Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 2053,
"has_wiki": true,
"homepage": "https://arenzana.github.io/arca/",
"languages": {
"Go": 883147,
"Makefile": 1189
},
"pushed_at": "2026-07-27T11:59:09Z",
"created_at": "2026-06-29T18:51:57Z",
"owner_type": "User",
"updated_at": "2026-07-27T10:11:05Z",
"description": "age-based, auditable, secret value encryption CLI. AI-agent friendly",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://arenzana.org",
"name": "Ismael Arenzana",
"type": "User",
"login": "arenzana",
"company": null,
"location": "Fort Wayne, IN & Madrid, Spain",
"followers": 8,
"avatar_url": "https://avatars.githubusercontent.com/u/5133407?v=4",
"created_at": "2013-07-31T23:31:42Z",
"is_verified": null,
"public_repos": 24,
"account_age_days": 4745
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-27T12:03:37Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-24T09:55:51Z"
},
{
"tag": "v0.7.2",
"kind": "patch",
"published_at": "2026-07-20T14:08:04Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-07-10T09:53:23Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-09T15:08:52Z"
},
{
"tag": "v0.6.5",
"kind": "patch",
"published_at": "2026-07-09T09:17:55Z"
},
{
"tag": "v0.6.4",
"kind": "patch",
"published_at": "2026-07-08T12:36:21Z"
},
{
"tag": "v0.6.3",
"kind": "patch",
"published_at": "2026-07-03T14:49:26Z"
},
{
"tag": "v0.6.2",
"kind": "patch",
"published_at": "2026-07-03T12:54:34Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-07-02T13:55:52Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-07-01T20:53:37Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-01T20:34:28Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-01T12:47:06Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-06-30T14:49:11Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-06-30T13:08:43Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-06-29T21:26:20Z"
}
],
"recent_commits": [
{
"oid": "d4266fc063fe16f1045ea891941c03548a7aa735",
"body": "…idual (#112)\n\nS6 docs: remove a dangling (see T15) cross-reference in the T2 residual and reword the $ARCA_AUDIT hatch note; document the D4 residual in CONFIGURATION.md — two spellings of one store still key to two state dirs if you symlink the store *file* (symlinks resolve on the directory, not the file) or if the parent dir doesn't exist when the key is first computed. A split is the safe direction (state looks fresh; arca doctor names the dirs to merge).",
"is_bot": false,
"headline": "docs: correct two S6 prose claims + document the statedir symlink res…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T10:09:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7acf1a1f6bf266d6b1f6d1600fbe6c4cae3dea9",
"body": "…tes (#114)\n\nRe-applied dependabot's SHA-pin bumps onto current main (preserving the gofmt\ngate #104 added to ci.yml) and signed to satisfy the DCO check. Supersedes #114's\noriginal commit.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": true,
"headline": "build(deps): bump the gh-actions group across 1 directory with 5 upda…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T09:29:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e5b0acbf4b290d67ef35119a73a70e21253128b3",
"body": "…#113)\n\nRe-applied via go get on current main and signed to satisfy the DCO check\n(dependabot's own commit carries no Signed-off-by). Supersedes #113's original.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": true,
"headline": "build(deps): bump github.com/mark3labs/mcp-go from 0.56.0 to 0.57.0 (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T09:24:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65881bd252a23dab737ecd098eb7cefd71a3aa36",
"body": "S22: go vet, staticcheck and gosec don't check formatting, so unformatted code merged silently. Add a gofmt step to the existing lint job (not a new job — a new job's context isn't in the required set, so it would look gated and not be). Tests the output of gofmt -l (which exits 0 even when it lists files) and prints the diff on failure.",
"is_bot": false,
"headline": "ci: gate gofmt in the lint job (#104)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T09:13:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bc3e00a7b8230bb7e256d140bb18649b197843d",
"body": "S19: set/generate could relax an existing secret's policy headless (--require-approval=false, --no-print=false, --require-grant=false, --rate \"\", --canary=false) — a control-plane change wearing a write command's clothes. Now anchored via requirePolicyOperator, with a deliberately narrow predicate: \n[…]\nintact.\n\nThreat model: T13's five relaxation flags close; the residual narrows to expiry extension. The now-closed sync-locking (#106) and MCP-unbounded (#105) findings are removed from Open findings.",
"is_bot": false,
"headline": "sec: anchor policy downgrades on set/generate (T13/R28) (#110)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T09:04:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4672ff60606084cf70d1f6ec2b42fe1313ac332b",
"body": "R2: run_with_secrets / run_with_handle capped their child's captured output (1 MiB/stream, ARCA_MCP_MAX_OUTPUT) with a truncation notice, and give the child a wall-clock deadline (120s, ARCA_MCP_TIMEOUT); both overrides are clamped to a range so an agent that owns the env can't spell 'unlimited'. Th\n[…]\nest.go moves to //go:build e2e && !windows (syscall.Rlimit is undefined on Windows) so the e2e package compiles for Windows and e2e (windows) actually runs its tests instead of silently building zero.",
"is_bot": false,
"headline": "fix(mcp): bound exec-tool output and runtime; disable core dumps (#105)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T08:51:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2d2b3b2cf12d966714081d98cb1d9780ee11c7c4",
"body": "…ack (#111)\n\nS7 (R16/R17/R18): centralize atomic file publishing in internal/atomicfile (write temp → fsync → rename → fsync parent dir), adopted by the store save and the state-dir writers.\n\n- R16: the store generation is bumped only AFTER the write that can fail succeeds, so a failed save no longe\n[…]\n can lose a concurrent-access race with 'access denied' — documented as availability, not a splice; tests tolerate it on Windows and keep the no-splice integrity assertion for successful ops (W3/W4b).",
"is_bot": false,
"headline": "fix: durable state writes; a failed save no longer looks like a rollb…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T08:44:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9365b5ffabbc3445a0604d4c0c02087e9b94dc6",
"body": "S4 (R1/D1): sync does all network I/O outside the store lock, then re-evaluates and commits under the lock conditional on the generation not having advanced (a local CAS mirroring the backend's) — no backend call while the lock is held, every state write under the lock. Stops an auto-sync pull silen\n[…]\n (cross-store clobber + false rollback alarm).\n\nS6 (R4/D2): a detected agent with $ARCA_AUDIT != default is refused (not silently redirected); an unrecordable canary trip fails the call (fail-closed).",
"is_bot": false,
"headline": "sec: sync-lock CAS, per-store state dir, audit-path refusal (#106)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T08:29:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c17431741dfa239eee246af4aa1ef02dac2b6f83",
"body": "…x (#108)\n\nS3: requireOperator() anchors grant, agent allow, recipients add, reencrypt, enable and handle create to an interactive terminal (T11/T12/R27) — refuse a detected agent, otherwise confirm on /dev/tty (CONIN$/CONOUT$ on Windows), no env bypass. Also audits recipients add + adds secret-scan\n[…]\nose on the expiry path; e2e now bounds every child with a ctx deadline and checks ctx.Err() before the *exec.ExitError branch so a hang can't read as a green pass. Proven by e2e (windows) going green.",
"is_bot": false,
"headline": "sec: anchor the control plane to an operator terminal + W1 Windows fi…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-27T08:15:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bc194c23eac1abd4c51023a9bcd7be44acfe95c7",
"body": "* fix: refuse an empty value that would destroy a stored secret (R3)\n\n`readValue` returned an empty slice with no error, so a pipe whose producer\nfailed silently replaced a real secret with nothing:\n\n vault-cli read prod/key | arca set PRODKEY # producer fails, prints nothing\n Stored PRODKEY\n[…]\n only the disabled state refuses.\n\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "S1: empty value and disabled handle (#107)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-26T07:05:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f984ce5a3c2550a0e7fb1cf3524addf5f4233e5a",
"body": "…w self-heal (#103)\n\nBundles the feat/user-safety work: arca doctor health check, exposure visibility (who-can-read + recipient labels), safer agent defaults (deny-by-default MCP exposure under --strict), and audit-escrow self-heal + `sync reset-escrow`. See PR #103 for detail.",
"is_bot": false,
"headline": "user-safety: doctor, exposure visibility, safer agent defaults, escro…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-24T09:50:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7cc9c60693f3a7142cb406b0cf018619637f7699",
"body": "…tes (#101)\n\nBumps the gh-actions group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/setup-go](https://github.com/actions/setup-go) | `6.5.0` | `7.0.0` |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.1` |\n| [gi\n[…]\n version-update:semver-patch\n dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the gh-actions group across 1 directory with 5 upda…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T14:02:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0338aa35ecb9b83504a9cf4e6e7e6ab58ad6ccdb",
"body": "Bumps the go-deps group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.53.0 to 1.54.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.53.0...v1.54.0)\n\n\n\n---\nupd\n[…]\npe: version-update:semver-minor\n dependency-group: go-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump modernc.org/sqlite in the go-deps group (#100)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T13:55:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1b63453fdfebd65c6d0eb1996d176106d6eba10",
"body": "The post-command auto-sync (PersistentPostRun) printed the same\ninformational notices as an explicit `arca sync` — \"in sync: nothing to\ndo\", \"pushed/pulled generation N\". After `arca get NAME`, whose value is\nwritten with no trailing newline so it pipes cleanly, that notice landed\non the same termin\n[…]\ning,\n so no stray blank line appears.\n\nAdds TestSyncQuietSuppressesInformationalOutput, TestNewlineGuard, and\nTestAutoSyncOutputNeverTrailsCommand.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "sync: make opportunistic auto-sync quiet and non-colliding (#102)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-20T13:32:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b744f6a89b94616e19c98110160a394c037e5cd2",
"body": "…SEC-43) (#99)\n\nThe SEC-39 segment-key shape check used \\d{6}, but the writer keys segments\nwith %06d — a MINIMUM width, so a Seq past 999999 emits 7+ digits. An exact-6\nregex would reject arca's own segment as 'injected' and break\nlog --verify --remote permanently. \\d{6,} matches the zero-padded-mi\n[…]\n.go\ncomment (the code does fsync before rename). No behavior change beyond the\nregex; the audit otherwise found the code clean (no new HIGH/MEDIUM).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "fix: escrow key regex accepts the writer's own keys past seq 999999 (…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-13T08:30:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "20f57febc649d3d559f5d1dca5e682a576952748",
"body": "Bumps the gh-actions group with 1 update in the / directory: [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action).\n\n\nUpdates `lycheeverse/lychee-action` from 2.8.0 to 2.9.0\n- [Release notes](https://github.com/lycheeverse/lychee-action/releases)\n- [Commits](https://github.com/ly\n[…]\n version-update:semver-minor\n dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump lycheeverse/lychee-action (#98)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-13T08:09:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6d6b1766e045798c08484acc9e88b516f1a73399",
"body": "… (#97)\n\nBumps the go-deps group with 2 updates in the / directory: [github.com/mark3labs/mcp-go](https://github.com/mark3labs/mcp-go) and [golang.org/x/term](https://github.com/golang/term).\n\n\nUpdates `github.com/mark3labs/mcp-go` from 0.55.1 to 0.56.0\n- [Release notes](https://github.com/mark3labs\n[…]\npe: version-update:semver-minor\n dependency-group: go-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the go-deps group across 1 directory with 2 updates…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-13T08:03:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "15f708bafb661d1e46c661db4c4741b46dc38f8e",
"body": "Bumps the docsgen-deps group in /tools/docsgen with 1 update: [github.com/yuin/goldmark](https://github.com/yuin/goldmark).\n\n\nUpdates `github.com/yuin/goldmark` from 1.8.2 to 1.8.4\n- [Release notes](https://github.com/yuin/goldmark/releases)\n- [Commits](https://github.com/yuin/goldmark/compare/v1.8.\n[…]\nersion-update:semver-patch\n dependency-group: docsgen-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump github.com/yuin/goldmark (#96)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-13T07:56:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd8618349f4579a4e0e8851cc3a3b0b5fbd2032f",
"body": "…tup walkthrough (#95)\n\nThe README Features table and docs index never listed sync, so the whole\nmulti-machine feature was invisible on the front page and the published\ndocs site. Adds a Sync feature row and a SYNC.md link.\n\nSYNC.md's 'a new machine just needs identity + URL' line became incomplete\n\n[…]\nrant + reencrypt + push → sync init --store-credentials →\npull), the stdin credential-passing pattern for remote hosts, and how to\nremove a machine.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: surface multi-machine sync on the landing page + add a fleet se…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-10T10:50:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63a09403b392b9f8fd6ae74bd3aa9311374db30c",
"body": "…5..42) (#94)\n\nFrom the 2026-07-10 audit. Logic-level defenses only; the complete fix for\nthe store authenticity gap (an operator signature over the store) is a\ntracked follow-up.\n\n- SEC-35 (HIGH): pull refuses replay/rollback/recipient-broadening. The\n rollback floor is the DURABLE high-water mark\n[…]\ned), escrow truncation + injected-key, atomic 0600 rewrite,\nS3 read-after-write + size cap via an httptest S3. Real-MinIO e2e green.\nCoverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security(sync): harden the untrusted-backend pull/escrow paths (SEC-3…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-10T09:49:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6ccc8b7458f83c9042f0eb6d6594b24b6e44aa4",
"body": "nfpm inside the existing goreleaser run: linux amd64/arm64, reproducible\nmtimes pinned to the commit like the archives, LICENSE/README under\n/usr/share/doc/arca. The packages land in checksums.txt, so the cosign\nbundle over the checksums covers them with no new signing machinery.\nVerified by installing the snapshot rpm on Rocky 9 and the deb on\nDebian 12 in containers.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(release): ship .rpm and .deb packages as release assets (#93)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-10T09:08:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed215c0f0855c9edebb804a0f61190f585846506",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.7.0 (2026-07-09) (#92)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-09T15:04:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9765b0b2f9024795a1f9957048ed9436c40b26bb",
"body": "…#91)\n\n* feat(sync): optionally persist backend credentials in the state dir\n\nSync credentials came from the environment only, which made automatic\nsync depend on ambient exports — exactly what retiring the env-file\nsecrets workflow removed. 'sync init URL --store-credentials' persists\nthe ARCA_SYNC\n[…]\nal call, not the struct fields; the\n nosec justification now sits on the right line.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(sync): optionally persist backend credentials in the state dir (…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-09T14:50:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eb510e590f7f200877cf93f8649569d841e06004",
"body": "… and audit escrow (#90)\n\n* feat: arca sync — multi-machine replication through an S3-compatible backend\n\nReplaces 'keep the store file in a git repo' as the only sync story.\n\n- internal/remote: Backend interface (Head/Fetch/Push/PutIfAbsent/Get/List),\n S3 implementation on minio-go with conditiona\n[…]\n>\n\n* test: skip the read-only-dir Save case on Windows (perm bits are advisory there)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat: arca sync — S3 replication with envelope encryption, auto mode,…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-09T10:15:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99b4186b980520ff09960d850a36988858a42b98",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.5 (2026-07-09) (#89)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-09T09:14:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9892e7b8beff267a458a1061e432bf268a75c4ea",
"body": "The nightly govulncheck failed: GO-2026-5856 in crypto/tls, reachable\nvia crypto.Decrypt -> age.Decrypt -> tls.Conn.Read (age's plugin path),\nfixed in Go 1.26.5. go.mod only said 'go 1.26' so CI built with the\nrunner's cached 1.26.4. Pinning the toolchain makes setup-go install\n1.26.5 across every workflow; govulncheck is clean on it.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "fix: pin toolchain go1.26.5 (GO-2026-5856, crypto/tls) (#88)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-09T09:05:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0818c651d2294982ea29d07853eaf3a0f50e295d",
"body": "Also adds the missing 0.6.3 compare link and repoints Unreleased.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.4 (2026-07-08) (#87)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T12:32:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f2152c82aa324b5bae1401a05e0ba719bc1adf2",
"body": "…tes (#85)\n\nBumps the gh-actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\n\n\n[…]\n version-update:semver-minor\n dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the gh-actions group across 1 directory with 3 upda…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T12:27:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bed5f1d3d126b602aafcfc54ad21ff35a2b421e8",
"body": "…, deeper) (#86)\n\nRolling the store and the audit DB back together yields a self-consistent\nolder state that no in-DB check can see — chain, head, signatures, and\ngenerations all agree with each other. A successful 'log --verify' now\nemits an anchor token (chained-event count + head hash) on stdout \n[…]\northy. THREAT-MODEL T9\nupdated: remaining residuals are the one-write-window rollback and the\nanchor's dependence on being minted/checked regularly.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: external audit anchors close the joint-rollback gap (SEC-14…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T12:21:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c23502ee0665765e368c9a02c36149dcf34047ab",
"body": "The docs renderer is its own module, so its dependencies were never\nbumped. Grouped weekly like the root module.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: cover tools/docsgen's go.mod with dependabot (#84)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T12:14:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db326c8f2b52af6975c68ad83e3b9efbe6be0d88",
"body": "--no-print promises the value never reaches stdout; --show is precisely\nthat disclosure, and previously won the conflict. Cobra now rejects the\npair before anything is generated — create with --no-print and consume\nvia exec.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: generate refuses --no-print together with --show (FU-9) (#83)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T11:17:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a5d1a516d76ed91b940051e781497d07e5663bb",
"body": "* security: sanitize DEL/C1 control characters in JSON output (FU-6)\n\nGo's JSON encoder escapes C0 but emits DEL (0x7f) and C1 (U+0080-U+009F)\nraw, so --json output and MCP tool results could carry live terminal\ncontrol sequences from a crafted description, tag, or ARCA_ACTOR — the\nsame injection th\n[…]\n@arenzana.org>\n\n* test: use escape sequences for control chars in FU-6 tests (ST1018)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: sanitize DEL/C1 control characters in JSON output (FU-6) (#82)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T11:13:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3be3f08ff70c04da1f1111d746f47e71459f6f89",
"body": "…re (FU-5) (#81)\n\nSEC-04 moved the decoy designation into the local registry but wasn't\nretroactive: a pre-0.6.2 store still carried canary:true in the synced\nfile, telling an off-host attacker exactly which secrets are traps. On\nload, copy any legacy flag into the local registry and strip it from t\n[…]\n leaves the flags in place (still\nhonored by isCanary) and the migration retries on the next load; a flag\nis never stripped before it was preserved.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: migrate legacy cleartext canary flags out of the synced sto…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T11:03:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50baac25b52f004b350da204e6a1c213ec4f7370",
"body": "…dual) (#80)\n\nThe rollback warning compared the store generation to a local high-water\nmark — a heuristic a machine owner can reset. Every audit event now records\nthe generation it observed, bound into the event's hash and signature, so\n'log --verify' detects a rollback from the tamper-evident log i\n[…]\nTHREAT-MODEL T9 rewritten with the sharper residuals (single-write-window\nrollback; store+audit rolled back together needs external head anchoring).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: bind the store generation into the audit chain (SEC-14 resi…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T10:58:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3dd3770b10486ec99403a23ad8752d7e2bad02b5",
"body": "* security: TTY-anchor the audit escape hatches (SEC-06 residual)\n\nARCA_STRICT_AUDIT=0 and get --no-log were gated on env-var-based agent\ndetection, which is advisory: an agent controls its own environment and\ncan scrub the markers to pass as a human. Anchor both to the controlling\nterminal — the sa\n[…]\nnd success at a real terminal (a developer's\nshell, or the Windows runner's console).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: TTY-anchor the audit escape hatches (SEC-06 residual) (#79)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T10:48:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0295eeb6683de7aadcba7b1a44221e1c1a580ce7",
"body": "The cask/scoop skip_upload templates hard-fail when the env keys are\nabsent ('map has no entry for key HOMEBREW_TAP_TOKEN'). Mirror release.yml:\ndefine them empty so the templates resolve to skip_upload=true and the\ndry-run can never push.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: define empty tap/scoop tokens in release-dryrun (#78)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T07:52:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f77d107486f8f5c9620f0a88e6c4e0e4fdf4284",
"body": "cosign-installer v4 installs Cosign v3, whose default bundle format ignores\nthe deprecated --output-signature/--output-certificate flags and then fails\nwith 'create bundle file: open : no such file or directory'. Caught by the\nrelease-dryrun workflow before any tag was cut.\n\nSign with --bundle produ\n[…]\nsums.txt.sigstore.json, update the dryrun\nto verify goreleaser's own bundle output, and document the new verify\ncommands in SECURITY.md + CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "fix(release): adopt cosign v3 bundle format for checksum signing (#77)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T07:45:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "266f1d3f3de4ad9136f9ba0607fa6ac4fd71313e",
"body": "…g (#76)\n\nThe release workflow only runs on tags, so toolchain bumps (cosign-installer,\ngoreleaser-action) go untested until a real release is in flight. This\nworkflow_dispatch job does a goreleaser snapshot build and a keyless cosign\nsign+verify over the checksums using the same invocation as the release signs\nconfig, publishing nothing.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: add release-dryrun workflow to exercise signing without publishin…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T07:35:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06a69dd2899c65485d9547c516ed53ab91e97062",
"body": "Bumps the gh-actions group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.12.1` | `2.20.0` |\n| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.0` |\n| [actions/dependency-review\n[…]\n version-update:semver-major\n dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the gh-actions group with 6 updates (#75)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T07:21:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cebd243023476382cca132cf58725b0bcdca28de",
"body": "codeql-action ships init/analyze/upload-sarif as steps of one action that\nmust run the same major version; per-step bumps (#69/#72 vs the v3 init\npin) break CodeQL at runtime. Group all actions bumps so they land\natomically, matching what gomod already does.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: group github-actions dependabot bumps into one PR (#73)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T07:04:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e77ce67525f785bb16a57b594369806c1b3c19f1",
"body": "…analyze) (#74)\n\n* build(deps): bump github/codeql-action/analyze from 3.36.2 to 4.36.3\n\nBumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 3.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/co\n[…]\n>\n\n---------\n\nSigned-off-by: dependabot[bot] <support@github.com>\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "build(deps): bump github/codeql-action from 3.36.2 to 4.36.3 (init + …",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-08T07:00:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "956412748aea38f55e6efa476085f6c658f11252",
"body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 3.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump github/codeql-action/upload-sarif (#69)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T06:57:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b8bfe3b841b2602794c78db501272d752d2ff09",
"body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.9.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/398d4b0eeef1380460a10c8013a76f728fb906ac...6f9f17788090df1f26\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump sigstore/cosign-installer from 3.9.1 to 4.1.2 (#70)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T06:52:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec4d8dea64addb7d498fd7f0fd37fbd8bc674b10",
"body": "Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4.0.5 to 5.0.0.\n- [Release notes](https://github.com/actions/deploy-pages/releases)\n- [Commits](https://github.com/actions/deploy-pages/compare/d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e...cd2ce8fcbc39b97be8ca5fce6e763baed58fa1\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/deploy-pages from 4.0.5 to 5.0.0 (#68)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T06:49:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ca95344ee1efd895913b7e3d7c7bd004401b9980",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.6.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v5.6.0...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated-dependencies:\n- dependency-name: \n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/setup-go from 5.6.0 to 6.5.0 (#71)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T06:38:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8c30a59b47ad58a1894eb1214a87762caa3cb1d9",
"body": "Consolidate the [Unreleased] entries into [0.6.3]: SEC-06/11/12/13/14/15/17 +\nFU-7, broader agent detection, and the test expansion.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.3 (2026-07-03) (#67)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T14:45:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d6cb1fb2caf3714e0517f3597f7bf1a052b3cf6",
"body": "recipients rm just edited the recipient list and told you to run reencrypt,\nimplying the removed key was cut off. But that key can still decrypt any copy it\nalready had — backups, clones, and every prior version of the git-synced store.\nThe only true revocation of a value is to rotate it.\n\nMake reci\n[…]\nts decryptable,\n--no-reencrypt still removes, and an e2e that asserts the full stderr warning on\nthe real binary. Coverage 90.7%; -race + e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: make recipient removal honest about revocation (SEC-15) (#66)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T14:39:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6640f82df2a720f3bf3e7e9fb4fd0941d109faa2",
"body": "… (#65)\n\nAgent detection was a hardcoded switch for Claude Code and Cursor. Refactor it\ninto an extensible table (agentSignatures) and add two agents whose runtime\nmarkers are confirmed: Gemini CLI (GEMINI_CLI) and OpenAI Codex (CODEX_SANDBOX /\nCODEX_SANDBOX_NETWORK_DISABLED).\n\nFor agents that don't\n[…]\nker, the AI_AGENT fallback + version parse, built-in precedence, and\nthe no-false-positive-on-API-keys guarantee. Coverage 90.8%; -race + e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat: broaden AI-agent detection (Gemini CLI, Codex) + custom markers…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T14:29:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7caeebd3b7e121223f9b63acc938dfc6322eaf1",
"body": "New e2e (real-binary) tests for behavior that only had unit coverage or none:\n- TestDisableEnable: disabled secret refused on read paths, surfaced by show/ls,\n and enable preserves a real future expiry (SEC-13).\n- TestAnnotate: metadata-only edits (add/rm tag, desc, meta) never touch the value.\n- T\n[…]\n was spuriously failing TestHandles\nlocally). Tests that need agent behavior still set AI_AGENT via runEnv.\n\nCoverage 90.7%; -race + full e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "test: expand unit + e2e coverage for the 2026-07 security work (#64)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T14:20:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3230b7e5252d986fb71bda9c742ccf708906383c",
"body": "…C-06) (#63)\n\nApproval was gated by env-var-based agent detection: ARCA_APPROVAL=allow\npre-approved a release for a caller that did not look like an AI agent. But an\nagent controls its own environment and could unset the detection vars to pass as\na human and self-approve — defeating the one control \n[…]\ns refusal\nonly). Update THREAT-MODEL T2, POLICIES, CONFIGURATION, ARCHITECTURE.\n\nNot framed as breaking: ARCA_APPROVAL=allow was effectively unused.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: --require-approval requires a real human, no env bypass (SE…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T14:11:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d1e7dc407049c45bb94b069972704d26be2b776",
"body": "The store is a git-synced JSON file, so restoring an older copy — a git revert,\na sync conflict, or an attacker resurrecting a rotated or deleted secret — was\nundetectable; the audit log doesn't witness the store's contents.\n\nAdd a monotonic Generation counter to the store, bumped on every Save. ope\n[…]\nnces past it again.\n\nTests: Save bumps the generation; the high-water logic flags a regression, stays\nhigh across a rollback, and clears on advance.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: warn when the store is rolled back (SEC-14) (#62)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T13:25:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dd5e7ccee5309a265772ea5859ce3aa3ba0b2505",
"body": "…(SEC-13) (#61)\n\ndisable suspended a secret by stamping expires_at to now, and enable cleared\nexpires_at entirely — so disabling then enabling a secret that carried a real\nfuture expiry silently wiped it (intent data-loss).\n\nAdd a dedicated store.Secret.Disabled field: disable sets it, enable clears\n[…]\nMCP surface\nhonors it. Repurposed the old TestEnableClearsHardExpiry (which asserted the very\nbug this fixes) into TestDisableEnablePreservesExpiry.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: model disable/enable as a distinct field, not expiry reuse …",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T13:18:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5be66f81d1219390055189dc82a3693382668eb3",
"body": "- SEC-12: get --no-log no longer evades a rate limit. Rate limits count audit\n rows, but --no-log skipped the read record, so a human could loop-read a\n rate-limited secret past its cap. --no-log is now ignored (with a note) for a\n rate-limited secret; still honored for ordinary secrets, never fo\n[…]\n refuses a short secret; --no-log doesn't evade a rate limit but still\nworks for ordinary secrets. Coverage 90.1%; race/vet/staticcheck/gosec clean.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: Group A hardening — SEC-11, SEC-12, SEC-17, FU-7 (#60)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T13:07:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba98955c65cf07a534fb57330bd0638b5fe4771f",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.2 (2026-07-03) (#59)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T12:50:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ed352254fc7db0daa1bd3d47d482956bfe0e1af",
"body": "The version was a header line (arca X.Y.Z) at a different column than the\ncommit/built/go/platform values below it. Make it a labeled 'version' row in a\nwidth-computed aligned table so every value lines up. --json output unchanged.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "fix: align arca version output into a single key/value column (#44)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T12:45:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32a1f7d7fc424d51a1bbb3ae04e54c4f3fe152fe",
"body": "The v0.6.1 cask/release checksum divergence had a deeper root cause than the\ndouble-run: the archives themselves aren't byte-reproducible. mod_timestamp\npins only the compiled binary (verified: the binary IS reproducible), but the\nbundled LICENSE/README/CHANGELOG take their on-disk checkout mtime, s\n[…]\n the\ncask — divergence is impossible, complementing the concurrency guard (#50) which\nserialized against it. Resolves the reproducibility follow-up.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: make release archives byte-reproducible (FU-8) (#58)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T03:22:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "827a155c606682497a2edc89284a631656e64db3",
"body": "…(#57)\n\nFollow-up fixes from the 2026-07-03 post-fix verification audit:\n\n- FU-1 (MEDIUM, completes SEC-09): the MCP list_secrets tool exposed per-secret\n last_read time, which advances when a handle is used (the underlying exec\n bumps the real secret's last-read). An agent holding only an opaque \n[…]\nsecrets omits last_read; run_with_handle refuses a tampered reserved\nenv name; show sanitizes a poisoned name; rename --force clears a stale canary.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: complete SEC-09 and audit follow-up hardening (FU-1..FU-4) …",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T03:17:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47a9620e3cbac0f382cb92e481b15574c15d938e",
"body": "…ing the value (#56)\n\nThere was no way to change a secret's tags/description/metadata after creation\nwithout re-entering its value: 'set' always re-prompts for the value, and a\n--no-print secret can't be re-piped at all (its value can't be read back). This\nmade simple relabeling impossible for exact\n[…]\n+ UpdatedAt unchanged, tag add/remove/replace, meta\nset/remove, desc set/clear, works on --no-print, audited, and the no-op /\nmissing-secret guards.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat: add 'arca annotate' to edit tags/description/meta without chang…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T02:56:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "08ea515b118999d47fd68b996d487d731f52bb24",
"body": "…ool (SEC-09) (#55)\n\nrun_with_handle is meant to let an agent use a secret without learning which\nsecret it is. But a handle-issued exec records the secret's real name with the\nhandle id (hdl_...) as caller, and the audit_log MCP tool returned events\nverbatim — so an agent could call audit_log and r\n[…]\ns, and that\nmapping is what audit_log leaked.\n\nTest: after using a handle, audit_log's handle events show the handle id, never\nthe real secret name.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: mask the secret name behind a handle in the audit_log MCP t…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T02:49:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0a353ad0ef252d3e2ee9820885aefa3a9b8df103",
"body": "The store lock released by deleting the lock file by path, and reclaimed a stale\nlock with a blind unlink. Two races followed: a process whose lock was reclaimed\ncould delete its successor's lock on release; and two processes could both\n'steal' the same stale lock, yielding two concurrent writers an\n[…]\njob.\n\nTests: ownership-checked release, heartbeat freshness, and a path-safe token\nguard. Existing lock + e2e concurrent-set tests pass under -race.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: token-owned store lock with heartbeat (SEC-08) (#54)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T02:42:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba9ec841a34a52de09cabc4ca11891af6a4ac07c",
"body": "…C-07) (#53)\n\nls/log/show — plus grants, handle ls, canary --list, and the canary alert —\nwrote secret descriptions/tags/meta and the audit log's agent/actor/caller/\nsession columns to the terminal raw. Those fields are attacker-influenced: a\npoisoned git-synced store, or a detected agent setting a \n[…]\n keeps Unicode), and end-to-end that a\ncrafted description/tag and a crafted $ARCA_ACTOR carry no escapes into\nshow/ls/log. Combined coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: sanitize terminal control characters in rendered output (SE…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T02:19:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8d60d32106d35957ba60bd9aef04ea6a65b841b",
"body": "… (SEC-05) (#52)\n\nrun_with_handle deliberately bypasses the require-grant/require-approval gates\n(the handle is the operator's pre-authorization), but 'handle create' only\nchecked that the secret existed. So a detected agent could mint itself a handle\nfor a require-approval/require-grant secret and \n[…]\ndeterministic regardless of what launched it (running inside a Claude Code\nsession set CLAUDECODE, which made every test caller look like an agent).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: restrict handle creation to close the grant/approval bypass…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-03T02:10:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5b51cf83dc3ae07e7f4b0a80101c92c398f23f3a",
"body": "The 'this is a decoy' flag was a cleartext `canary` field in store.json, which\nis git-synced. Anyone who obtained the store — the exact exfiltration a canary\nexists to catch — could read `\"canary\": true` and step around the decoys while\nlearning which entries are real, defeating the honeytoken again\n[…]\n trips, legacy store\nflag still trips + lists, rename follows, unmark/rm clean up, and the registry\nerror/failure branches. Combined coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: keep canary designation out of the synced store (SEC-04) (#51)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T14:38:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "934d3808a77ee6e40db114fc322da440f9b34faf",
"body": "…s (#50)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "ci: prevent duplicate release runs from publishing divergent artifact…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T14:21:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "60cbec54cca6c8a8df69125b973f5367d737d0de",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.1 (2026-07-02) (#49)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T13:51:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7890c8ef2d06ee74828b9e6216f9bd6ba816870c",
"body": "The nightly fuzz job went red on FuzzGlobMatch with:\n globMatch(\"*\", \"\\n\") = true; regexp reference = false\n\nglobMatch is correct: it is byte-based (HasPrefix/Index/HasSuffix), so '*'\nmatches any byte including a newline — the behaviour we want when matching a\ncommand string against a grant pattern\n[…]\nVerified: the CI-minimized input now passes and 90s / 1.47M execs of fuzzing\nfound no other discrepancy — globMatch itself is unchanged and correct.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "test: fix FuzzGlobMatch oracle to match glob newline semantics (#48)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T13:42:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "292e2b3792e8b19df444f78795784c5b23c21f5a",
"body": "…EC-03) (#47)\n\nlog --verify could return a clean result after a DB-writer rewrote history,\nbecause three tamper shapes were reported as benign rather than failed:\n\n1. Legacy downgrade: NULL every row's hash so the chain walk skips them and the\n log reports Checked=0/Legacy=N/OK=true. Fixed by reco\n[…]\nd (passes signed, fails stripped, rejected without --verify).\nExisting legacy-DB / truncation / empty-log tests still pass; combined coverage\n90.2%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: harden audit log verification against false-green tamper (S…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T13:37:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89300098e94578b96fd07a0e54d54f8a2a4d508d",
"body": "edit gated the access but never checked NoPrint before decrypting and handing\nthe plaintext to $EDITOR. Because the caller controls $EDITOR (EDITOR=cat,\nEDITOR='cp {} ...'), 'arca edit' was a disclosure path that get/inject/env and\nMCP read_secret all refuse — defeating the flagship --no-print contr\n[…]\nore decrypting, and point the user at\nrotate (which replaces the value without revealing the old one). Document it in\nPOLICIES.md and the CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: refuse to edit a --no-print secret (SEC-02) (#46)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T13:26:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f02fad675fd14d147e5e114ace1fec9b8688bd6",
"body": "A secret name that passes the identifier shape check but collides with an\nenvironment variable the child process trusts — PATH, LD_PRELOAD, DYLD_*, IFS,\nBASH_ENV, PROMPT_COMMAND, PYTHONPATH, NODE_OPTIONS, and kin — would hijack the\nprocess when injected by exec/env/run_with_secrets/handle. Because t\n[…]\ntion\nsite — so an already-poisoned store is refused there too. Update THREAT-MODEL\nT3, which previously claimed this was handled, and the CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "security: reject reserved env-var names as secret names (SEC-01) (#45)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-02T12:56:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "257641b1b39f6d19b11e08e56e21e3e3f1445397",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.6.0 (2026-07-01) (#43)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T20:50:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f08a6607d6bd1bd043c16346cdd6e34ec2e4c0ea",
"body": "…en release publish (#42)\n\n- 'arca version' prints version + VCS commit + build date + Go toolchain + platform\n (--json for scripts/agents). 'arca --version' still prints just the version string.\n- skills/arca/SKILL.md: a shippable Claude Code skill teaching an agent arca's\n 'use, don't reveal' wo\n[…]\nppened to v0.5.0).\n\nTests: version (human + --json) and formatVersion branch coverage. Docs: COMMANDS.md\nrow + CHANGELOG. Coverage 90.3% (gate 90%).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat: add 'arca version' subcommand and a shippable agent skill; hard…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T20:44:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9dc35c8d65d4dd93dc5a5abd6e48aa3d9605bb58",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: stamp CHANGELOG v0.5.0 (2026-07-01) (#41)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T20:24:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fbda872fb4bc86bf288e01ec13d4a7d235ccf6f",
"body": "…ts (#40)\n\nAdd 'arca disable NAME' / 'arca enable NAME' — a fast, reversible way to take\na secret out of service on every access path (get/exec/inject/env + MCP)\nwithout deleting it or changing its value. Implemented over the existing hard-\nexpiry mechanism (disable stamps expires_at=now, enable cle\n[…]\nclearing a hard expiry, and the not-found/no-store error paths. Docs:\nCOMMANDS.md reference + section, CHANGELOG entries. Coverage 90.2% (gate 90%).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat: add disable/enable kill switch; fix env aborting on gated secre…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T20:18:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48f1450856a8ac0fcde71378d2a8199ad36b789a",
"body": "Add a Documentation section + Docs nav link to the landing page, and a\ntools/docsgen generator that renders docs/*.md into standalone HTML pages\nmatching the landing page's look, plus an auto-generated docs.html catalog.\n\nThe generator is its own Go module so goldmark stays out of arca's main\ngo.mod\n[…]\nate/deploy, so published docs never drift from their Markdown source.\nGenerated HTML is git-ignored and rebuilt in CI; `make docs` previews locally.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: render Markdown docs into styled HTML in CI (#39)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T19:44:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a9dab6da2c6780adaf12d68a8a2b00d2ab5bb9fd",
"body": "The README had grown to ~530 lines with the command reference, config, storage model, MCP, importing, and six sprawling policy features inline. Trim it to an overview (why/features/install/quickstart/recipes/model) plus a Documentation index, and move the detail into docs/ topic pages:\n\n- docs/COMMA\n[…]\n source recipe matrix\n- docs/CONFIGURATION.md — ARCA_* env vars, paths, storage model\n\nEach page cross-links; nothing lost. README 530 -> 350 lines.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: split the README into docs/ topic pages (#38)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T18:15:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4e4f46186ac478991cb8b97152e02787341cbbc2",
"body": "Second test batch plus continuous fuzzing:\n\n- FuzzShellQuote (upgraded from a weak structural check to the authoritative one): a value quoted for 'eval \"$(arca env)\"' is round-tripped through a real shell — proving it can't inject.\n- TestEnvEvalSafety: end-to-end, a secret full of shell metacharacte\n[…]\nill answers a later valid request.\n\n- .github/workflows/fuzz.yml: nightly (and manual) job runs every fuzz target ~60s and uploads any crash corpus.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "test(ci): env/inject/MCP safety tests + nightly fuzz workflow (#37)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T18:02:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63274266d3c9260a9fd02778a06cfbc8bae1eec7",
"body": "A substantial test push focused on the security-critical invariants:\n\n- Fuzz targets: redaction never leaks the value (any value/output/chunking), globMatch always agrees with a regexp reference, import parsers never surface an unsafe name, validName only accepts the safe grammar, parseTTL/parseRate\n[…]\n one), verifying gate ordering.\n- Multi-secret redaction; a few error-path/fault-injection tests.\n\nCoverage 90.3%; race/vet/staticcheck/gosec clean.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "test: fuzz targets, property, concurrency, and cross-feature tests (#36)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T17:42:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2848c2831d25af31f7afef3877b696e1d03630fd",
"body": "Render log/ls/grants/handle-ls/stale as color-coded aligned tables on a terminal — bold teal header, dimmed timestamps, ops tinted by kind (green=use, amber=write, coral=alert/removal) — with no new dependencies. Column widths are computed from visible text (ANSI stripped) so colored cells align exa\n[…]\nk to plain tab-separated columns when piped so scripts stay parseable. Also fixes a latent ls header/row mismatch when the audit DB can't be opened.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(ui): color-coded terminal tables (zero-dependency ANSI) (#35)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T17:20:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb160028be90b793371dbd0902636f40d7d72583",
"body": "…process (#33)\n\nThe audit log showed a blank ACTOR and a blank CALLER for get/read (only exec set the caller). Populate both: detectIdentity falls back the actor to the OS user when $ARCA_ACTOR is unset, and recordAudit defaults the caller to the parent process command (via /proc on Linux, ps on mac\n[…]\n$ARCA_ACTOR still wins; exec's command caller is unchanged.\n\nAlso add tests for strict-audit invariants, the rate-limit bad-window fallback, and rm.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(audit): default actor to the OS user and caller to the invoking …",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T15:04:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ada1c26b37d548f2ae354040b79969d2fa458f8",
"body": "… (tier-2 moat B2) (#32)\n\nLet an agent USE a secret over MCP without learning its name or value, and without enumerating the store. 'arca handle create SECRET --ttl 1h [--command GLOB] [--as ENV]' mints an opaque token (hdl_...); the new MCP 'run_with_handle' tool resolves it, enforces the command s\n[…]\nMCP handler (run_with_handle incl. redaction, scope, rate-limit, canary, target-gone, run-error), and a black-box e2e over JSON-RPC. Coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(mcp): opaque capability handles + redact run_with_secrets output…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T14:43:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "499eaa91ed9e522a9d8446b5fe1b8dc2ca915a25",
"body": "Cap how often a secret may be used within a rolling window, to stop a runaway agent hammering it. 'set'/'generate --rate N/DURATION' (e.g. 10/1h) sets the policy; gate() refuses the access once the window's prior uses reach the cap and records the throttle (op=ratelimit), with a note on the last per\n[…]\nr roll back. Shown by 'show'; cleared with --rate ''. Honest boundary in SECURITY.md: a throttle, not a quota — a patient caller can spread use out.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(rate): per-secret rate limiting (tier-2 moat B1) (#31)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T14:20:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af1c98bcea130bb2f066f1d610129b6cd6b7eacb",
"body": "The site predated the agent-control-plane moats. Update the features grid and\nthe 'what makes it different' recipes to cover output redaction, the\ntamper-evident signed audit (log --verify), canary secrets, and just-in-time\ngrants; add a log --verify line to the quickstart. Design system unchanged.\n\nAlso align the README canary example's agent name with the site (malicious-agent).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs(site): refresh landing page for the v0.4.0 security features (#30)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T13:10:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "51e3a1b8822204b7f016eb40ce148d2a4e293aa6",
"body": "Roll the accumulated Unreleased changes into v0.4.0: import --json + ergonomics\nflags, exec output redaction, tamper-evident signed audit + log --verify, canary\nsecrets, and command-scoped just-in-time grants.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "release: v0.4.0 (#29)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T12:43:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eab3828e92349145ad6634742d19f444f70a76ee",
"body": "* feat(grants): command-scoped, just-in-time grants (moat #3)\n\nBind a secret to *what* an agent does, not just whether it can see it.\n\n- New per-secret flag --require-grant: such a secret is usable only via exec /\n MCP run_with_secrets, and only when a matching active grant exists. get / env\n / in\n[…]\nness so grants.json and session\nsigning keys never touch the real $HOME during tests.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "grants: command-scoped, just-in-time grants (moat #3) (#28)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-07-01T12:39:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32e8449e9ac6bbb73fc62f74ece90f3d8e480176",
"body": "Coverage was sitting at exactly 90.0% (the CI gate is <90). Add fault-injection\ntests for the lowest-covered error branches:\n- audit Record/Verify/LastOp/LastRead/Recent on a closed handle (DB-error paths)\n- redactWriter Write/Flush propagating a downstream writer error\n\nTotal coverage 90.0% -> 90.4%; audit package 87.7% -> 90.8%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "test: cover DB-error and redact-writer error paths for margin (#27)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T19:33:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e30ec6b8c428ab0c4b9ec169898cc92f2a2ec494",
"body": "… (#26)\n\nA canary is a decoy that should never legitimately be used; any use is a strong\nsignal that something is enumerating or exfiltrating secrets.\n\n- 'arca canary NAME --template stripe|github|aws|slack|generic' plants a\n realistic-looking decoy; 'set'/'generate --canary' mark an existing secre\n[…]\nicated attacker who inspects metadata can identify\nand avoid a canary; its value is catching the common case of an agent that uses\nwhat it can read.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(canary): decoy secrets that trip a signed alert on use (moat #4)…",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T19:22:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bc3172cb11c1647cf1f6b025cb0c3037b245f856",
"body": "Turn the audit log from advisory into tamper-evident and attributable.\n\n- Hash-chain every event: hashᵢ = SHA-256(hashᵢ₋₁ ‖ canonical(eventᵢ)), so an\n edit, deletion, or reordering breaks the chain and is detectable.\n- Sign each event's chain hash with the recording session's Ed25519 key (one\n key\n[…]\nests: clean/signed verify, detection of edit/delete/sig-forgery/truncation,\nlegacy-DB migration, empty log, and a CLI verify-then-tamper round trip.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(audit): tamper-evident, signed audit log (moat #2)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T18:58:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c174c1713c60387551887cb7123f1783a5a874e6",
"body": "Moat #1 of the agent-control-plane set. When a command run under 'arca exec'\nprints an injected secret, arca replaces the value with «arca:NAME» in the\ncaptured stdout/stderr before it reaches the reader (an AI agent, a log), and\nrecords the catch in the audit log (op=redact) as a potential-leak sig\n[…]\n the 'the command could still print it' caveat documented in SECURITY.md\nand the threat model, restating it as redacted-by-default defense in depth.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(exec): redact injected secret values from command output",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T18:21:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7bd6326b8f8ba3b3635f2f57e416b4f6bb41e70d",
"body": "…by default\n\n- import now skips a name that already exists instead of silently overwriting\n it; --overwrite restores replace-in-place. Stops a re-run from clobbering.\n- --dry-run previews the plan (new/overwrite/skip) and writes nothing; it\n doesn't even take the store lock.\n- --prefix namespaces \n[…]\nnames (re-validating the combined name), and\n --tag attaches tags to every imported secret.\n- README import table + examples and CHANGELOG updated.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(import): --dry-run, --overwrite, --prefix, --tag; skip existing …",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T18:03:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "586f0eba7ef515410bd1f360677a884ad3f7f0ae",
"body": "- import --json reads {\"KEY\":\"value\"} from stdin, the shape AWS Secrets\n Manager / Vault / 1Password / gcloud emit, so they pipe in without jq\n reshaping. String values pass through (multi-line JSON strings round-trip),\n numbers/bools are stringified, null/nested values are skipped.\n- import now \n[…]\ncipe\n matrix (sops/.env/JSON/1Password/Vault/AWS/GCP/pass/env), and set NAME < file\n for single multi-line blobs (PEM keys, service-account JSON).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "feat(import): JSON object input, audit every import, document sources",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T17:43:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c7ad8cac933d9c571d0abc06dae04ee7e09c6a6",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: show OpenSSF Baseline + Scorecard badges on the website footer",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T17:24:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b9595aaba230b9e9bb6247295cbfb3117d26ad61",
"body": "TestConcurrentSet intermittently failed on the Windows CI runner: 8 concurrent\n'arca set' processes serialize on the store lockfile, and on a loaded 2-core\nrunner the per-hold cost (process spawn + age encrypt + audit write) for the\nwaiters ahead could exceed the 5s acquisition window. 15s leaves he\n[…]\nended writes (also relevant to many-agent and slow/networked-FS use)\nwithout masking a genuinely stuck lock, which the 30s stale-lock steal handles.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "fix: widen store-lock timeout to 15s for contended writes",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T17:04:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ab96c123f4372542631dfac6dacc39d41b361ca",
"body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs: add OpenSSF Baseline badge to README",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T17:04:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2bf70ab24cca940187f75b7082f6b9ffb972b8ef",
"body": "Close the six Baseline Level 2 gaps:\n\n- DO-06.01: document how dependencies are selected, obtained, and tracked\n (new Dependencies section in CONTRIBUTING).\n- GV-01.01/02: add MAINTAINERS.md listing members, roles, and access to\n sensitive resources.\n- SA-01.01: add docs/ARCHITECTURE.md (actors, c\n[…]\nailer on every commit, enforced\n by a new dco CI check and documented in CONTRIBUTING.\n\nLink the new design and threat-model docs from SECURITY.md.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
"is_bot": false,
"headline": "docs,ci: meet OSPS Baseline Level 2 criteria",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T16:46:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7f444214a52d683b4f82a146a58d7cf4ab38ec3c",
"body": "TestMainEntry set os.Stdout to a pipe with a DISCARDED read end, then called main(). When the GC\nclosed that unread reader mid-write, the --version write broke ('broken pipe' / 'pipe is being\nclosed'), Execute returned an error, and main() called os.Exit(1) — killing the whole test\nbinary intermittently on any OS. Write to a temp file instead. Verified: 20x -race stress green.",
"is_bot": false,
"headline": "test: fix TestMainEntry pipe flake (the actual cross-OS failure)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T16:13:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24b7d6ac19957f76be5a8480740248c8e8c48ac6",
"body": "Remove embedded metadata (including the image generator's Exif 'Signature' string) from the\nlogo, favicon, and social card. Pixels and dimensions are unchanged; images verified usable.",
"is_bot": false,
"headline": "assets: strip image metadata (Exif/text chunks)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T16:13:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf151cf9589a0ef3dc8ed845a900b18630a9174d",
"body": "The harness swapped os.Stdin/os.Stdout with os.Pipe + goroutines; on Windows a pipe whose peer\nclosed early failed the write with 'the pipe is being closed', flaking the Windows test job.\nBack stdin/stdout with temp files instead — no reader/writer race, deterministic on every OS.\nRace suite + e2e green; coverage unchanged.",
"is_bot": false,
"headline": "test: file-backed execArca harness (fix Windows pipe-race flake)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T16:13:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "723c3d5b4ed664bb9f6f0c11c16d36138abd081d",
"body": "Document the three repos the project spans — arca (source), homebrew-tap and scoop-bucket\n(auto-published distribution artifacts) — in CONTRIBUTING.",
"is_bot": false,
"headline": "docs: list the project's repositories (OSPS-QA-04.01)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T16:13:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0e3fb2b015e9e135b8d93099fe676dd8f74a3ac",
"body": "- docs/: a static landing page (on-brand teal/coral from the logo) with copy-to-clipboard\n install commands, a favicon, an OG/Twitter social card (og.png, 1200x630), and an\n 'in practice' section showing the moat (use-without-revealing, agent-can't-read, ephemeral\n + audited). The page's logo cop\n[…]\n least-privilege, harden-runner). PRs validate only.\n- README: a Recipes section (exec/least-privilege, templating, generate+rotate, TTL, no-print/\n approval, teams, env, MCP, audit, dotfiles, JSON).",
"is_bot": false,
"headline": "site: GitHub Pages landing page + deploy CI; README recipes",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T15:30:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5cb8ac57a86552232a7dba7e51d91db35d491505",
"body": "Defines the SemVer contract for v1.0: stable surfaces (commands/flags, exit codes, store schema\nwith forward migration, arca:// references, ARCA_* config, policy semantics, --json shapes, MCP\ntool names) vs. what may change (human-readable text, internal packages, audit DB layout), plus\na deprecation policy and supported platforms. Linked from README + ToC; noted in CHANGELOG.",
"is_bot": false,
"headline": "docs: v1.0 stability policy (STABILITY.md)",
"author_name": "Ismael Arenzana",
"author_login": "arenzana",
"committed_at": "2026-06-30T14:58:05Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 16,
"commits_last_year": 135,
"latest_release_at": "2026-07-27T12:03:37Z",
"latest_release_tag": "v0.9.0",
"releases_from_tags": false,
"days_since_last_push": 2,
"active_weeks_last_year": 5,
"days_since_latest_release": 2,
"mean_days_between_releases": 2.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/arenzana/arca",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/arenzana/arca",
"is_deprecated": false,
"latest_version": "v0.9.0",
"repository_url": "https://github.com/arenzana/arca",
"versions_count": 16,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-27T10:09:32Z",
"latest_version_yanked": null,
"days_since_latest_publish": 2
}
]
},
"popularity": {
"forks": 0,
"stars": 1,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod",
"tools/docsgen/go.mod"
],
"largest_source_bytes": 90985,
"source_files_sampled": 100,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.18.6",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5841"
],
"fixed_version": "1.18.7",
"advisory_count": 1,
"oldest_advisory_days": 1
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 21
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.55.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5942"
],
"fixed_version": "0.56.0",
"advisory_count": 1,
"oldest_advisory_days": 14
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.38.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 14
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 4
},
"advisory_count": 4,
"affected_count": 4,
"assessed_count": 38,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "filippo.io/age",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.1"
},
{
"name": "github.com/mark3labs/mcp-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.57.0"
},
{
"name": "github.com/minio/minio-go/v7",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v7.2.1"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "golang.org/x/term",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.54.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "filippo.io/age",
"direct": true,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/mark3labs/mcp-go",
"direct": true,
"version": "v0.57.0",
"ecosystem": "go"
},
{
"name": "github.com/minio/minio-go/v7",
"direct": true,
"version": "v7.2.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "modernc.org/sqlite",
"direct": true,
"version": "v1.54.0",
"ecosystem": "go"
},
{
"name": "filippo.io/hpke",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/google/jsonschema-go",
"direct": false,
"version": "v0.4.2",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.18.6",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/cpuid/v2",
"direct": false,
"version": "v2.2.11",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/crc32",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.22",
"ecosystem": "go"
},
{
"name": "github.com/minio/crc64nvme",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/minio/md5-simd",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/ncruces/go-strftime",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/philhofer/fwd",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/remyoudompheng/bigfft",
"direct": false,
"version": "v0.0.0-20230129092748-24d4a6f8daec",
"ecosystem": "go"
},
{
"name": "github.com/rs/xid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"direct": false,
"version": "v6.0.2",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": false,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/tinylib/msgp",
"direct": false,
"version": "v1.6.1",
"ecosystem": "go"
},
{
"name": "github.com/yosida95/uritemplate/v3",
"direct": false,
"version": "v3.0.2",
"ecosystem": "go"
},
{
"name": "github.com/yuin/goldmark",
"direct": false,
"version": "v1.8.4",
"ecosystem": "go"
},
{
"name": "github.com/zeebo/xxh3",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.55.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/ini.v1",
"direct": false,
"version": "v1.67.2",
"ecosystem": "go"
},
{
"name": "modernc.org/libc",
"direct": false,
"version": "v1.74.1",
"ecosystem": "go"
},
{
"name": "modernc.org/mathutil",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "modernc.org/memory",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 38,
"direct_count": 6,
"indirect_count": 32
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 106,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 7
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "arenzana",
"commits": 122,
"avatar_url": "https://avatars.githubusercontent.com/u/5133407?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"dco.yml",
"fuzz.yml",
"pages.yml",
"release-dryrun.yml",
"release.yml",
"scorecard.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 2,
"reason": "badge detected: InProgress",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/22 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 8,
"reason": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 6,
"reason": "4 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "d4266fc063fe16f1045ea891941c03548a7aa735",
"ran_at": "2026-07-29T13:02:23Z",
"aggregate_score": 7.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-29T08:02:45Z",
"oldest_open_prs": [
{
"number": 109,
"created_at": "2026-07-26T06:27:52Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-27T10:09:33Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/arenzana/arca",
"host": "github.com",
"name": "arca",
"owner": "arenzana"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"security": 78,
"vitality": 74,
"community": 43,
"governance": 52,
"engineering": 77
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"commits_last_year": 135,
"human_commit_share": 0.87,
"days_since_last_push": 2,
"active_weeks_last_year": 5
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "5/52 weeks with commits",
"points": 3.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 5
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "135 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 135
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"releases_count": 16,
"latest_release_tag": "v0.9.0",
"releases_from_tags": false,
"days_since_latest_release": 2,
"mean_days_between_releases": 2.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "16 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 16
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 43,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 1,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "1 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 1
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 52,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 67,
"inputs": {
"merged_prs": 106,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 7
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "106/113 decided PRs merged",
"points": 35.9,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 106,
"decided": 113
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 49,
"inputs": {
"followers": 8,
"owner_type": "User",
"is_verified": null,
"owner_login": "arenzana",
"public_repos": 24,
"account_age_days": 4745
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "8 followers of arenzana",
"points": 6.9,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 8,
"login": "arenzana"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "24 public repos, account ~13 yr old",
"points": 22.2,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 24
}
},
{
"code": "account_age_years",
"params": {
"years": 13
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/arenzana/arca"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 2
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 2 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 2
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "16 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 16
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 77,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "8 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 8
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://arenzana.github.io/arca/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://arenzana.github.io/arca/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 78,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 7.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "badge detected: InProgress",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "4 existing vulnerabilities detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 38 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 38
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 4,
"affected_packages": 4,
"assessed_packages": 38,
"unassessed_packages": 0,
"affected_by_severity": "unknown 4",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 38,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 69,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 87,
"sampled": 87
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod",
"tools/docsgen/go.mod"
],
"dependency_bot_commit_share": 0.13
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "13 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 13,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 90985,
"source_files_sampled": 100,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/100 source files over 60KB",
"points": 54.5,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 100,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-29T13:02:40.793934Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/arenzana/arca.svg",
"full_name": "arenzana/arca",
"license_state": "standard",
"license_spdx": "MIT"
}