          "kind": "patch",
          "published_at": "2026-06-08T18:22:26Z"
        },
        {
          "tag": "v0.0.3",
          "kind": "patch",
          "published_at": "2026-06-05T18:36:23Z"
        },
        {
          "tag": "v0.0.2",
          "kind": "patch",
          "published_at": "2026-06-05T12:07:54Z"
        },
        {
          "tag": "v0.0.1",
          "kind": "patch",
          "published_at": "2026-06-02T11:45:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e55cd5b1a2b0798e20d8637cc71cfaa9f4d640a3",
          "body": "delta_columnar.go: remove trailing spaces before inline comments in nChanged varint patch.\nqpack_rle_bench_test.go: normalize const-block tab alignment.\nstate.go: normalize mapShapeBinding field alignment after betteralign reorder.\nqpack_pfor_test.go: pre-allocate bufU/bufI with capacity 8+len(maxU64Varint)+1\n  so the two append calls below never reallocate (prealloc linter).",
          "is_bot": false,
          "headline": "style: fix golangci-lint gofmt and prealloc findings",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "362aa8a3dc88588388b56cf49185dc96169712cf",
          "body": "…rder\n\nbatchPlan: mirrorSlicePtr (sync.Pool) promoted to lead → ptrdata 120→104 B.\nmapShapeBinding: valType (reflect.Type, 2-ptr interface) promoted to lead → ptrdata 64→48 B.\nThree example structs reordered (pointer fields before scalars).\n\nencState and Encoder are annotated betteralign:ignore — th\n[…]\nirst cache line) or\nsize-tuned (bools packed last to avoid padding), so GC-ptrdata reordering\nwould regress throughput.\n\nAll tests pass. betteralign converges in two passes with no remaining findings.",
          "is_bot": false,
          "headline": "perf(structs): reduce GC scan-work estimate via betteralign field reo…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd325d83a662a4c4c9770234a2090ddc402cf10a",
          "body": "…e_scratch",
          "is_bot": false,
          "headline": "fix(rle): apply subtraction guard to *Into decoders in columnar_decod…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4b34632bd5a946bf361eaf680ae357088ec4e28",
          "body": "…ncode\n\nAdd fsstCachedTbl/*fsstBatchCount* to Encoder and reuse the trained symbol\ntable for up to fsstReuseInterval (8) consecutive same-encoder batches before\nretraining. Avoids the ~140-311 µs per-batch Build() cost on the streaming\npattern where one Encoder is reused across many Marshal calls.\n\n\n[…]\n42% ns/op (209 µs -> 91 µs), p=0.000, n=10 interleaved,\nApple M5 Pro arm64. Allocs/op unchanged (2); B/op +2198% expected (Clone\namortises ~14 KB of symbols/cands over 9 batches -> ~1.7 KB/batch avg).",
          "is_bot": false,
          "headline": "perf(fsst): cache trained symbol table across batches for streaming e…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1340fff5f8db2057787f32802bb63da48fd9545",
          "body": "…codeCompressible\n\nMeasure full encode path for non-compressible (random-byte) and compressible\n(URL-like) corpora. Used to gate any future FSST early-exit probe against\nboth the ≥15% improvement requirement and the no-regression requirement.",
          "is_bot": false,
          "headline": "test(fsst): add BenchmarkFSSTEncodeIncompressible and BenchmarkFSSTEn…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "518e47b1039305674f0a68e27a43794f953e63f8",
          "body": "… broadcast\n\nApply the copy-doubling pattern to all four RLE fill loops:\n- readPackedRLEUint64Slice / readPackedRLEInt64Slice in qpack_rle.go\n- readPackedRLEUint64SliceInto / readPackedRLEInt64SliceInto in columnar_decode_scratch.go\n\nThe idiom writes the first element then doubles via copy(), routin\n[…]\nPackedRLEUint64Slice) show only ~5% end-to-end\nimprovement because make() zeroing dominates timing; the Into hot path (no\nallocation, reused scratch buffer) is where the gain is measured and material.",
          "is_bot": false,
          "headline": "perf(rle): replace scalar fill loop with copy-doubling idiom for NEON…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c2171df5e276e3d8d8dec1b0177ea2b9862e0d81",
          "body": "Single-pass collect-sort-encode for string/int/uint/bool canonical map\nkeys. A pre-allocated reflect.ArrayOf slab holds all n values; each slot\nis filled via SetIterValue (zero per-key alloc). Eliminates the old\nemit-closure pattern that called rv.MapIndex per key, which triggers\nreflect.unsafe_New \n[…]\ndeCanonicalMap, 64-key map[string]rec, n=10):\n  allocs/op  76 → 6     -92.11%  (p=0.000)\n  ns/op      5.58µ → 4.79µ -14.19%  (p=0.000)\n  B/op       4526 → 4141  -8.51%   (p=0.000)\n  Apple M5 Pro arm64",
          "is_bot": false,
          "headline": "perf(reflect): replace MapIndex with SetIterValue in encodeMapCanonical",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c95c9bba02517df46f4f15e6a36c4dd9fe9fee79",
          "body": "…iminate per-key heap alloc\n\nReplace rv.MapIndex(keyHolder) in encodeStringMapShaped's emitValues loop with\na single MapRange pass using SetIterValue into pre-allocated per-shape value slots\n(mapShapeBinding.valSlots). On the hot fast path this merges the old two-step\nhasAll (MapRange) + emitValues \n[…]\ns slots while emitSlotsOrdered is actively iterating them.\nemitSlotsOrdered uses index-based access (not a pointer) so that inner\ndeclares which reallocate st.mapShapes don't create dangling pointers.",
          "is_bot": false,
          "headline": "perf(reflect): replace MapIndex with SetIterValue in emitValues to el…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8b5be66b7d5659828623254e4f2322d78ec2e2e",
          "body": "…all alloc",
          "is_bot": false,
          "headline": "perf(rans): pool encode scratch buffer via bufpool to eliminate per-c…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5b7d03a4c13a9a0507f6a81ee77676318968137",
          "body": "…te heap escape\"\n\nThis reverts commit 144b443aa58ef6552bba6fe79c93d426ef49dc75.",
          "is_bot": false,
          "headline": "Revert \"perf(delta): promote noop closure to package-level to elimina…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "569b5c3771f3f551fd61ddc5c8cb2d869cc479a7",
          "body": "…escape",
          "is_bot": false,
          "headline": "perf(delta): promote noop closure to package-level to eliminate heap …",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c774561a8b603e6c037449ea20916e1375665e8a",
          "body": "…s >=128 columns\n\nThe placeholder-patch body[colCountPos] = byte(nChanged) truncated any\nnChanged value >=128 to a single byte with the high bit set; the varint\ndecoder (readUvarint) then consumed it as a continuation byte, producing\ngarbage. diffColumnarEligible previously guarded this with a hard \n[…]\ns both widths without change.\n\nAdd TestColDiff128ColsRoundTrip: 130-field struct, all columns changed\n(nChangedCols=130), verifies tagColSlicePatch is used and round-trip\nproduces the original values.",
          "is_bot": false,
          "headline": "fix(delta): use 2-byte padded uvarint for nChangedCols when struct ha…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f99a9e9c67af4b4bdd1bc88fa45d864c001eeb97",
          "body": null,
          "is_bot": false,
          "headline": "fix(pfor): prevent exception-delta uint64->int cast overflow in decode",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cd283c7965bdcc8530bb67bb4ef99c2fc100b97",
          "body": "Replace addition-based guard (uint64(idx)+runLen > uint64(n)) with\nsubtraction-based (runLen > uint64(n-idx)). The addition wraps to 0\nwhen idx=1 and runLen=MaxUint64, letting a crafted 10-byte uvarint\nbypass the check. With idx reset to 0, a subsequent valid run fills\nthe entire output slice and re\n[…]\nidx<=n guarantees\nn-idx never underflows. Apply to both uint64 and int64 variants.\n\nRegression test encodes (run1=valid, run2=MaxUint64-bypass, run3=fill-all)\nand asserts ErrInvalidLength is returned.",
          "is_bot": false,
          "headline": "fix(rle): prevent uint64 overflow bypass in run-length bounds guard",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-18T07:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bffc9a38e8c241e245dbe784ee8face58ebcc30a",
          "body": null,
          "is_bot": false,
          "headline": "perf(BenchmarkDiffKeyed): optimize loop structure for benchmarking",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ec8c997ad6f12f49adabb65ef8cbb1870f9e834",
          "body": null,
          "is_bot": false,
          "headline": "perf(BenchmarkDiffMap): optimize map copying with maps.Copy",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "099c275c106094eb239e961e38bd49c1ed12f577",
          "body": null,
          "is_bot": false,
          "headline": "style(hadamard): fix gofmt double blank line",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94a7132a2e65443629f6846fdf631a169271be82",
          "body": null,
          "is_bot": false,
          "headline": "style(gorilla): remove stale double blank line after readBits",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5523232bddac4b2c6949cae623be38add4642458",
          "body": "…ar kernel\n\nMoves fwht() out of hadamard.go into platform files:\n- hadamard_generic.go (//go:build !arm64): original scalar triple-loop\n- hadamard_arm64.go + hadamard_arm64.s: ARM64 asm kernel\n\nThe ARM64 kernel uses a 4-pair unrolled inner loop (F0–F15) backed by a\n2-pair tier for the h=2 remainder.\n[…]\n\n\nNote: Go ARM64 assembler does not support FADDD/FSUBD with 3-operand\nvector arrangements (C_ARNG×C_ARNG→C_ARNG illegal combination). The\n4-pair scalar unroll achieves equivalent ILP on Apple M CPUs.",
          "is_bot": false,
          "headline": "perf(hadamard): vectorize FWHT butterfly with ARM64 asm unrolled scal…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09786d2f6327f2f2330bb8ab3bb513da7afef368",
          "body": null,
          "is_bot": false,
          "headline": "perf(gorilla): replace per-bit writeBits loop with bulk byte-packing",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2fad7f97a80376793fb535df6adc5a9feed7efe",
          "body": "…bulk rewrite)",
          "is_bot": false,
          "headline": "style(gorilla): remove unused btoU64 helper (now dead after readBits …",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6de43c5ac4aef142518f5d74c7d1482095b185b7",
          "body": null,
          "is_bot": false,
          "headline": "perf(gorilla): replace per-bit readBits loop with bulk byte-extraction",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-17T17:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66f8b4a431fd5b7de5e09a2dcd342ab0edaadaa4",
          "body": "…nvert)",
          "is_bot": false,
          "headline": "style: fix gofmt in pfor test and remove redundant uintptr cast (unco…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deea21fc31999f274c8ef21d865f260c8fe8efe2",
          "body": "…orruption",
          "is_bot": false,
          "headline": "fix(lossyvec): cap flat-slab sub-slices to prevent cross-row append c…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b4370130bacd291c30428b8a8604b9f66beab14",
          "body": "…ctor make",
          "is_bot": false,
          "headline": "perf(vecquant): single flat alloc for Decode output instead of per-ve…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "599f587f5b6ce937daf142e11cc23457331e93fe",
          "body": null,
          "is_bot": false,
          "headline": "perf(lossyvec): pre-alloc flat float32 slab in decode scatter loop",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59f0a4b972eb0fa831a254f5b65bf7e31aa25410",
          "body": null,
          "is_bot": false,
          "headline": "perf(decode): inline tagUint cases in decodeInt to avoid double dispatch",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3475f352f535dc279366f9f2bc14d241ea1fb238",
          "body": "…pe path\n\nReplace the string(kb) copy in decoder_skip.go's tagMapShape handler with\nd.keyCache.Make(kb), matching the pattern used everywhere else in the\ndecoder (map_shape.go:153, reflect_encode.go:1631, maps_fast_generated.go).\n\nKeys shared across multiple map-shape declarations in a single decode\n[…]\ns with\noverlapping keys pay zero allocs for those keys.\n\nBenchmarkSkipMapShape (n=10 interleaved, Apple M5 Pro arm64):\n  allocs/op: 25 → 17  (-32.00%, p=0.000)\n  B/op:    1088 → 1044 (-4.22%, p=0.000)",
          "is_bot": false,
          "headline": "perf(decode): use keyCache.Make instead of string(kb) in skip map-sha…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b00414365bb048ef98e4a160531d65048a765e5a",
          "body": "…10→0x08)",
          "is_bot": false,
          "headline": "fix(bitpack/arm64): correct stale UMOV D[0] imm5 in comment block (0x…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86ef3b937ebbf6811f928fa0c840b9289f6dd5f6",
          "body": "Replace scalar Pack() dispatch in packBits10/12/14/20 with ARM64 NEON\nkernels. Each kernel processes 4 values per iteration (2 for 20-bit):\nload into two 128-bit registers, mask via VAND, per-lane left-shift via\nSSHL with pre-loaded shift vectors, VORR+EXT+VORR to OR all lanes into\nlane 0, UMOV to G\n[…]\ned, geomean -86% ns/op (p=0.000 for all widths):\n  PackWidth10: 830 ns -> 124 ns  -85%\n  PackWidth12: 1263 ns -> 127 ns -90%\n  PackWidth14: 988 ns -> 138 ns  -86%\n  PackWidth20: 1046 ns -> 173 ns -83%",
          "is_bot": false,
          "headline": "perf(bitpack/arm64): NEON variable-width pack for 10/12/14/20-bit",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "752158be8b502bfdd8604f51acc3f6871c021461",
          "body": "…t loops",
          "is_bot": false,
          "headline": "perf(bitpack/arm64): NEON packBits8/16/32 replacing scalar per-elemen…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "293d50c43977e621ed3bef65ee6909441599f91b",
          "body": "Replace the 1-bool-per-iteration scalar accumulator with a NEON kernel\nthat packs 8 bools per cycle. VLD1 loads 8 bool bytes, VDUP+VAND\nsanitises LSBs, MUL multiplies each lane by its bit-position weight\n(1,2,4,8,...,128), ADDV reduces to the packed byte, ST1 stores one\nelement directly to dst. WORD\n[…]\nd ST1 since Go's\narm64 assembler lacks those vector mnemonics natively.\n\nbenchstat n=10 interleaved on M5 Pro:\n  PackBoolsLSB: 4296ns → 440ns  −89.8%  p=0.000\n  (909 MB/s → 8876 MB/s, ~10× throughput)",
          "is_bot": false,
          "headline": "perf(bitpack/arm64): NEON 8-wide PackBoolsLSB replacing scalar loop",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0537df2ffba75582f025b31eba7fd05b4e47a8e9",
          "body": "…ch field\n\nKeyed-slice diffs with n > keyedLinearMax (32) called make(map[string]struct{},n)\non every invocation. For n=50 this allocates an initial bucket array plus\noverflow buckets — 3 heap allocs and ~1835 bytes per diff call.\n\nAdd enc.newKeyIdx (map[string]struct{}) and enc.newKeyIdxBusy to Enc\n[…]\n means allocate locally.\n\nBenchmarkDiffKeyed (n=50, OptBalanced, n=10 interleaved):\n  allocs/op: 11 → 8  (-27%, p=0.000)\n  B/op:    2067 → 232  (-89%, p=0.000)\n  sec/op:  5.03µ → 4.70µ  (-7%, p=0.001)",
          "is_bot": false,
          "headline": "perf(delta): pool new-key seen-map in hasDupNewKeys via encoder scrat…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5e01ae7754404af7574ff88379dc991e28a444c",
          "body": "Change canonSortedMapKeys from returning []reflect.Value (N allocs) to\nan inline callback iterator (1 alloc). A single reflect.Value holder is\nallocated once per call and reused via SetString/SetInt/SetUint for each\nsorted key, matching the pattern in reflect_encode.go's encodeMapCanonical.\n\nRemoves\n[…]\nvalues throughout fn's execution.\n\nBenchmarkDiffMap (16-key map[string]int, OptCanonical, n=10 interleaved):\n  allocs/op: 233.5 → 202.0  -13.49% (p=0.000)\n  sec/op:      5.98 → 5.49µ  -8.10% (p=0.000)",
          "is_bot": false,
          "headline": "perf(delta): eliminate per-key reflect.New in canonSortedMapKeys",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47e28b17bf8b9800f11217e68ea3aa718a00e766",
          "body": "… during pack\n\nWhen plan.exc > 0 the old path re-iterated all n elements a second time,\nrecomputing RoundToEven + Float64bits for every value just to locate the few\nexception positions. Fuse the collection into the existing pack loop: append\neach exception index to a pooled []int scratch (alpExcScra\n[…]\nt is bit-identical: same absolute indices in the same order.\n\nBench (Apple M5 Pro arm64, n=10 interleaved, BenchmarkWritePackedALPExc):\n  −22.59% ns/op (2.366µ → 1.832µ), p=0.000, 0 allocs/op in both.",
          "is_bot": false,
          "headline": "perf(alp): eliminate second O(n) scan by collecting exception indices…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4a0084c6aee100a2a6d3c4d3c3d96d048fb4c74",
          "body": "…igration\n\nDeleted unused strHandleScratchPool variable and its associated getter/setter\nfunctions (getStrHandleScratch, putStrHandleScratch). String scratch allocation\nis now managed via decoder state field. Kept dictHandleScratchPool for dict\ntable handle scatter.",
          "is_bot": false,
          "headline": "refactor(batch): remove dead strHandleScratchPool after state-field m…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86402544316b8462f27a39dc6ab32ac0c33f47f3",
          "body": "…tate\n\nReplace per-call getStrHandleScratch/putStrHandleScratch sync.Pool round-\ntrips in scatterBatchColumn with a colStrHandles []Str field on decState,\nmirroring the colScratchI64 pattern already used for int/bool/float scratch.\n\nBench gate (n=10 interleaved, Apple M5 Pro):\n  BenchmarkBatchFSSTDe\n[…]\n)  B/op -100% (24→0, p=0.000)\n  BenchmarkBatchAlphaDecode: allocs/op -100% (1→0, p=0.000)  B/op -100% (24→0, p=0.000)\n  BenchmarkBatchDecode/handles: allocs/op -18% (11→9, p=0.000)  B/op -3% (p=0.000)",
          "is_bot": false,
          "headline": "perf(batch): move string handle scratch from global pool to decoder s…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "074c5f6035b1b06b635c32d250fdd5bbb228c16b",
          "body": "…g pack\n\nDuring the pack loop both writePackedPForUint64Slice and\nwritePackedPForInt64Slice already compute d=v-mn and test pforIsException.\nPreviously that was the only use; a second identical O(n) loop then\nre-scanned s to emit (relPos, delta) pairs.\n\nAdd pforExcPos/pforExcDelta scratch slices on \n[…]\n=0.000)\n  PFor_EncodeI64/n=4096   -17.4% (p=0.000)\n  PFor_EncodeI64/n=16384  -21.3% (p=0.000)\n  geomean                 -21.1% ns/op  (+26.7% GB/s)\nWire format is bit-identical; decode path unchanged.",
          "is_bot": false,
          "headline": "perf(pfor): eliminate second O(n) scan by collecting exceptions durin…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9b713373a229935231b7377c1452b427fd94644",
          "body": "…non-nil\n\nGo has a non-moving GC: if a pointer field already holds a live object,\ndecode into it directly rather than calling reflect.New each time.\nThe reuse path eliminates one heap allocation per pointer field per\ndecode cycle; BenchmarkDecodePtrReuse shows -34% latency and -100%\nallocs (1→0 allocs/op, p=0.000, n=10 interleaved, Apple M5 Pro).\n\nAdd TestDecodePtrReuse (correctness: reuse confirmed and nil-tag path\nstill clears the field) and BenchmarkDecodePtrReuse as bench gate.",
          "is_bot": false,
          "headline": "perf(decode): reuse existing allocation in decodePtr when pointer is …",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a07fe748f3480f9cc1fbbc4f1904203905d2f0ed",
          "body": "…ntKeys/UintKeys\n\nit.Key() on each loop iteration allocates a new reflect.Value header per map key\n(copyVal calls unsafe_New when ifaceIndir is true for string/array/struct keys).\nSetIterKey writes the current iterator entry into a pre-allocated reflect.Value\nin-place — O(1) allocs total instead of \n[…]\nodeCanonicalMap (map[string]rec, 64 keys, n=10 interleaved):\n  allocs/op  139 → 76   -45.32% (p=0.000)\n  B/op      5.405Ki → 4.419Ki  -18.25% (p=0.000)\n  sec/op    6.114µ → 5.616µ    -8.15%  (p=0.000)",
          "is_bot": false,
          "headline": "perf(reflect): replace it.Key() with SetIterKey in gatherStringKeys/I…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "283a899c3f4325da64179af453dd8f2ed20ff1b7",
          "body": "…variants\n\nReplace 'append(out, make([]byte, bodyBytes)...)' with direct slice\nextension using capacity guaranteed by slices.Grow, followed by\nclear() for zero-initialization. This eliminates one allocation per\nPFOR-encoded column by avoiding the temporary slice creation and\nappend copy.",
          "is_bot": false,
          "headline": "perf(pfor): eliminate throwaway make for body buffer in uint64+int64 …",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26a55b3caba27cf401f26d0a4281c27d979e56a4",
          "body": null,
          "is_bot": false,
          "headline": "fix(.gitignore): ensure .superpowers and CLAUDE.md are tracked",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef3d90af00b892cf3ab07efa369e7aeab337057c",
          "body": null,
          "is_bot": false,
          "headline": "fix(.gitignore): add .superpowers to ignored files",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff162c48acb1c7dcb492e3ce6aab45f3235320b0",
          "body": "… data pointer\n\nFor struct and array types with size > ptrSize, the interface boxing at\nthe call site already produced a heap copy. Extract eface.data directly\ninstead of calling reflect.New + Set, removing one allocation per\nMarshal(structVal).\n\nDirect-interface structs (size == ptrSize, single poi\n[…]\n→2 allocs/op  (-33%), 528→336 B/op  (-36%)\n  BenchmarkEncode_Nested/qdf_fast: 3→2 allocs/op  (-33%), 256→176 B/op  (-31%)\n  BenchmarkEncode_MapHeavy/qdf_fast: 3→2 allocs/op (-33%), 416→368 B/op (-12%)",
          "is_bot": false,
          "headline": "perf(encode): skip reflect.New for by-value struct encoding via eface…",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-16T06:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "73a3e5118084b2361108ee551f49ee4d6b967e75",
          "body": "Replace atomic.Uint32 rrCounter (two LDADD instructions per Get+Put\npair, one global cache line under contention) with a goroutine-local\nshard index derived from the caller's stack address.\n\nThe local variable &hint resides on the goroutine's stack, whose base\naddress differs per goroutine by at lea\n[…]\n targets\nthe same shard, improving pool hit rate for round-trip callers. The\nbenefit is largest under high goroutine counts where the previous\nrrCounter caused a LDADD cache-line bounce on every call.",
          "is_bot": false,
          "headline": "perf(bufpool): eliminate global atomic counter in shard selection",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-15T11:34:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "deb3ef40b73029bf0e557804e4867f395357952d",
          "body": "Add fsst.SymbolTable.Reset() and fsst.UnmarshalInto(b, t) that reuse\nthe table's symbols/cands backing arrays in-place, avoiding the three\nheap allocations that UnmarshalSymbolTable makes per call (SymbolTable\nstruct, []symbol backing, []cand index). UnmarshalInto also skips the\nintermediate [][]byt\n[…]\nnchmarks (Apple M, -count=6):\n  BenchmarkBatchFSSTDecode: 41198 -> 31567 ns/op  (+23%)\n                            29967  ->    24 B/op   (-99.9%)\n                               13  ->     1 allocs/op",
          "is_bot": false,
          "headline": "perf(fsst): pool SymbolTable on decode path, add UnmarshalInto",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-15T11:34:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adee628c00b708ba4743b80d58d794d297b446c0",
          "body": "…columns\n\nreadNullableMask: replace byte-at-a-time OnesCount8 loop with an\nOnesCount64 word loop (8 bytes per POPCNT/CNT instruction, O(n/8)\niterations instead of O(n)). Byte tail handled separately.\n\ndecodeNullableColumnVals: replace O(n) bit-by-bit setBit loop building\nthe colVals.present []uint64\n[…]\n block (256 B for float64, 128 B for float32).\n\nBenchmarks (Apple M, -count=6):\n  BenchmarkBatchDecode/handles: 4372 -> 4138 ns/op  (+5.3%)\n  BenchmarkBatchAlphaDecode:    6539 -> 6411 ns/op   (+2.0%)",
          "is_bot": false,
          "headline": "perf(decode): word-granular popcount + bulk bitset copy for nullable …",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-15T11:34:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c878d261fd72b589dcc6f4eec47bc15e4e69812d",
          "body": "Sync nested modules (replace => ../../) after a Dependabot dependency bump so their go.mod/go.sum match the root. Generated by the dependabot-auto-tidy workflow.",
          "is_bot": true,
          "headline": "build(deps): go mod tidy across modules",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-15T11:14:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d75bc40955ab74558a9f7bf2173cda956daafd8c",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.47.0 to 0.48.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.47.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version: 0.48.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump golang.org/x/tools in /cmd/qdfgen",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-15T11:14:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d3c39863344412f3e91eabd16fc0c864c9e0c95",
          "body": "CVE-2026-42505 / GO-2026-5856: ECH key disclosure in crypto/tls,\nfixed in go1.26.5. govulncheck exits 3 for qdf-bench because it\nmakes outbound HTTPS calls (fetchSampleData), making the vulnerable\ntls.Conn/tls.Dialer symbols reachable.\n\nAffected range: go1.26.0–go1.26.4.\nFix: bump `go` directive in every module to 1.26.5 so the CI runner\npicks up the patched toolchain via setup-go's go-version-file lookup.",
          "is_bot": false,
          "headline": "fix(security): bump go directive to 1.26.5 across all modules",
          "author_name": "alex60217101990",
          "author_login": null,
          "committed_at": "2026-07-15T10:04:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "536378189f2ecb3d1c78819f74b0c49cd56ee2b6",
          "body": "Sync nested modules (replace => ../../) after a Dependabot dependency bump so their go.mod/go.sum match the root. Generated by the dependabot-auto-tidy workflow.",
          "is_bot": true,
          "headline": "build(deps): go mod tidy across modules",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-15T09:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fafb673518a0b2c44728f28b999ff4775be6342a",
          "body": "Bumps the go-deps group with 1 update: [golang.org/x/sys](https://github.com/golang/sys).\n\n\nUpdates `golang.org/x/sys` from 0.46.0 to 0.47.0\n- [Commits](https://github.com/golang/sys/compare/v0.46.0...v0.47.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/sys\n  dependency-version: 0.47.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: go-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump golang.org/x/sys in the go-deps group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-15T09:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "436136d7ade9b9460e335d783324fa1869430dc5",
          "body": "decodeAny boxes every time.Time value into an interface — a 24-byte heap\nallocation per occurrence. Unset time fields (DeletedAt, ExpiresAt, LastSeen\n...) decode to the zero time.Time en masse, so on time-bearing dynamic data\nmost of that boxing is one repeated value.\n\ndecState caches the boxed zero\n[…]\n nothing.\n\nMeasured (map[string]any, 90% zero times): 1984 -> 1084 allocs/op (-45%),\n110KB -> 88KB, -22% time. All-unique timestamps: neutral. Sharing the\nimmutable zero-time box across slots is safe.",
          "is_bot": false,
          "headline": "perf(decode): share one boxed any for the zero time.Time value",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T19:37:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc4337a3f12580781d53dad906b794037eab2e04",
          "body": null,
          "is_bot": false,
          "headline": "test(decode): cover boxed-any string value cache under WithArena",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T19:37:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e238a9addc016caf264168e11615753369044a9f",
          "body": "Decoding a map[string]any / []any boxes every value into an interface, one\nallocation per occurrence — the dominant decode cost on dynamic payloads.\nString interning already deduplicates the string BYTES, but each occurrence\nstill boxes its own any(s). On repetitive data (config/telemetry/AD dumps,\n\n[…]\nclock. All-distinct worst case: neutral, zero\nalloc change. Sharing an immutable boxed scalar across map/slice slots is\nsafe; gated on !noCopy so the cached box matches the shared stringValues\nstring.",
          "is_bot": false,
          "headline": "perf(decode): cache boxed any per interned string value",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T19:37:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2682b9f32cf8700b3f5b6b791afce5bfd78d9a19",
          "body": "…raw/dict\n\nThe single-string-column FSST and alpha tests only ever exercise the\ndirect-into-slab arms at slab base 0. This decodes a four-string-column\nbatch (URL->FSST, hex->alpha, random->raw, category->dict) so columns 2..4\nrun at a non-zero slab base, and asserts every field is byte-identical via\nUnmarshalBatch against BOTH the source and the authoritative reflect\nUnmarshal — covering the cross-column offset math a base bug would corrupt.\nPlus every-prefix truncation.",
          "is_bot": false,
          "headline": "test(batch): multi-string-column round-trip parity across FSST/alpha/…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4959fd3cd759a6c0039d0517d37c412c345f305",
          "body": "readStringColumnHandles routed tagColStrAlpha columns through the general\narm: readStringColumnAlpha unpacked the whole column into a fresh\nmake([]byte, totalChars) temp, then each string was copied a second time\ninto the batch slab. Add readStringColumnAlphaInto, a dedicated arm that\nunpacks the al\n[…]\non. readStringColumnAlpha itself\nis unchanged — the reflect Unmarshal path still uses it.\n\nMeasured (1000-row 16-char hex column): 16445 B/2 allocs/~24us ->\n24 B/1 alloc/~15us (-16KB, -1 alloc, -37%).",
          "is_bot": false,
          "headline": "perf(batch): unpack alpha string columns directly into the slab",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0c00a00d9522e462d2877d2ef424d0e15a2bed2",
          "body": "… paths\n\nUpdate BATCH-HANDLES.md 'How it works' for the three decode strategies (two\ndirect fast paths + reflect fallback), split the FSST string-column arm out\nas direct-into-slab, and add the row-major and FSST decode benchmarks to the\nmeasured story. Drop stale internal references from two benchmark-control\ncomments.",
          "is_bot": false,
          "headline": "docs(batch): document row-major-direct + FSST direct-into-slab decode…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7535dfb59c02f055bb68b27db44e8628ca655524",
          "body": "readStringColumnHandles routed FSST columns through the general arm:\nreadStringColumnFSST decompressed the whole column into a fresh\nmake([]byte,0,dt64) temp, then each string was copied a second time into\nthe batch slab. Add readStringColumnFSSTInto, a dedicated tagColStrFSST arm\nthat decompresses \n[…]\nreflect\nUnmarshal path keeps using readStringColumnFSST unchanged.\n\nMeasured (1000-row FSST column, i7-9750H): 111925 B/op/14 allocs/~138us ->\n29864 B/op/13 allocs/~105us (-82KB, -1 alloc, -24% time).",
          "is_bot": false,
          "headline": "perf(batch): decompress FSST string columns directly into the slab",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f5c8b2e35c6c6d98654245e2253f45f659219e8",
          "body": "…lback for non-row-major wires\n\nAdd d.CheckLength(n, 1) right after ReadArrayHeader in tryDecodeBatchRowMajor:\nReadArrayHeader's tagArr16 arm (unlike tagArr32) does not bound n against the\nremaining buffer, so a tiny hostile wire could drive a multi-MB transient\nrows(n) allocation before checkColumn\n[…]\n batched-vector wires are\ndocumented unreachable for a legitimately-typed Batch[T] (batchPlanOf rejects\nevery pointer/slice field that could produce them), per grep evidence in the\ntest's doc comment.",
          "is_bot": false,
          "headline": "harden(batch): bound row-major array count by input; prove mirror fal…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44c75cbcd94be57e0865ea6a84cf7f75b39ff8ad",
          "body": "… mirror)",
          "is_bot": false,
          "headline": "feat(batch): decode row-major struct-slice directly into T + slab (no…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cd727102cbf184ca9e4201d95d36e20ecebf7f1",
          "body": null,
          "is_bot": false,
          "headline": "feat(batch): row-major-direct fast-path skeleton (delegates to mirror)",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T17:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eeccc2e6a175ad8a7c92c0ba04a64eeeaebc6c7d",
          "body": "Native Go fuzzing occasionally reports \"0 execs/sec\" then \"context\ndeadline exceeded\" and exits non-zero at the -fuzztime boundary without\nfinding a bug (golang/go#51484) — observed on the nightly fuzz-extended\nrun for FuzzRoundTrip_StringSlice (7.6M clean execs, no reproducer, sibling\ntarget green,\n[…]\nproducer was written, tolerate the bare boundary flake,\nand still fail on any other unrecognized non-zero exit. Mirrors go.dev's\nregression-corpus model (fuzzing discovers, corpus replay is the gate).",
          "is_bot": false,
          "headline": "ci(fuzz): tolerate -fuzztime boundary flake, gate on written reproducer",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T07:35:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b2d4aa8066ccf9f2786682a9d317fb1f328f88b",
          "body": "…on wins\n\nDeep line-by-line audit (45 units, ~41K LOC, adversarially verified; each\nre-verified by hand — 2 findings rejected: a []byte scatter copy that is\naliasing insurance not waste, and an E8 coset re-alloc with a stale-bit\nhazard already declined in a prior pass).\n\n- batch mirror fallback conv\n[…]\n except the batch time-zero fix (correctness) and the\nnullable-time cost estimate (heuristic accuracy). build+vet+lint0+full suite\n+internal+codegen_test+qdf_simd+qdf_reflect2+qdfdebug+race all green.",
          "is_bot": false,
          "headline": "perf/fix(audit-18): batch time-zero divergence + decode alloc/iterati…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f72c4389d53212a974d765edb8de1e72004b41a",
          "body": "Owner-review pass:\n- Benchmarks use Go 1.24 b.Loop() (setup/teardown auto-excluded; manual\n  Reset/StopTimer scaffolding dropped); bench setup errors now b.Fatal.\n- Per-cell dispatch hoisted out of hot loops: scalar scatter runs\n  width-specialized loops (the old storeIntWidth/storeUintWidth per-ele\n[…]\npseudo-arrows; right\n  offset arrows no longer cross the row boxes — they route around the free\n  corridor and drop into their slab segments from above); doc no longer\n  references an internal report.",
          "is_bot": false,
          "headline": "polish(batch): b.Loop benches, width-hoisted scatters, SVG relocation",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05cb1c22e33f746a4f2a10341132fc39b9044c96",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt batch_desc var block",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34904081f5b7bc11ef7f025a2ea5e305583f52dc",
          "body": "Deep second-pass review findings:\n- Slab offsets are uint32: past 4 GiB, uint32(len(buf)) silently wrapped\n  and handles resolved to the wrong bytes with no error (the debug bounds\n  check cannot catch a wrapped-but-in-range offset; reaching it needs a\n  >4 GiB payload). append now rejects growth pa\n[…]\nong) — covered by\n  the new TestUnmarshalBatchColIndexWire.\n- Stale bench comment 5.2x -> 3.89x; reuse package timeType instead of a\n  duplicate time.Time reflect var; BytesOf doc notes nil-for-empty.",
          "is_bot": false,
          "headline": "fix(batch): cap slab at uint32 handle space; deep-review cleanups",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c12a589573c26f1a18b18cba963a1d3405326885",
          "body": "- Batch[T] and batchPlan reorder pointer-bearing fields first (GC-scanned\n  prefix 32->16 and 128->104 bytes); construction is named-fields only and\n  field access is by name, so layout order is not API.\n- NumField/Field loops -> Type.Fields iterator (appendBatchFields,\n  validateBatchStruct); interface{} -> any and range-over-int in tests.\nDiagnostics-only run of fieldalignment/modernize (no -fix), per directive.",
          "is_bot": false,
          "headline": "style(batch): fieldalignment-tuned layouts and modernize idioms",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "549f2350737e4d0fc204a89545da503754b27e0c",
          "body": null,
          "is_bot": false,
          "headline": "test(batch): narrow-width scalar dispatch round-trip (final-review add)",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "412dbd4baaec1f16a0cfdd7d17325d3849cf6c41",
          "body": null,
          "is_bot": false,
          "headline": "test(batch): OptZoneMap wire through the columnar fast path",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6554fd952a71711edb88195dab79279835844c9d",
          "body": "Add examples/batchdecode/main.go: a held-store scenario comparing plain\nUnmarshal against UnmarshalBatch (1000-row, low-card Region + high-card\nMsg), single-run timing labeled honestly, a Release-reuse loop, and\nhandle-dedup spot checks.\n\nAppend ExampleBatch_Release (streaming decode/use/Release loop) and\nExampleBatch_Str (handle resolve + dict-dedup) to example_batch_test.go,\nalongside the existing ExampleUnmarshalBatch.",
          "is_bot": false,
          "headline": "docs(batch): runnable batchdecode example and godoc examples",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fca101fbf0a75fa9c6bde76286a19c7ef02d34a3",
          "body": "…rt path",
          "is_bot": false,
          "headline": "docs(batch): cite reproducible bench command instead of internal repo…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf1b24c46f30593631003a5a60f10df23e41191b",
          "body": "…-refs\n\nAdds docs/BATCH-HANDLES.md (type rules, columnar/mirror decode internals,\nlifetime contract, comparison table) plus two hand-written SVG diagrams\n(memory layout, GC scan bar chart), following the LOSSY-VECTOR.md/ARENA.md\ndoc pattern. Cross-links from README, CHOOSING.md, DECODE-PERF.md, and\nARENA.md. No source changes.",
          "is_bot": false,
          "headline": "docs(batch): deep feature guide, memory-layout and GC diagrams, cross…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d8473803f8c1b1e96d2c217a0f93a88101299d8",
          "body": null,
          "is_bot": false,
          "headline": "docs(batch): pointer-free batch decode section and example",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a75b0e082c3534afdc8b52c658b83ce753ab678",
          "body": null,
          "is_bot": false,
          "headline": "bench(batch): decode, steady-state, and held-GC scan benchmarks",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2bb013c73d81b943b2495dd9296ed4b7a48173d",
          "body": "Batch[T] now captures the slab's epoch at decode time. Str/BytesOf call\nslab.checkEpoch before resolving: a no-op in production (inlines away\nto nothing, verified with -gcflags=-m) and a panic in debug/race builds\nwhen the slab was recycled (nil slab or epoch mismatch after Release),\ncatching stale-\n[…]\nandle use loudly instead of returning silent garbage.\n\nAdds FuzzUnmarshalBatch (row-major, columnar, and columnar+OptCompression\nseeds) — 30s run across default/-race/-tags qdfdebug found no crashers.",
          "is_bot": false,
          "headline": "feat(batch): debug stale-handle epoch panics + decode fuzz",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9776d5f2e7559fd3447f6a7101b17bbaf382eb90",
          "body": "Review findings: batchReadColShape relied on the Dense header path having\ninitialised d.state (an incidental invariant the scatter helpers then\ndereference) — restore readColShape's unconditional init so the safety is\nexplicit. Also remove a no-effect write-back of the shape scratch slices.",
          "is_bot": false,
          "headline": "fix(batch): explicit decoder-state init in shape reader; drop dead store",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a643c6add53f3af2d33d5b0de5034f495797c2b5",
          "body": "Two hot-path optimizations per the code-quality directives:\n\n- The mirror fallback read/wrote the pooled slice via\n  reflect.ValueOf(...).Elem()/Index(0).UnsafeAddr() per decode. The pool now\n  hands out a mirrorSlot{box any; ptr unsafe.Pointer} so the hot path goes\n  through *sliceHeader directly —\n[…]\ne, so a reference is unresolvable here by\n  construction.\n\nSteady-state decode+Release: 8 -> 2 allocs/op (threshold tightened to 3).\nVerified under default, qdf_simd, qdf_reflect2 and qdfdebug builds.",
          "is_bot": false,
          "headline": "perf(batch): reflection-free mirror access and zero-alloc shape reader",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de8084394618e35cc0096b86f436ed5c80cdc0e3",
          "body": null,
          "is_bot": false,
          "headline": "feat(batch): pooled rows backing, zero-alloc steady state, value Batch",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc312a0a600c88b69adeaebc051d525f22529b49",
          "body": null,
          "is_bot": false,
          "headline": "style(batch): document width-switch cases per code-quality directive",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "268d46cbb1dabc296b4fa92efffa7e0d56b142c2",
          "body": "…signment\n\nreadStringColumnHandles indexed the tag byte with no bounds check: a\ntruncated/hostile payload with n>0 string rows and an exhausted buffer\npanicked through the public UnmarshalBatch (DoS-class regression vs the\nreference decoder, which guards every entry). Return ErrShortBuffer.\nRegression: TestUnmarshalBatchTruncated (every truncation of a valid\ncolumnar payload must error, never panic).\n\nAlso replace the dead '_ = opts' with a documented reserved parameter.",
          "is_bot": false,
          "headline": "fix(batch): guard truncated string-column tag read; drop dead opts as…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25362cdf39801d80e71760f2328d9f27b2851eff",
          "body": null,
          "is_bot": false,
          "headline": "feat(batch): columnar fast path with slab string materialization",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d533c6678567c19ab27df9bb89472c175dcb87e",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt batch_desc_test",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c518fcff224956b05759fda92a2af652c018c434",
          "body": "Adds Batch[T]/UnmarshalBatch/Str/BytesOf/TimeOf/Release plus the v1\nfallback core: batchPlan gains a runtime-built mirror struct type\n(reflect.StructOf swapping Str/Bytes/Time for string/[]byte/time.Time)\nthat the existing reflect-driven Unmarshal decodes into directly, then\na single copy pass scatters mirror rows into pointer-free T rows and\nslab-backed string/bytes bodies.",
          "is_bot": false,
          "headline": "feat(batch): UnmarshalBatch with row-major fallback decode",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b144553d08d077e2e76257945e9386967c381aa3",
          "body": null,
          "is_bot": false,
          "headline": "fix(batch): honor embedded-field skip tag and encoder flatten exclusions",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8593fa0c99cf9cc600dcc06b548082b58963b1b",
          "body": null,
          "is_bot": false,
          "headline": "feat(batch): strict pointer-free batch plan with field mapping",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6136daef4ca231c0f4dc02aad73acec623622f10",
          "body": null,
          "is_bot": false,
          "headline": "test(batch): cover bytes resolve and grow offset stability",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87423533f1057eba874e2891c44af278f090d630",
          "body": null,
          "is_bot": false,
          "headline": "feat(batch): pointer-free handle types and grow-copy slab",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-04T05:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5326153fc249a2e41ed2e1ea281347637d31bf6c",
          "body": "Line-by-line audit (~39K LOC, per-line-range agents, adversarially verified,\nevery finding re-verified and reproduced by hand). Nine fixes:\n\nCodegen correctness:\n- appendFields flattened an embedded time.Time / Marshaler / Unmarshaler\n  value-struct; its fields are unexported (time.Time) or its wire\n[…]\noverwritten — clear the full backing first (mirrors colDictTable).\n- skipColumnValue boxed every present nullable value into []any just to\n  discard it; skip is now mask + base-kind skip, zero boxing.",
          "is_bot": false,
          "headline": "fix: deep-audit round — codegen parity, decode guards, state hygiene",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T21:53:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f734773a81cda5dbcee690738bd49e8a70a8e754",
          "body": "readLossyVec accepted any E8 variant block after only validating the\nvariant enum and the dim/count bounds. E8 quantizes in 8-D blocks and\nReconstructE8 walks nb = n/8 blocks, silently leaving the output tail\nzero when n = count*pdim is not a multiple of 8. A hostile/corrupt wire\nblob with dim in 1.\n[…]\nim>=16 (e8Eligible), so reject any\nE8 block whose pdim is not a multiple of 8. Byte-identical for all valid\ninput (no honest E8 block is ever rejected). Regression:\nTestReadLossyVecE8RejectsSmallPdim.",
          "is_bot": false,
          "headline": "fix: reject E8 lossy-vec block with pdim < 8 (fail closed)",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T12:24:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acd8a6f4fd0e32d5e5106d8d26a89a63ace30964",
          "body": "The package doc listed `UnmarshalT[T any](data []byte) (T, error)`, but\nthe implementation (qdf_generic.go) is `UnmarshalT[T any](data []byte,\nout *T) error`. A caller copying the documented form fails to compile.",
          "is_bot": false,
          "headline": "docs: fix UnmarshalT signature in the public-API doc comment",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T11:53:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c22ac42a42193806399dd814a8901de25cca58d1",
          "body": "…codeValue\n\nqdfgen emitted e.EncodeValue for an any-typed struct field / container\nelement. EncodeValue calls encodeReflect at ifaceDepth==0, so under\nOptLossyVec a []float32/[]float64 or a batchable []struct held in that\nany field emitted a tagColVecLossy (0xFD) / tagVecBatchStruct (0xFE)\nblock. An\n[…]\nbare []float32 and batchable []struct, generated + reflect decode).\n\nSame bug-class as the map-any / any-boxed-block gaps: every tag reachable\nthrough a schemaless position must be decodeAny-readable.",
          "is_bot": false,
          "headline": "fix: codegen any-field must encode via EncodeAny (schemaless), not En…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T11:53:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bff185b26df62e378519ce735e34cf1e05003ea",
          "body": "readPackedGorillaHeader bounded n64 only by the bit-count check\n(n64 > rem*8+1) and then cast n = int(n64) with no MaxInt guard. On a\n32-bit build int/len are 32-bit, so a buffer > ~256MB makes rem*8+1\nexceed MaxInt32; a crafted n64 in that gap passes every check, int(n64)\nwraps negative, and make([\n[…]\nFOR, DeltaFOR, PFOR, bool) already has\nthis exact guard; Gorilla was the sole outlier.\n\nAdd the standard n64 > MaxInt reject. Reject-only: no wire change for\nvalid input; dead branch on 64-bit builds.",
          "is_bot": false,
          "headline": "fix: bound Gorilla decode element count by MaxInt before int narrowing",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T08:40:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "389a55a2d14f815fdee0f075da28a40ae3f22646",
          "body": "… slices\n\nA long []int/[]int64/[]uint/[]uint64 encoded with the per-block adaptive\ncodec (tagPackBlock 0xF0) failed to round-trip when reached through a\nschemaless position — an any value, a map[K]any value, or an any-typed\nstruct field. writeQPackInt64/Uint64 emits 0xF0 with no ifaceDepth gate\n(unl\n[…]\n.\nDecode-only; wire output unchanged. Regression: TestAnyPackBlockRoundTrip.\n\nSame bug-class as the map-any lossy-vec gap: every tag reachable through\na schemaless position must be decodeAny-readable.",
          "is_bot": false,
          "headline": "fix: decodeAny must handle tagPackBlock (0xF0) for any-boxed int/uint…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T08:40:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0c01c44deb87370a904a582efdbf397c028c9f1",
          "body": "encodeSliceFloat32Impl/Float64Impl appended tag+body per element with no\nupfront reservation, unlike every sibling codec (FOR/RLE/dict/PFOR/delta/\nALP/Gorilla all slices.Grow once before the loop). Grow e.buf by n*5\n(float32) / n*9 (float64) after the empty-slice guard so the loop does no\nrepeated growth checks or copies. Byte-identical; qdf_simd build tag only.",
          "is_bot": false,
          "headline": "perf: reserve buffer capacity once in the qdf_simd bulk float encoders",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T08:09:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d070993f39381effbc2bf2d21d47770258dce11b",
          "body": "writeZoneChunkInt64/Uint64 scanned every zone with minMaxI64/minMaxU64\nto size the min/max zonemap for the never-worse comparison against the\nlinear zonemap, then — when the linear map lost — scanned every zone a\nsecond time to emit the identical values. Cache the pairs (reduced to\ntheir uvarint pay\n[…]\nByte-identical output (same values, same varint encoding, same order);\nonly the opt-in OptZoneMap columnar path is affected. Alloc-free: the\nscratch is reused across columns and capped on pool return.",
          "is_bot": false,
          "headline": "perf: reuse per-zone min/max pass in zone-chunk encode",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T08:09:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fadc413560e7252509a212c81d7b1b0f42989b3",
          "body": "A []float32/[]float64 (or batchable []struct-with-vector) held in a\nmap[K]any value slot was encoded through encodeReflect, which — unlike\nencodeIface — never raised e.ifaceDepth. With ifaceDepth==0 the\nlossy-vector / batched-struct gate fired under OptLossyVec and emitted a\ntagColVecLossy (0xFD) / \n[…]\nt is byte-identical for every value that\nwas previously decodable (encodeIface is encodeReflect plus a balanced\nifaceDepth inc/dec and the cycle-depth guard).\n\nRegression: TestMapAnyLossyVecRoundTrip.",
          "is_bot": false,
          "headline": "fix: map[K]any values must encode via encodeIface, not encodeReflect",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-02T08:09:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be8a5154d397b3152bee76c5763dd2bf919b9f70",
          "body": null,
          "is_bot": false,
          "headline": "chore: gitignore docs/promo/ (local-only promotion drafts)",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-01T18:17:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2bfdeaccc8be5f7a48fcfb0fee4ccb6e34a56e5",
          "body": "- README: an honest when-to-reach-for-qdf / when-something-else table high up,\n  so the right users adopt and the wrong ones don't churn (batch/streaming\n  structured data & decode-heavy & embeddings vs single-tiny-message,\n  cross-language IDL, mmap random-access, max encode throughput, frozen spec).\n- New issue template inviting \"a payload where qdf loses that it shouldn't\" —\n  the deep-dive posts' CTA, turned into a structured perf/size report funnel.",
          "is_bot": false,
          "headline": "docs: add \"When to use qdf\" fit guide + \"qdf loses\" issue template",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-01T17:59:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53d0b63f7098c44a5da6969585aca890c7474cd2",
          "body": "…-format\n\ndocs: rebrand to Quick Data Format + benchmark-first README + SVG logo",
          "is_bot": false,
          "headline": "Merge pull request #145 from alex60217101990/chore/rebrand-quick-data…",
          "author_name": "alex60217101990",
          "author_login": "alex60217101990",
          "committed_at": "2026-07-01T17:48:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 12,
      "commits_last_year": 822,
      "latest_release_at": "2026-07-18T07:23:37Z",
      "latest_release_tag": "v0.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 4.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/alex60217101990/qdf",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/alex60217101990/qdf",
          "is_deprecated": false,
          "latest_version": "v0.1.2",
          "repository_url": "https://github.com/alex60217101990/qdf",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T07:19:56Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 26,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "bench/pb/bench.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "bench/go.mod",
        "cmd/qdf-bench/go.mod",
        "cmd/qdf-vecbench/go.mod",
        "cmd/qdfgen/go.mod",
        "go.mod",
        "internal/codegen_test/go.mod"
      ],
      "largest_source_bytes": 101562,
      "source_files_sampled": 409,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "bench/go.mod",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 9,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/alex60217101990/qdf",
          "manifest": "bench/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/google/flatbuffers",
          "manifest": "bench/go.mod",
          "ecosystem": "go",
          "version_constraint": "v25.12.19+incompatible"
        },
        {
          "name": "github.com/vmihailenco/msgpack/v5",
          "manifest": "bench/go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.4.1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "bench/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "github.com/modern-go/reflect2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.2"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.47.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/google/flatbuffers",
            "direct": true,
            "version": "v25.12.19+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": true,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/msgpack/v5",
            "direct": true,
            "version": "v5.4.1",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/tagparser/v2",
            "direct": false,
            "version": "v2.0.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.48.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 9,
        "direct_count": 5,
        "indirect_count": 4
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 162,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "alex60217101990",
          "commits": 777,
          "avatar_url": "https://avatars.githubusercontent.com/u/33520849?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "bench-trend.yml",
        "bench.yml",
        "ci.yml",
        "codeql.yml",
        "dependabot-auto-tidy.yml",
        "fuzz-extended.yml",
        "govulncheck.yml",
        "pages-ai-article.yml",
        "pages-article.yml",
        "pr-label.yml",
        "qdf-bench-matrix.yml",
        "release.yml",
        "scorecard.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 8,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "3 out of 3 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/3 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e55cd5b1a2b0798e20d8637cc71cfaa9f4d640a3",
        "ran_at": "2026-07-23T17:47:38Z",
        "aggregate_score": 6.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T07:46:05Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-18T07:19:57Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/alex60217101990/qdf",
    "host": "github.com",
    "name": "qdf",
    "owner": "alex60217101990"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 72,
        "vitality": 76,
        "community": 39,
        "governance": 53,
        "engineering": 84
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 822,
              "human_commit_share": 0.96,
              "days_since_last_push": 5,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "822 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 822
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 12,
              "latest_release_tag": "v0.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 4.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "12 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 39,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "forks": 0,
              "stars": 26,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "26 stars",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "merged_prs": 162,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "162/164 decided PRs merged",
                "points": 37.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 162,
                      "decided": 164
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/3 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "followers": 4,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "alex60217101990",
              "public_repos": 44,
              "account_age_days": 3178
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of alex60217101990",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "alex60217101990"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "44 public repos, account ~8 yr old",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 44
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/alex60217101990/qdf"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 84,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "13 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "3 out of 3 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "binary-serialization",
                "codec",
                "columnar",
                "compression",
                "data-format",
                "encoding",
                "go",
                "golang",
                "messagepack",
                "protobuf",
                "serialization",
                "serialization-library"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "12 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 72,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 65,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "3 out of 3 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/3 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 9 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 9
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 9,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 9,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 73,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 96 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 96
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "bench/go.mod",
                "cmd/qdf-bench/go.mod",
                "cmd/qdf-vecbench/go.mod",
                "cmd/qdfgen/go.mod",
                "go.mod",
                "internal/codegen_test/go.mod"
              ],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "bench/go.mod, cmd/qdf-bench/go.mod, cmd/qdf-vecbench/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "bench/go.mod, cmd/qdf-bench/go.mod, cmd/qdf-vecbench/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 101562,
              "source_files_sampled": 409,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/409 source files over 60KB",
                "points": 54.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 409,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "bench/pb/bench.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "bench/pb/bench.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "bench/pb/bench.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T17:47:53.880368Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/alex60217101990/qdf.svg",
  "full_name": "alex60217101990/qdf",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.