Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 09:49 UTC

cyanheads / mcp-ts-core

Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.

TypeScriptApache-2.0★ 147 зірок⑂ 29 форківз бер. 2025 р.Переглянути на GitHub ↗

cyanheads/mcp-ts-core має індекс здоров’я 65 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (93/100), найнижчий — Security (47/100). Останнє оновлення було 3 дні тому. Більшість нещодавньої роботи виконує один учасник.

65
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

65
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Casey HandОсобистий обліковий запис
175 підписників146 публічних репозиторіївз груд. 2014 р.

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npm@cyanheads/mcp-ts-core0.10.1544 6181425 днів томуagentagent-nativeaiai-agentbuncloudflare-workersdeclarativeframeworkmcpmcp-servermcp-frameworkmodel-context-protocolobservabilityopentelemetrytoolstypescript

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

93Відмінний · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 3 дн. тому
23.5/36Ритм комітів — 34/52 тижнів із комітами
18/18Обсяг комітів — 1 289 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year1 289
human_commit_share1
days_since_last_push3
active_weeks_last_year34
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 33 релізів
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~4,2 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count33
latest_release_tagv0.10.15
releases_from_tagsні
days_since_latest_release5
mean_days_between_releases4,2
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

56Помірний · 18% загального індексу
Як обчислюється оцінка
35.1/60Зірки — 147 зірок
12.1/25Форки — 29 форків
0/15Спостерігачі — 2 спостерігачів
Використані вхідні дані
forks29
stars147
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
62/80Щомісячні завантаження — 44 618 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@cyanheads/mcp-ts-core
dependents
ecosystemsnpm
total_downloads
monthly_downloads44 618
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

55Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0.1/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
2.7/13.5Широта контриб’юторів — 2 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled2
top_contributor_share0,995
Як обчислюється оцінка
35.9/46.8Вирішення issue — закрито 77% issue
19.1/38.3Прийняття PR — злито 13/26 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs13
open_issues59
closed_issues195
issue_closed_ratio0,768
closed_unmerged_prs13
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
16.1/25Охоплення власника — 175 підписників у cyanheads
25/25Послужний список — 146 публічних репозиторіїв, вік облікового запису ~11 р.
Використані вхідні дані
followers175
owner_typeUser
is_verified
owner_logincyanheads
public_repos146
account_age_days4 225
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 142 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@cyanheads/mcp-ts-core
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

70Добрий · 20% загального індексу
Як обчислюється оцінка
0/24Процеси CI
24/24Наявні тести
16/16Конфігурація лінтера — biome.json
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciні
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

100Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://www.npmjs.com/package/@cyanheads/mcp-ts-core
10/10Опис репозиторію
10/10Теми — 10 тем
10/10Wiki
Використані вхідні дані
topicsmcp, mcp-server, model-context-protocol, ai, opentelemetry, cloudflare-workers, agent-native, framework, typescript, cyanheads
has_wikiтак
homepagehttps://www.npmjs.com/package/@cyanheads/mcp-ts-core
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

47У зоні ризику · 16% загального індексу

Стан безпеки

37У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
0/10Dangerous-Workflow — немає даних
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — немає даних
0/5Pinned-Dependencies — немає даних
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — немає даних
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate3,7
Виключено з оцінювання (немає даних або не застосовно): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
13.2/25Непрямі залежності без відомих сповіщень — уражено 1: @hono/node-server 1.19.15 (moderate 5.9)
40/40Немає задавнених сповіщень — жодне сповіщення не є публічним довше за 90 дн.
Використані вхідні дані
sourceosv
advisories1
affected_packages1
assessed_packages115
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Звірено з runtime-замиканням залежностей npm:@cyanheads/mcp-ts-core@0.10.15 — тим, що тягне за собою встановлення опублікованого пакета, — 115 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

74Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 100 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
agent_instruction_max_bytes39 823
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — biome.json
11/11Статична перевірка типів — tsconfig.json
10/10Відтворюване середовище — Dockerfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — немає даних
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileтак
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Pinned-Dependencies. Залишкові ваги перенормовано.
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
55/55Керовані розміри файлів — 0/445 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes54 037
source_files_sampled445
oversized_source_files0
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalтак
api_schema_files

Ключові факти

147зірок GitHub
2контриб'юторів
1 289комітів за останні 12 місяців
3днів від останнього пушу
33релізів
1бас-фактор
59відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package '{{PACKAGE_NAME}}' from its registry

Докладніше

Історія зірок і форків 0 ★ / 29 ⇿
0Зірки
29Форки
28Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

0510152025302922025-042025-112026-07
Мажорні 0Мінорні 1Патчі 27

Кожна точка охоплює 2 днів.

OpenSSF Scorecard 3.7 / 10
3.7сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 09:49 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
н/дDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
н/дPackagingpackaging workflow not detected
н/дPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
н/дToken-PermissionsNo tokens found
1Vulnerabilities9 existing vulnerabilities detected
Прямі залежності 13
РеєстрПакетОбмеження версіїМаніфест
npm@hono/mcp^0.3.1package.json
npm@hono/node-server^2.0.10package.json
npm@modelcontextprotocol/ext-apps^1.7.4package.json
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@opentelemetry/api^1.9.1package.json
npmdotenv^17.4.2package.json
npmhono^4.12.30package.json
npmjose^6.2.3package.json
npmpino^10.3.1package.json
npmzod^4.4.3package.json
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}templates/package.json
npmpino-pretty^13.1.3templates/package.json
npmzod{{ZOD_VERSION}}templates/package.json
Усі залежності 66

Повний розв'язаний набір залежностей із графа залежностей GitHub: 13 прямих і 53 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}пряма
npm@hono/mcp^0.3.1пряма
npm@hono/node-server^2.0.10пряма
npm@modelcontextprotocol/ext-apps^1.7.4пряма
npm@modelcontextprotocol/sdk^1.29.0пряма
npm@opentelemetry/api^1.9.1пряма
npmdotenv^17.4.2пряма
npmhono^4.12.30пряма
npmjose^6.2.3пряма
npmpino^10.3.1пряма
npmpino-pretty^13.1.3пряма
npmzod^4.4.3пряма
npmzod{{ZOD_VERSION}}пряма
npm@biomejs/biome2.5.4непряма
npm@cloudflare/vitest-pool-workers^0.18.4непряма
npm@cloudflare/workers-types5.20260706.1непряма
npm@duckdb/node-api^1.5.4-r.1непряма
npm@hono/otel^1.1.2непряма
npm@opentelemetry/exporter-metrics-otlp-http^0.220.0непряма
npm@opentelemetry/exporter-trace-otlp-http^0.220.0непряма
npm@opentelemetry/instrumentation-http^0.220.0непряма
npm@opentelemetry/instrumentation-pino^0.66.0непряма
npm@opentelemetry/resources^2.9.0непряма
npm@opentelemetry/sdk-metrics^2.9.0непряма
npm@opentelemetry/sdk-node^0.220.0непряма
npm@opentelemetry/sdk-trace-node^2.9.0непряма
npm@opentelemetry/semantic-conventions^1.43.0непряма
npm@socketsecurity/bun-security-scanner^1.1.2непряма
npm@supabase/supabase-js^2.110.6непряма
npm@types/bun^1.3.14непряма
npm@types/node26.1.1непряма
npm@types/papaparse^5.5.2непряма
npm@types/sanitize-html^2.16.1непряма
npm@types/validator^13.15.10непряма
npm@vitest/coverage-istanbul4.1.10непряма
npm@vitest/ui4.1.10непряма
npmbetter-sqlite3^12.11.1непряма
npmbun-types^1.3.14непряма
npmchrono-node^2.10.0непряма
npmclipboardy^5.3.1непряма
npmdefuddle^0.19.1непряма
npmdepcheck^1.4.7непряма
npmdiff^9.0.0непряма
npmexeca^9.6.1непряма
npmfast-check^4.9.0непряма
npmfast-xml-parser^5.10.1непряма
npmignore^7.0.5непряма
npmignore^7.0.6непряма
npmjs-yaml^5.2.1непряма
npmlinkedom^0.18.13непряма
npmnode-cron^4.6.0непряма
npmopenai^6.46.0непряма
npmpapaparse^5.5.4непряма
npmpartial-json^0.1.7непряма
npmpdf-lib^1.17.1непряма
npmrepomix^1.16.1непряма
npmsanitize-html^2.17.6непряма
npmtsc-alias^1.9.0непряма
npmtsc-alias^1.9.1непряма
npmtypedoc^0.28.20непряма
npmtypescript^6.0.3непряма
npmunpdf^1.6.2непряма
npmvalidator^13.15.35непряма
npmvite8.1.5непряма
npmvitest^4.1.10непряма
npmvitest^4.1.9непряма
Сповіщення про залежності 1

Встановлення npm:@cyanheads/mcp-ts-core@0.10.15 тягне 115 пакетів, прямих і транзитивних: 1 мають відомі сповіщення, з них 0 — прямі залежності.

ПакетВерсіяЗв'язокКритичністьСповіщеньВиправлено в
@hono/node-server1.19.15непрямапомірна12.0.5

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "ai",
        "opentelemetry",
        "cloudflare-workers",
        "agent-native",
        "framework",
        "typescript",
        "cyanheads"
      ],
      "is_fork": false,
      "size_kb": 8898,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
      "languages": {
        "Shell": 102,
        "Dockerfile": 9732,
        "JavaScript": 109642,
        "TypeScript": 3872892
      },
      "pushed_at": "2026-07-22T01:11:54Z",
      "created_at": "2025-03-20T05:07:04Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T18:42:03Z",
      "description": "Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://caseyjhand.com",
      "name": "Casey Hand",
      "type": "User",
      "login": "cyanheads",
      "company": null,
      "location": "Seattle, WA",
      "followers": 175,
      "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4",
      "created_at": "2014-12-29T13:01:12Z",
      "is_verified": null,
      "public_repos": 146,
      "account_age_days": 4225
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.15",
          "kind": "patch",
          "published_at": "2026-07-19T12:24:31Z"
        },
        {
          "tag": "v0.10.14",
          "kind": "patch",
          "published_at": "2026-07-06T08:08:16Z"
        },
        {
          "tag": "v0.10.13",
          "kind": "patch",
          "published_at": "2026-07-05T18:04:33Z"
        },
        {
          "tag": "v0.10.12",
          "kind": "patch",
          "published_at": "2026-07-05T08:45:52Z"
        },
        {
          "tag": "v0.10.11",
          "kind": "patch",
          "published_at": "2026-07-05T05:59:38Z"
        },
        {
          "tag": "v0.10.10",
          "kind": "patch",
          "published_at": "2026-06-30T09:19:32Z"
        },
        {
          "tag": "v0.10.9",
          "kind": "patch",
          "published_at": "2026-06-20T07:52:14Z"
        },
        {
          "tag": "v0.10.8",
          "kind": "patch",
          "published_at": "2026-06-19T23:56:33Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-06-19T21:26:53Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-06-11T20:27:22Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-06-11T16:51:26Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-06-11T01:20:20Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-06-10T23:14:46Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-10T17:48:09Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-08T14:46:42Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-05T12:16:41Z"
        },
        {
          "tag": "v0.9.21",
          "kind": "patch",
          "published_at": "2026-06-02T09:05:28Z"
        },
        {
          "tag": "v0.9.20",
          "kind": "patch",
          "published_at": "2026-06-02T03:44:02Z"
        },
        {
          "tag": "v0.9.19",
          "kind": "patch",
          "published_at": "2026-05-31T11:08:20Z"
        },
        {
          "tag": "v0.9.18",
          "kind": "patch",
          "published_at": "2026-05-31T10:18:08Z"
        },
        {
          "tag": "v0.9.17",
          "kind": "patch",
          "published_at": "2026-05-31T05:42:27Z"
        },
        {
          "tag": "v0.9.16",
          "kind": "patch",
          "published_at": "2026-05-30T03:28:09Z"
        },
        {
          "tag": "v0.9.15",
          "kind": "patch",
          "published_at": "2026-05-30T02:47:15Z"
        },
        {
          "tag": "v0.9.14",
          "kind": "patch",
          "published_at": "2026-05-29T11:58:20Z"
        },
        {
          "tag": "v0.9.13",
          "kind": "patch",
          "published_at": "2026-05-29T01:58:44Z"
        },
        {
          "tag": "v0.9.12",
          "kind": "patch",
          "published_at": "2026-05-29T00:42:33Z"
        },
        {
          "tag": "v0.9.11",
          "kind": "patch",
          "published_at": "2026-05-28T08:26:20Z"
        },
        {
          "tag": "v0.9.10",
          "kind": "patch",
          "published_at": "2026-05-27T04:33:29Z"
        },
        {
          "tag": "v0.9.9",
          "kind": "patch",
          "published_at": "2026-05-24T10:13:49Z"
        },
        {
          "tag": "v0.9.8",
          "kind": "patch",
          "published_at": "2026-05-24T09:30:02Z"
        },
        {
          "tag": "v0.9.7",
          "kind": "patch",
          "published_at": "2026-05-23T16:45:02Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-05-23T10:27:23Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-05-23T08:40:15Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
          "body": "…fields, expectedStatuses opt-out",
          "is_bot": false,
          "headline": "chore(release): 0.10.15 — Retry-After honoring, canonical HTTP error …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:20:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac3b9e5aee765fdbacc4415b997ab0f9925284d7",
          "body": "Dependency arrows of note: @biomejs/biome 2.5.2 -> 2.5.4 (biome.json\nschema migrated via 'bunx biome migrate'), @cloudflare/vitest-pool-workers\n^0.18.0 -> ^0.18.4, @opentelemetry/semantic-conventions ^1.41.1 -> ^1.43.0,\nhono ^4.12.27 -> ^4.12.30, vite 8.1.3 -> 8.1.5, vitest/@vitest/coverage-istanbul\n[…]\n'\ncasts; fixed across 7 test files by extracting the cast to a local\nbefore the property access (behavior-preserving). The remaining 2 test\nfiles carry only Biome's it.each argument-list reformatting.",
          "is_bot": false,
          "headline": "chore(deps): bun update; biome 2.5.4 migration; typescript 7 held",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:18:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53ed7cd01b96c3d45a6b9c81f4a0d6dd53f4009d",
          "body": "…l-defs-analysis 1.4\n\ngit-wrapup: tag-annotation format overhauled to a flat-bullet headline\ndigest — no Keep-a-Changelog section headers, no gates line, deps\ncapped at one line naming only what earns it; notable changes get\ntheir own bullet, minor/internal items share one grouped bullet.\norchestrat\n[…]\ns (naming taxonomy, parameter vocabulary, tool overlap,\ninstructions drift, length outliers).\n\nfield-test-fix.md, fix-wrapup-release.md, maintenance-release.md updated\nto reference the new tag format.",
          "is_bot": false,
          "headline": "docs(skills): field-test 2.7, git-wrapup 1.8, orchestrations 1.7, too…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c00f24e7bb63d33f562e0d701faacb162badcdb",
          "body": "The 0.10.13 agent-notes told downstream maintenance agents to add a\ntrustedDependencies entry alongside the @socketsecurity/bun-security-scanner\ndevDependency. No such entry exists in that release — the instruction\nwould send an adopting agent looking for something that isn't there.",
          "is_bot": false,
          "headline": "docs(changelog): drop trustedDependencies from 0.10.13 notes (#281)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "685203b8c8ab1c8be4e4df458fc9001295924de9",
          "body": "…ror fields (#256, #279)\n\nfetchWithTimeout gains options.expectedStatuses: number[] — a listed\nnon-2xx status logs at debug instead of error; the thrown, status-mapped\nMcpError is unchanged. Also stops double-logging: the catch block now\nre-throws a FetchHttpError-tagged McpError as-is instead of re\n[…]\nside the\npre-existing statusCode/responseBody aliases (kept, identical values) so\na consumer can read either helper's error the same way.\n\nskills/api-utils/SKILL.md documents both changes (2.4 → 2.5).",
          "is_bot": false,
          "headline": "feat(network): expectedStatuses log opt-out; canonical status/body er…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d6143cc8c91701025dbe292b8521de24244b1fd",
          "body": "Parses an upstream Retry-After hint (RFC 9110 §10.2.3 delta-seconds\nor HTTP-date) off McpError.data.retryAfter and waits that long instead\nof blind exponential backoff. The honored delay is not jittered. When\nthe requested wait exceeds maxDelayMs, the error is treated as\nnon-transient and fails fast with the original error rather than\nburning an attempt that can't succeed in time.",
          "is_bot": false,
          "headline": "feat(network): withRetry honors Retry-After (#285)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "352addd4d50a55cd73c04c64e7a86bad0fa0c671",
          "body": "Split the dense post-snippet block into shorter paragraphs, cut a redundant sentence, and tighten wording. Facts and code samples unchanged.",
          "is_bot": false,
          "headline": "docs: condense README intro prose",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T09:26:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a6235c923aaabfd4b172cad81a919a38e6b482",
          "body": "…oc fixes\n\nVersion bumps across package.json, server.json, README, CLAUDE.md, AGENTS.md; changelog 0.10.14; regenerated CHANGELOG.md rollup and docs/tree.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.14 — Docker build, linter null guard, canvas + d…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "738a6bb9bd6431b49f012ddc504f7b23332011db",
          "body": "…262)\n\nA bare-token curl 404s on the multi-arch OCI indexes docker buildx pushes; the manifest-list Accept header is missing. docker manifest inspect resolves them and exits non-zero when the tag is genuinely absent.",
          "is_bot": false,
          "headline": "docs(release-and-publish): verify GHCR via docker manifest inspect (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f40d4383847f5ce21f3f9e67ee0a95b9c8bbbbe",
          "body": "…minated union (#249)\n\nOUTLINE_VARIANT and outlineOnOverflow JSDoc and the techniques, add-tool, and design-mcp-server skills advertised a z.discriminatedUnion output that tool() rejects (schema-is-object lint and enrichment .extend() are ZodObject-only). Document the flat z.object with a kind discriminator and presence-based optional arms, rendered per field presence in format(). Docs and JSDoc only; no runtime change.",
          "is_bot": false,
          "headline": "docs(overflow): correct outline output to a flat object, not a discri…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb9a6321d856dac49592da1511695db6f22eba19",
          "body": "…overy (#264)\n\nMirror the missing_table precedent from query(): the source-table-not-found throw in DuckdbProvider.importFrom now sets reason missing_table plus a recovery hint. The sibling import_same_canvas and import_view_clash throws gain recovery hints too.",
          "is_bot": false,
          "headline": "fix(canvas): importFrom missing-table NotFound carries reason and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13dbdbdbefa7b7a87ec76640a328c5eb4787f58e",
          "body": "… entry (#265)\n\nA null or undefined entry in a tools/resources/prompts array threw a TypeError and aborted validateDefinitions; only the prompts path survived. Harden the three shared sub-linters (lintEnrichmentContract, lintCappedListTruncation, lintHandlerBody) to early-return on a non-object def, and guard each per-definition loop before dispatch, emitting one definition-invalid error per bad entry. Adds src/linter/rules/definition-rules.ts.",
          "is_bot": false,
          "headline": "fix(linter): surface definition-invalid instead of crashing on a null…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a546e8e4db6d71236bce5049dd938ebc38f5f13",
          "body": "The build stage ran every dependency lifecycle script; better-sqlite3 prebuild-install falls back to node-gyp (absent in oven/bun) and exits 127, failing the build. Match the production stage with --ignore-scripts: the build only runs tsc, which needs type declarations, not native bindings. templates/Dockerfile mirrors it.",
          "is_bot": false,
          "headline": "fix(build): install with --ignore-scripts in Docker build stage (#267)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:04:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e82602fdbf699318a63a740bca990d3ca0061e92",
          "body": "…ization",
          "is_bot": false,
          "headline": "chore(release): 0.10.13 — supply-chain guard, coverage, config modern…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29e3ceb99a7453a83f620f5e08e8f0e617566ed8",
          "body": "AGENTS.md and CLAUDE.md note that init now scaffolds bunfig.toml, LICENSE, and .gitattributes. .github/FUNDING.yml trims to the active github and buy_me_a_coffee entries; LICENSE copyright year 2025 → 2026 (still Apache-2.0).",
          "is_bot": false,
          "headline": "docs: sync consumer-path list; trim FUNDING; LICENSE year 2026",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53aca5fc19253a53c30aa365e3bac7c591b6f8c3",
          "body": "…lish-docs-meta 2.11\n\napi-workers documents the @duckdb/node-api Worker stub alias. git-wrapup and orchestrations add the changelog-link final line to tag bodies. polish-docs-meta covers manifest.json author identity plus author/packageManager/engines metadata guidance.",
          "is_bot": false,
          "headline": "docs(skills): api-workers 1.6, git-wrapup 1.7, orchestrations 1.6, po…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7940d011996224e29aaf1dc506352cbfb0cb9d87",
          "body": "init now copies an Apache-2.0 LICENSE and a .gitattributes (LF normalization, binary-asset and machine-generated markers) into newly scaffolded servers.",
          "is_bot": false,
          "headline": "feat(templates): scaffold LICENSE and .gitattributes",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f5027b6404f6ef5fa4d3d16f2b36b73f8d34b2",
          "body": "tsconfig.json extends a deduped tsconfig.base.json; the base moves target/lib ESNext → ES2025 (plus ESNext.TypedArrays). Dockerfile and templates/Dockerfile pin oven/bun:1.3.14 and add BuildKit install-cache mounts. .gitattributes overhauls the lockfile and linguist-generated markers and the git-arc\n[…]\nommit gains a POSIX shebang. Stricter-tsconfig script fixes: devdocs.ts explicit return, lint-mcp.ts conditional packageJson spread, tree.ts entries() iteration. typedoc drops the scripts entry point.",
          "is_bot": false,
          "headline": "build: modernize tsconfig, Dockerfile, and tooling config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e0fbfd49e4365027c17e8ae8e8623e47bddb49b",
          "body": null,
          "is_bot": false,
          "headline": "chore: drop Smithery deployment config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69433f431c6e695df623a831b57561d1f34d1821",
          "body": "wrangler.toml becomes wrangler.jsonc (schema-referenced, inline comments). An alias maps @duckdb/node-api to examples/duckdb-stub.ts so wrangler's esbuild step stops failing on DuckDB's native bindings — the DataCanvas provider's lazy import() is statically reachable from the Worker entry but never executes there.",
          "is_bot": false,
          "headline": "build(workers): migrate wrangler config to JSONC; stub @duckdb/node-api",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "114edd0339601adcc4294ffab99e024c7ce236c0",
          "body": "bunfig.toml adds a 3-day minimumReleaseAge hold on fresh publishes and an [install.security] Socket scanner; package.json declares the @socketsecurity/bun-security-scanner devDependency and trusts it. devcheck's Outdated gate now skips versions bun holds by release age (Update == Current, marked *),\n[…]\n .github/SECURITY.md adds a disclosure policy.\n\npackage.json also drops the unused main/types fields, adds a prepare hook-path script, bumps packageManager to bun@1.3.14, and sets the author identity.",
          "is_bot": false,
          "headline": "chore(security): minimumReleaseAge hold + Socket install scanner",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e301d1fe4e54c48702db126410acbeedbcb99554",
          "body": "…/services",
          "is_bot": false,
          "headline": "test: expand unit coverage; move DuckDB smoke suite under tests/smoke…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:58:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebbb12bfe2a8e37cbbccface856c59a9ae758c98",
          "body": "…separator",
          "is_bot": false,
          "headline": "chore(release): 0.10.12 — canvas error contracts, enrichment trailer …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c415f70563ad2bef2ae6eda735f136151f24269",
          "body": "…h (#261, #254)\n\nCanvasRegistry's not-found throws (acquire, touchOrThrow, touchWithTable, touchWithSqlTables) and DuckdbProvider.requireCanvas() now carry data.reason 'canvas_not_found', the canvasId, and a default recovery.hint, so consumer-declared canvas_not_found error contracts populate on the\n[…]\ny-structured McpError unchanged instead of reclassifying it to DatabaseError, preserving register_as_clash and export_path_* ValidationError codes and data across all four provider catch sites (#254).",
          "is_bot": false,
          "headline": "fix(canvas): structured canvas_not_found errors, McpError pass-throug…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07928d739c5ab069b8ca38c5339a2517bb0906c3",
          "body": "Clients that concatenate adjacent content[] text blocks with no join (Claude Desktop, claude.ai) rendered the trailer glued onto the last domain line. Markdown collapses consecutive blank lines, so clients that insert their own separator render at most one blank line either way.",
          "is_bot": false,
          "headline": "fix(tools): lead enrichment trailer with a blank-line separator (#257)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0c35f0558e3375079acc9212ffb7937b7ece8c9",
          "body": "…ics, dep refresh",
          "is_bot": false,
          "headline": "chore(release): 0.10.11 — scaffold devcheck fix, security-flag semant…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf33b280dfaf83378157eafb3961dfbb3cfea0a3",
          "body": "…overy discipline\n\nAdds the Reference tool shape to the taxonomy (decoder ring for opaque domain vocabulary — codes, enums, identifier formats; the standing target of recovery routing; implement first) with its own subsection. API probing gains unknown-param and omission-semantics probes, and the st\n[…]\nfalse, guidance } instead of throwing, zero-hit behavior is specced at design time, and design docs settle verbatim recovery strings under a no-dead-ends rule (each names the concrete next tool call).",
          "is_bot": false,
          "headline": "docs(skills): design-mcp-server 2.19 — reference tools, probe and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8199830341c44d465e6c02bbd98e7224ae512d2e",
          "body": "@biomejs/biome 2.5.1 → 2.5.2 (biome.json $schema follows), @cloudflare/vitest-pool-workers ^0.16.20 → ^0.18.0, @cloudflare/workers-types 4.20260630.1 → 5.20260705.1, @opentelemetry/* 0.219→0.220 and 2.8→2.9 sets, @opentelemetry/instrumentation-pino ^0.65.0 → ^0.66.0, @supabase/supabase-js ^2.109.0 →\n[…]\nte 8.1.0 → 8.1.3.\ntemplates/package.json pins @biomejs/biome 2.5.2 and @types/node 26.1.0 so a fresh scaffold's Biome CLI matches the shared config's $schema and devcheck passes out of the box (#260).",
          "is_bot": false,
          "headline": "chore(deps): bun update --latest; align template biome/types pins (#260)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8ff580bcbf7110eb5539d859339c768a02a657c",
          "body": "…263)\n\n0.9.0 removed the startup lint gate — createApp() no longer invokes validateDefinitions — but three comment sites still described it: the errors-contract and format-parity JSDoc in toolDefinition.ts and the startup-fatal error comment in app.ts. All three now state the current mechanism (bun run lint:mcp, gated in devcheck). These ship in the published .d.ts, so hover docs previously contradicted actual behavior.",
          "is_bot": false,
          "headline": "docs(src): stale startup-linter JSDoc corrected to build-time lint (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4fc2f05c948da905d86127aceadc95e6046ba11",
          "body": "… as-built\n\nRoot protocol: definition linting described as build-time (bun run lint:mcp / devcheck), not startup — schema-serializable and format-parity notes corrected; init copy list completed (devcheck.config.json, tests, scripts/, skills/, never-overwrite + in-place upgrade); ContentCollect/Cont\n[…]\n(devcheck removed; techniques and api-mirror added; bun run list-skills), commands table moved npm→bun and gains lint:mcp / lint:packaging / list-skills rows, security frontmatter scoped the same way.",
          "is_bot": false,
          "headline": "docs(protocol): sync CLAUDE.md/AGENTS.md and template counterparts to…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0736c339d407ed94df2c285971e2049f2da1260",
          "body": "git-wrapup 1.6: create annotated tags with --cleanup=whitespace (default strip deletes #-leading markdown lines; verbatim breaks SSH signature parsing and leaks the signature block into the release body), verify the tag reads as signed in the end-state check, and scope the changelog security flag to\n[…]\nruns the project gates, and three transformation rows corrected (TS 5.5 inferred type predicates, enum-value serialization caveat, walrus example).\napi-utils 2.4, polish-docs-meta 2.10: version bumps.",
          "is_bot": false,
          "headline": "docs(skills): tag-signature safeguards, code-simplifier corrections",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18abb9cd5b3312619179ee6186cb4d303b091b77",
          "body": "The security frontmatter field flags a vulnerability or hardening fix in this project's own code. A dependency or transitive CVE bump is routine maintenance: it stays under ## Dependencies with the flag false, so the Security badge answers \"does the shipped code have a vuln\" rather than tripping on every dep refresh. Tightened in both changelog templates and the build-changelog JSDoc.",
          "is_bot": false,
          "headline": "docs(changelog): scope security flag to source-code fixes only",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8373752be1f3395fb2f05c224bbd512b88b4165",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.10.10 — js-yaml v5 migration, dependency refresh",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c34bf3dc3b3dd43cfc68fc94448df9dc96eefc2",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): remove Contributing from readme reference",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a95a408dd2a77eff8501f3e4952bc65bcc1bae3d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): remove Contributing section",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-28T08:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c5b9ccb6e01cc88a0064b2e94f5ab9b669bee85",
          "body": "…uards\n\n@cloudflare/workers-types 4.20260619.1 → 4.20260620.1",
          "is_bot": false,
          "headline": "chore(release): 0.10.9 — devcheck dep-specifier and plugin-manifest g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af5d2643d70b08990fb3f292c74b579663da67ad",
          "body": "…manifests (#246, #240)\n\ncheck-dependency-specifiers (new ALL_CHECKS step, --no-dep-specifiers): hard-fails on latest/*/dist-tag specifiers in package.json's four dep sections and bun.lock's workspaces map, never the packages section. latest fails everywhere; */next/beta/canary/rc fail in dependenci\n[…]\nnstall arg (an unscoped arg for a scoped package 404s). Gated by devcheck.config.json packaging.pluginManifests (default on); the Packaging gate now also runs when a plugin manifest is present. (#240)",
          "is_bot": false,
          "headline": "feat(devcheck): guard floating dep specifiers and plugin marketplace …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:46:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3de075e7b090a669334e8e4378de9e5fcb20f98",
          "body": "…assification",
          "is_bot": false,
          "headline": "chore(release): 0.10.8 — ctx.content collector, canvas invalid_sql cl…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "669ae01e52082d23bf3417f2756b83d8aff9324d",
          "body": "…(#239)",
          "is_bot": false,
          "headline": "feat(context): add ctx.content collector for non-text content blocks …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1761990cd6080eab5d4c62421c9e6999b69953d2",
          "body": "…ith binder detail (#236)",
          "is_bot": false,
          "headline": "fix(canvas): classify SELECT-shaped prepare failures as invalid_sql w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267e6da839c3b7dddd0e50463019ada1a106a1c1",
          "body": "…eeds it (#233)",
          "is_bot": false,
          "headline": "docs(telemetry): correct OTEL_SERVICE_NAME default — createApp name s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa1faca2c84607ea2e53887a4cdee69c5f6dec49",
          "body": "…x, dep refresh\n\nFresh-scaffold devcheck fixes (#242 #243), check-skill-versions worktree-deletion guard (#237), and the DuckdbProvider.describe() Binder Error fix (#235); seven skill version bumps (#238). Dependency refresh: biome 2.4.16 -> 2.5.0 (biome migrate applied to biome.json), node-cron 4.2\n[…]\nuler test moved to vi.mock for the frozen ESM namespace), and the resolutions block trimmed to one js-yaml pin (bun audit clean). Version bumped across package.json, server.json, CLAUDE.md, AGENTS.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.7 — devcheck scaffold guards, canvas describe fi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7d73e49c18598a3db6a72d60d141a17c9a06edb",
          "body": "…244)\n\nThe #157 body-size tests assert only an eventual 413, which passes even when the whole over-limit body is buffered via arrayBuffer() first. This adds an instrumented-stream test asserting the cap bounds buffering — cancels the stream shortly after the limit on a no-Content-Length body. Marked test.fails: the current buffer-then-check code does not satisfy it, so the suite stays green while #244 is open; implementing the streaming cap flips it red as the signal to restore test.",
          "is_bot": false,
          "headline": "test(transport): stage streaming body-cap regression as test.fails (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5e164216ada101b985998c12fae3d023ca20079",
          "body": "…ver isolation note\n\ngit-wrapup v1.4: tag annotations may carry one concise context line under the subject (one or two lines, never paragraph blocks); restate the Bash-git rule without the obsolete git-mcp-server rationale. orchestrations v1.4: parallel sub-agents drive git through the shell against their own working directory.",
          "is_bot": false,
          "headline": "docs(skills): allow one tag-annotation context line; drop git-mcp-ser…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe9e8b48439374b5c9fc551eb8872009fc20e900",
          "body": "…y drift (#238)\n\nSeven external skills carried body changes that shipped pre-0.9.18 with no metadata.version bump, so the version-gated maintenance Phase A sync never propagated them to consumers. Bumped: api-auth 1.1->1.2, api-errors 1.6->1.7, api-services 1.3->1.4, api-telemetry 1.0->1.1, field-test 2.5->2.6, report-issue-local 1.5->1.6, tool-defs-analysis 1.2->1.3. Mirrors in .claude/skills and .agents/skills already match.",
          "is_bot": false,
          "headline": "chore(skills): bump metadata.version on seven skills with shipped bod…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "200454465ad226087acd70a71a5de9621a5ae2bf",
          "body": "…oin (#235)\n\ndescribe({ tableName }) pushed an unqualified table_name predicate into a query joining information_schema.tables t with duckdb_tables(), both exposing table_name — DuckDB raised a Binder Error (ambiguous column) on every filtered call. Qualified the pushed filters with the t alias (t.table_name, t.table_type, t.table_schema); the table_type arm was latent but qualified for consistency.",
          "is_bot": false,
          "headline": "fix(canvas): qualify describe() filters against the duckdb_tables() j…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecccb7e85cfe939574346987b110a8e4ae5f5de0",
          "body": "git diff --name-only HEAD lists a deleted skill and git show HEAD:<path> still returns the blob, so the loop reached readFileSync on a path no longer on disk and crashed with ENOENT — hit on every maintenance pass that prunes an upstream-removed skill. Added an existsSync guard before the read; a deleted file has no body to compare and cannot violate the policy.",
          "is_bot": false,
          "headline": "fix(scripts): skip worktree-deleted SKILL.md in the version gate (#237)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71f4c5818d574962a6f0c0a91273509cfa79dd69",
          "body": "TODOs/FIXMEs, Tracked Secrets, and Framework Antipatterns shell out to git grep / git ls-files, which exit 128 (not a finding) on a fresh scaffold before git init — devcheck reported it as a failure. Added a shared isGitRepo() helper that returns null from those getCommand()s when .git is absent; check-framework-antipatterns.ts also self-guards for direct invocation.",
          "is_bot": false,
          "headline": "fix(scripts): guard git-dependent devcheck checks outside a repo (#243)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b8a17d22f9a44bfe1a4207d077df4cc4179e2",
          "body": "build-changelog.ts --check exited via a thrown buildRollup() when changelog/ held only template.md and no <major.minor>.x/ version files — a fresh scaffold's own shipped state, surfacing as a stack trace on the first devcheck. Now exits 0 under --check when collectVersionFiles() is empty; a manual changelog:build still throws on an empty tree.",
          "is_bot": false,
          "headline": "fix(scripts): skip changelog sync cleanly on a fresh scaffold (#242)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d491a2789a3f20d0e3ea5496a8a84c53081f3da",
          "body": "…e preamble (git-wrapup v1.3)",
          "is_bot": false,
          "headline": "docs(skills): tag annotations are sections+bullets only — no narrativ…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78d58aaafb9cacd17323633f93c09a1ea72f43f",
          "body": "…lated to #230; clean-mcpb ships by init copy/script sync, not node_modules reference",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.6 entry — orchestrations bullet is unre…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:30:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65ce31ab46f45575c2f09358acfe32f99bbbb1a8",
          "body": "…ity lint (#230, #231)",
          "is_bot": false,
          "headline": "feat(packaging): 0.10.6 — bundle cleaner, post-bundle content + ident…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3e3c7551f0f00e43f79e55272fe69989b23ae76",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): orchestrations v1.3 — Phase 4 close-loop wording",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b8955b8164ca51b09b787b79f5cde879ac6eb5a",
          "body": "…ndings attribution, linter-claim wording",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.5 entry — skill version 1.5, fixture/bi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:56:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f4222e37bd18d26b2f37c187a2e2d5f24c46e3a",
          "body": "New ./testing/vitest subpath exports mcpTest (test.extend with ctx + storage fixtures) and McpTestFixtures interface. vitest >=4.0.0 added as an optional peer dependency. packaging guards updated: export-map allowlist gains ./testing/vitest; optional-peer-deps test adds an integration-entrypoint exe\n[…]\nino ^0.64.0 → ^0.65.0; @opentelemetry/resources ^2.7.1 → ^2.8.0; @opentelemetry/sdk-metrics ^2.7.1 → ^2.8.0; @opentelemetry/sdk-node ^0.218.0 → ^0.219.0; @opentelemetry/sdk-trace-node ^2.7.1 → ^2.8.0.",
          "is_bot": false,
          "headline": "feat(testing): 0.10.5 — mcpTest fixture-based Vitest subpath (#227)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:50:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1362c22cc9038c1e1aef17c9d262ef6b7765cb2",
          "body": "lintCappedListTruncation checked allowlist.includes(name) without guarding against non-array truncationAllowlist values; guard added.",
          "is_bot": false,
          "headline": "chore(linter): Array.isArray guard for the truncation allowlist check",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d44bee496c12fdfdaa011f1efbcfd0fb5fe2c8e2",
          "body": "… cases (#229)\n\nFifth vitest project 'typecheck' over tests/types/**/*.test-d.ts, using tsc checker with ignoreSourceErrors. maxWorkers: 4 required by vitest's uniform-sequence-group rule. New test:typecheck script. Three .test-d.ts files: error-contract (ReasonOf, TypedFail, TypedRecoveryFor, createFail, createRecoveryFor, HandlerContext), handler-context (HandlerContext inference), and tool-builder (output type inference).",
          "is_bot": false,
          "headline": "chore(tests): vitest typecheck project with @ts-expect-error negative…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbbec769c5bd2baa13452419568870b3028458cd",
          "body": "r2Buckets and d1Databases miniflare bindings added to the worker-runtime fixture. Per-provider test files exercise set/get/delete/list/TTL through the worker handler. skills/api-workers v1.3 documents the binding pattern.",
          "is_bot": false,
          "headline": "chore(tests): R2/D1 emulated workerd storage suites (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0760ea0a627008344836ffad7a27e185bfff40da",
          "body": "R2 rejects list() limits above 1000; limit+1 now clamped to R2_MAX_LIST_LIMIT=1000. At the cap, the response's truncated flag covers has-more detection instead of the +1 probe.",
          "is_bot": false,
          "headline": "fix(storage): clamp R2 list +1 page probe at the 1000-key cap (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54fd2e650dbde7474c170947873d503376cb2619",
          "body": "….3 floors (#216)\n\nAbortSignal.any for fetchWithTimeout external-signal composition and retry sleep cancellation. Uint8Array.toBase64/fromBase64 replaces chunked string-based encoding in the workerd/browser branch; Buffer fast-path stays primary. globalThis.performance.now direct delegation in nowMs\n[…]\nre extends AsyncDisposable — custom backend implementations must add [Symbol.asyncDispose]. TextToSpeechResult.audio and SpeechToTextOptions.audio type changed from Buffer|string to Uint8Array|string.",
          "is_bot": false,
          "headline": "refactor(utils,services): platform-native sweep under Node>=24/Bun>=1…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:48:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffa740dda1ec7f793efe305e9cad953ae50b15d2",
          "body": "…rom peers",
          "is_bot": false,
          "headline": "docs(changelog): fast-check was added to devDependencies, not moved f…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:22:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95c4927058f500771a797617abf425b3193c824c",
          "body": "…ync (#217)\n\nPackaging (#217):\n\n- exports map: default condition added to all 18 JS entries\n\n- HEALTHCHECK in Dockerfile and templates/Dockerfile (bun-native fetch, no curl dep)\n\n- tsconfig.base.json, tsconfig.json: importHelpers removed (no-op at ESNext, tslib never declared)\n\n- tsconfig.test.json \n[…]\nerage thresholds raised (stmts 88->91, branches 79->83, fns 90->92, lines 89->92)\n\nSkills:\n\n- api-testing v1.4: output schema assertions via expect.schemaMatching\n\n- api-canvas v1.6: see canvas commit",
          "is_bot": false,
          "headline": "chore(build,test): 0.10.4 — packaging hygiene, test infra, template s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:19:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0ad33f93e4241bf5a3f14da20b131f3f6b6000c",
          "body": "…Found, catalog deny layer, approxSizeBytes (#221, #222, #223, #224, #226)\n\n- inferSchemaFromRows: all inferred columns now nullable: true; sample cannot prove NOT NULL (#221)\n\n- query() non-registerAs path: streamAndReadUntil(rowLimit+1) replaces runAndReadAll+slice; adds truncated flag to QueryRes\n[…]\nSystemCatalogs: new export; opt-in QueryOptions/RegisterViewOptions.denySystemCatalogs flag (#224)\n\n- describe(): LEFT JOIN duckdb_tables() to populate TableInfo.approxSizeBytes for base tables (#226)",
          "is_bot": false,
          "headline": "feat(canvas): inferred-nullable fix, streaming cap, missing-table Not…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:18:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfeb9ff6de473a04837319999a718e7676b2a8bd",
          "body": "…on, sampling removed, server identity, completable args\n\nVersion: 0.10.2 → 0.10.3\nDependency: @types/node ^25.9.2 → 25.9.3 (pinned to patch)",
          "is_bot": false,
          "headline": "chore(release): 0.10.3 — elicit wired on the wire, URL-mode elicitati…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:12:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07d71331263b1db5ade50df0608912df8a83c110",
          "body": "…tures\n\ngit ls-files lists files deleted from the worktree but not yet staged. The audit\ncrashed when trying to read those paths. Added existsSync() filter so uncommitted\ndeletions don't break the audit during development.",
          "is_bot": false,
          "headline": "chore(scripts): skip worktree-deleted files in audit-open-index-signa…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44d6bda1e971ed14e89ddba0719f3137d0144e96",
          "body": "…#213, #218)\n\nCreateAppOptions gains optional title, websiteUrl, description, icons (typed against\nImplementation['icons']). All four are forwarded to the McpServer constructor's\nserverInfo and to buildServerManifest so initialize and /.well-known/mcp.json stay\nconsistent. Explicit description wins \n[…]\nervices and createMcpServerInstance\nbut the registerAll() call was a no-op. The roots/ directory and its test are gone.\nRoots is also deprecated by SEP-2577. RootsRegistry was never publicly exported.",
          "is_bot": false,
          "headline": "feat(app): server identity fields, remove RootsRegistry placeholder (…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc7e7b02e607eb1c7694fc8c049d5371e353dc71",
          "body": "…mpt title (#214)\n\nprompt() args fields may be wrapped with completable() — re-exported from the main\nentry so consumers don't need a direct SDK import. The SDK auto-installs\ncompletion/complete handling and advertises the completions capability when any\nregistered prompt has a completable argument.\n[…]\nResourceTemplate constructor second argument; triggers the\nsame automatic completions capability advertisement.\n\nresource-registration.ts also carries the #211 elicit notifier wiring (file atomicity).",
          "is_bot": false,
          "headline": "feat(prompts,resources): completable args, resource complete map, pro…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee720eb0c63cb25938796bf1dee3da15bc54521f",
          "body": "…, #212, #220)\n\nctx.elicit was never defined at runtime — the extra-sniffing approach misread the\nSDK's RequestHandlerExtra shape. Now wired via registration-time notifier closures:\nelicitInput and getClientCapabilities bound to the per-server Server instance in\nboth tool-registration.ts and resourc\n[…]\nicitFn with a default no-op .url()\nstub so tests exercising form-mode elicitation don't need to supply .url explicitly.\n\nsrc/core/index.ts also carries the #214 completion re-exports (file atomicity).",
          "is_bot": false,
          "headline": "feat(context): wire ctx.elicit, add URL-mode, remove ctx.sample (#211…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:10:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43b072e45ea9344b4a4dcf6de720959d8935a36e",
          "body": "…irror-CLI recipe description, cap-field list",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.2 entry — scaffold stanza paths/user, m…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:50:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75c2b0bc10d1f7efb44f40565d2ed14074864518",
          "body": "… rules, scaffold data dirs\n\nhono ^4.12.24 → ^4.12.25\n@cloudflare/vitest-pool-workers ^0.16.13 → ^0.16.14\n@cloudflare/workers-types 4.20260608.1 → 4.20260610.1\n@supabase/supabase-js ^2.108.0 → ^2.108.1\nsanitize-html ^2.17.4 → ^2.17.5",
          "is_bot": false,
          "headline": "chore(release): 0.10.2 — per-table canvas TTL, canvas/truncation lint…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6aa8b05262127d4b7ca429eb37307e447b780a96",
          "body": "…rror-CLI Docker recipe (#199, #195)",
          "is_bot": false,
          "headline": "feat(templates): writable SQLite data dirs in scaffold Dockerfile, mi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "772939b251f95fa23ddf4de2aef52d198b334eec",
          "body": "…rich.truncated (#209, #197)",
          "is_bot": false,
          "headline": "feat(linter): canvas-consumer and truncation-disclosure rules, ctx.en…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a058c5efbad6b7e63779510ad706434f987a8d5a",
          "body": "…pillover (#140)",
          "is_bot": false,
          "headline": "feat(canvas): per-table TTL on registerTable, query registerAs, and s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "158747a30ee6c82246925f2c55190e8223d2d8fc",
          "body": "…scaffold/packaging fixes",
          "is_bot": false,
          "headline": "chore(release): 0.10.1 — canvas SQL gate fail-closed, pragma_* deny, …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a641fe30dec6ebfb21cd919d74968e1ce2bf3dbc",
          "body": "…ons (#210)",
          "is_bot": false,
          "headline": "fix(canvas): fail closed on non-SELECT and deny pragma_* table functi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4fe4cc7ec1b5ef3b974f7c8418c867b860ee8d3",
          "body": null,
          "is_bot": false,
          "headline": "fix(scheduling): actionable error when node-cron peer is missing (#200)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc402edbe765de8bdae29594baff47eb892e0cd",
          "body": "…uard (#207)",
          "is_bot": false,
          "headline": "fix(packaging): anchor .mcpbignore dev patterns, add bundle-content g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2a055524862a95b1f015ecb05c9ba4db0dbfea2",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): ship repository object in manifest (#206)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a59dea547837af557f39d34a5b9c1b6e3741b951",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): run scaffold scripts via Bun, drop tsx (#205)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e6cd672ee25a8f9e24234b4bfb3dc93fd919e73",
          "body": "@cloudflare/vitest-pool-workers ^0.16.11 → ^0.16.13\n@cloudflare/workers-types 4.20260602.1 → 4.20260605.1\n@supabase/supabase-js ^2.106.2 → ^2.107.0\nopenai ^6.41.0 → ^6.42.0",
          "is_bot": false,
          "headline": "chore(release): 0.10.0 — outline-on-overflow, stringbool env booleans",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ac4cc9089157bdfb7f1065ca2994160e59e316d",
          "body": "…202)\n\ntemplates/Dockerfile now accepts an APP_VERSION build arg and stamps\norg.opencontainers.image.version in the OCI label block; also declares\norg.opencontainers.image.source (filled with the repo URL at scaffold\ntime). release-and-publish skill updated to pass --build-arg APP_VERSION\nto docker buildx for both amd64/arm64 platforms. Scaffolded servers only\n— existing servers pick this up on re-scaffold.",
          "is_bot": false,
          "headline": "fix(templates): stamp OCI image.version and source on built images (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15d8d2b7eea4e77301d5737d4b84e4ecd9f02b7d",
          "body": "New /utils exports: outlineOnOverflow(), OUTLINE_VARIANT, selectSections(),\nformatOutline(), DEFAULT_OUTLINE_BUDGET_BYTES. When a document-shaped\npayload exceeds a serialized-byte budget, returns a section outline\n(top-level keys + per-section size) and a re-call notice instead of\ntruncating. Agent \n[…]\nte cache, when to choose\nit over spillover() or capped-list disclosure).\n\ndesign-mcp-server and add-tool skills updated with overflow guidance.\nCLAUDE.md, AGENTS.md, docs/tree.md updated for new dirs.",
          "is_bot": false,
          "headline": "feat(utils): outline-on-overflow for oversized document payloads (#204)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63655562b73a7694d85c5cb6ce2564b40195453f",
          "body": "Replaces the hand-rolled envBoolean preprocess in src/config/index.ts\nwith Zod z.stringbool(). Accepts true/false/1/0/yes/no/on/off\n(case-insensitive); rejects unrecognized values at startup instead of\nsilently coercing them to false. Real booleans pass through (Workers\n[vars]). yes/on/y/enabled now\n[…]\nin src/, which coerces \"false\" to true. Scanner now\nskips comment lines to avoid false-positives on doc mentions. Server-\nconfig docs (api-config skill, templates) updated to recommend\nz.stringbool().",
          "is_bot": false,
          "headline": "feat(config): parse env booleans via Zod stringbool (#201)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:12:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db1bc01d26a51e50bd2a27342ccc7a695f85c110",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.9.21 — HTTP transport per-request log context fix",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ddb7eb9322592f8af3d01f893e28b0d06cf3ee",
          "body": "…ions skill",
          "is_bot": false,
          "headline": "docs(templates): expand First Session onboarding, document orchestrat…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a367b9c7edfff97e419f834335912ed63eca6284",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): mark orchestrations workflows as audience: external",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fd7c11e126b727e120a847383015725f0ceb2c3",
          "body": null,
          "is_bot": false,
          "headline": "fix(transport): derive per-request context in HTTP handlers (#194)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b24ebb00efd4d556a310236a7631483c1c9d5408",
          "body": "…ication routing",
          "is_bot": false,
          "headline": "chore(release): 0.9.20 — query-string redaction, lint fix, HTTP notif…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "908cadf8a147f5a11c86abdf7134a1d3befb71cd",
          "body": "…anvas, design-mcp-server",
          "is_bot": false,
          "headline": "docs(skills): add MCP-side list-filtering guidance to add-tool, api-c…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "664e10f2bbd43d26535f305162b92940abc5fbde",
          "body": "…135)",
          "is_bot": false,
          "headline": "fix: route list-changed notifications via request scope under HTTP (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4ab379de4de2acfe1c4d30c4fd417f60afcce41",
          "body": "…ns (#191)",
          "is_bot": false,
          "headline": "fix(linter): scope error-contract rules to throw sites, not compariso…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3109bb5993ff1eb7d7627b4814bf086a4e7ff577",
          "body": "… and logs (#190)",
          "is_bot": false,
          "headline": "fix(security): redact query-string secrets in fetchWithTimeout errors…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f72213a81ba556d899d3ab112c99a537028ecad",
          "body": "…orkflow gate markers\n\nAdds scripts/release-github.ts (bun run release:github): reads package.json version, derives tag subject, runs gh release create with --verify-tag --notes-from-tag --title 'v<VERSION>: <subject>', attaches dist/*.mcpb when manifest.json exists, and handles the release-already-\n[…]\ny fail-fast on data.retryable === false (#174), ctx.fail auto-populates data.retryable from contract entry, Gate after column in workflow phase tables (#183), MirrorService design-mcp-server guidance.",
          "is_bot": false,
          "headline": "feat(scripts): 0.9.19 — release:github script, withRetry fail-fast, w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa7601461e0ea4543c0b5fe8db5c5c8970a61b54",
          "body": "New bullet in the output-design section of design-mcp-server/SKILL.md: when to mirror a bulk upstream instead of paginating it live, with corpus-size thresholds (in-memory / MirrorService / external store) and a pointer to api-mirror.",
          "is_bot": false,
          "headline": "docs(design-mcp-server): add MirrorService bulk-upstream design guidance",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f625b576d2d0f79cd41dfabadb141559548fbf3",
          "body": "Every phase row in skills/orchestrations/workflows/*.md now has a Gate after column: barrier (with a terse reason) or gate-free. The orchestrator can derive spawn/round structure directly from the table without re-deriving the barrier positions each run.\n\nskills/orchestrations/SKILL.md adds a one-line pointer tying the new column back to the 'Barriers only where gates sit' principle.",
          "is_bot": false,
          "headline": "feat(orchestrations): Gate after column in workflow phase tables (#183)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f825f53b7b2f58d39bea80315c3b1a54c88a77b7",
          "body": "defaultIsTransient now checks error.data.retryable === false and returns non-transient immediately, even when the error code is in the transient set (Timeout, ServiceUnavailable, RateLimited). This closes the gap for deterministic upstream failures surfaced as HTTP 200 with an error body — they no l\n[…]\ncontract entry's retryable field as a base default. Caller-supplied data.retryable overrides per-occurrence; reason is always forced last. Contract entries that omit retryable inject no key onto data.",
          "is_bot": false,
          "headline": "feat(utils): withRetry fail-fast on data.retryable === false (#174)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a458781a006bf8d1909704cd504740c46fc972b9",
          "body": "… gate (#123)",
          "is_bot": false,
          "headline": "feat(devcheck): 0.9.18 — skill-version gate (#99), open-indexed-named…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T10:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72ec04223613586ac432f68c99947a6075725538",
          "body": "…e3 peer dep\n\nNew Tier 3 primitive: `defineMirror()` + `sqliteMirrorStore()` under\n`@cyanheads/mcp-ts-core/mirror`. Provides the source-agnostic machinery\nfor a persistent, self-refreshing local mirror of a bulk upstream dataset\n(embedded SQLite + FTS5): cross-runtime store, volatile cursor / durabl\n[…]\npply only the ingester (sync generator) and schema. Node/Bun only;\n`bun:sqlite` built-in on Bun, `better-sqlite3` optional peer on Node.\n\n`@cloudflare/workers-types` 4.20260530.1 → 4.20260531.1 (dev).",
          "is_bot": false,
          "headline": "feat(services): 0.9.17 — MirrorService, /mirror subpath, better-sqlit…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T05:41:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52a7122c5ba6def233f6e71900537e886a9d9c09",
          "body": "The httpError test built a Response with status 204 and an empty-string body; 204 is a null-body status that rejects any body, so the suite failed under current runtimes. Default the helper body to null.\n\nAdd behavior coverage for untested paths: a new resource-rules suite, landing-rules validation \n[…]\nraversal, sanitization security edge cases, scheduler lifecycle (listJobs/destroyAll/not-found), error factories, tokenCounter, and JSON/YAML error truncation. Branches 83.0% to 83.9%; no src changes.",
          "is_bot": false,
          "headline": "test: fix null-body httpError helper, expand suite coverage",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T14:16:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6002abf68947d859e1523e607fae3f6084e416bf",
          "body": "…tools\n\nenrichmentTrailer.render was an arrow property, so its parameter was\nvariance-strict under strictFunctionTypes — a concrete tool's narrow\nrender value no longer assigned to the type-erased AnyToolDefinition,\nbreaking createApp({ tools }) typecheck for every tool declaring an\nenrichment block (even with no trailer literal). Switch to method\nsyntax for bivariant params, matching format and handler.\n\nType-only; no runtime change. (#180)",
          "is_bot": false,
          "headline": "fix: 0.9.16 — restore AnyToolDefinition assignability for enrichment …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T03:27:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 33,
      "commits_last_year": 1289,
      "latest_release_at": "2026-07-19T12:24:31Z",
      "latest_release_tag": "v0.10.15",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 34,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 4.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@cyanheads/mcp-ts-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "agent",
            "agent-native",
            "ai",
            "ai-agent",
            "bun",
            "cloudflare-workers",
            "declarative",
            "framework",
            "mcp",
            "mcp-server",
            "mcp-framework",
            "model-context-protocol",
            "observability",
            "opentelemetry",
            "tools",
            "typescript"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
          "is_deprecated": false,
          "latest_version": "0.10.15",
          "repository_url": "https://github.com/cyanheads/mcp-ts-core",
          "versions_count": 142,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 44618,
          "first_published_at": "2026-03-12T12:17:08.098000Z",
          "latest_published_at": "2026-07-19T12:24:09.144000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 29,
      "stars": 147,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-27",
            "count": 1
          },
          {
            "date": "2025-05-12",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 2
          },
          {
            "date": "2025-05-17",
            "count": 1
          },
          {
            "date": "2025-07-09",
            "count": 1
          },
          {
            "date": "2025-07-23",
            "count": 1
          },
          {
            "date": "2025-09-03",
            "count": 1
          },
          {
            "date": "2025-10-02",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-10-16",
            "count": 1
          },
          {
            "date": "2025-10-30",
            "count": 1
          },
          {
            "date": "2025-11-17",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2025-12-24",
            "count": 1
          },
          {
            "date": "2026-01-02",
            "count": 1
          },
          {
            "date": "2026-01-04",
            "count": 1
          },
          {
            "date": "2026-01-14",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 2
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 29,
        "total_forks": 29
      },
      "star_history": null,
      "open_issues_and_prs": 59
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 54037,
      "source_files_sampled": 445,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "templates/AGENTS.md",
        "templates/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 39823
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "templates/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 115,
        "malicious_count": 0,
        "assessed_package": "npm:@cyanheads/mcp-ts-core@0.10.15",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@hono/mcp",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.1"
        },
        {
          "name": "@hono/node-server",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.10"
        },
        {
          "name": "@modelcontextprotocol/ext-apps",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.4"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@opentelemetry/api",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.1"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "hono",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.30"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.3.1"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@cyanheads/mcp-ts-core",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^{{FRAMEWORK_VERSION}}"
        },
        {
          "name": "pino-pretty",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.1.3"
        },
        {
          "name": "zod",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "{{ZOD_VERSION}}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@cyanheads/mcp-ts-core",
            "direct": true,
            "version": "^{{FRAMEWORK_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/mcp",
            "direct": true,
            "version": "^0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": true,
            "version": "^2.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/ext-apps",
            "direct": true,
            "version": "^1.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "^1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": true,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "^17.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": true,
            "version": "^4.12.30",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "^6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": true,
            "version": "^10.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pino-pretty",
            "direct": true,
            "version": "^13.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "{{ZOD_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/vitest-pool-workers",
            "direct": false,
            "version": "^0.18.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/workers-types",
            "direct": false,
            "version": "5.20260706.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-api",
            "direct": false,
            "version": "^1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/otel",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-pino",
            "direct": false,
            "version": "^0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-metrics",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-node",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-node",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "^1.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "@socketsecurity/bun-security-scanner",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/supabase-js",
            "direct": false,
            "version": "^2.110.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/papaparse",
            "direct": false,
            "version": "^5.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/sanitize-html",
            "direct": false,
            "version": "^2.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/validator",
            "direct": false,
            "version": "^13.15.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-istanbul",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/ui",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "better-sqlite3",
            "direct": false,
            "version": "^12.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "bun-types",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "chrono-node",
            "direct": false,
            "version": "^2.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "clipboardy",
            "direct": false,
            "version": "^5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "defuddle",
            "direct": false,
            "version": "^0.19.1",
            "ecosystem": "npm"
          },
          {
            "name": "depcheck",
            "direct": false,
            "version": "^1.4.7",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "^9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "^4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": false,
            "version": "^5.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "^5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "linkedom",
            "direct": false,
            "version": "^0.18.13",
            "ecosystem": "npm"
          },
          {
            "name": "node-cron",
            "direct": false,
            "version": "^4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "openai",
            "direct": false,
            "version": "^6.46.0",
            "ecosystem": "npm"
          },
          {
            "name": "papaparse",
            "direct": false,
            "version": "^5.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "partial-json",
            "direct": false,
            "version": "^0.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "pdf-lib",
            "direct": false,
            "version": "^1.17.1",
            "ecosystem": "npm"
          },
          {
            "name": "repomix",
            "direct": false,
            "version": "^1.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "sanitize-html",
            "direct": false,
            "version": "^2.17.6",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "typedoc",
            "direct": false,
            "version": "^0.28.20",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "unpdf",
            "direct": false,
            "version": "^1.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "validator",
            "direct": false,
            "version": "^13.15.35",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.9",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 66,
        "direct_count": 13,
        "indirect_count": 53
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 13,
        "open_issues": 59,
        "closed_ratio": 0.768,
        "closed_issues": 195,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "cyanheads",
          "commits": 1544,
          "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4"
        },
        {
          "type": "User",
          "login": "caseybreen",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/26234849?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
        "ran_at": "2026-07-25T09:49:09Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T12:23:34Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-05-23T02:12:04Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 66,
          "created_at": "2026-04-24T21:00:39Z",
          "last_comment_at": "2026-05-22T00:35:02Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 75,
          "created_at": "2026-04-28T04:08:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 77,
          "created_at": "2026-04-28T23:53:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 78,
          "created_at": "2026-04-28T23:53:33Z",
          "last_comment_at": "2026-06-07T18:16:07Z",
          "last_comment_author": "xlyoung"
        },
        {
          "number": 79,
          "created_at": "2026-04-28T23:53:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 94,
          "created_at": "2026-05-01T23:25:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2026-05-03T07:02:02Z",
          "last_comment_at": "2026-05-03T08:11:29Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 107,
          "created_at": "2026-05-03T07:39:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-05-03T22:45:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-05-17T18:23:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 142,
          "created_at": "2026-05-21T15:01:15Z",
          "last_comment_at": "2026-06-11T22:37:44Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 151,
          "created_at": "2026-05-23T16:12:48Z",
          "last_comment_at": "2026-06-02T10:26:46Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 152,
          "created_at": "2026-05-23T18:12:07Z",
          "last_comment_at": "2026-05-23T18:18:18Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 162,
          "created_at": "2026-05-28T09:05:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 163,
          "created_at": "2026-05-28T10:14:45Z",
          "last_comment_at": "2026-05-28T12:41:51Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 164,
          "created_at": "2026-05-28T23:27:45Z",
          "last_comment_at": "2026-05-31T05:42:50Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 187,
          "created_at": "2026-06-01T06:12:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 188,
          "created_at": "2026-06-01T06:13:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 193,
          "created_at": "2026-06-02T03:33:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 196,
          "created_at": "2026-06-02T10:26:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cyanheads/mcp-ts-core",
    "host": "github.com",
    "name": "mcp-ts-core",
    "owner": "cyanheads"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 47,
        "vitality": 93,
        "community": 56,
        "governance": 55,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 93,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 1289,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 34
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "34/52 weeks with commits",
                "points": 23.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 34
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1289 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1289
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 33,
              "latest_release_tag": "v0.10.15",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 4.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "33 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 29,
              "stars": 147,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "147 stars",
                "points": 35.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 147
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "29 forks",
                "points": 12.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 44618
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "44,618 downloads/month across npm",
                "points": 62,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 44618,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "merged_prs": 13,
              "open_issues": 59,
              "closed_issues": 195,
              "issue_closed_ratio": 0.768,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "77% of issues closed",
                "points": 35.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "13/26 decided PRs merged",
                "points": 19.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 13,
                      "decided": 26
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "followers": 175,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "cyanheads",
              "public_repos": 146,
              "account_age_days": 4225
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "175 followers of cyanheads",
                "points": 16.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 175,
                      "login": "cyanheads"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "146 public repos, account ~11 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 146
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "142 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 142
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "ai",
                "opentelemetry",
                "cloudflare-workers",
                "agent-native",
                "framework",
                "typescript",
                "cyanheads"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@cyanheads/mcp-ts-core@0.10.15 runtime dependency closure — what installing the published package pulls in — 115 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@cyanheads/mcp-ts-core@0.10.15",
                  "assessed": 115
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 115,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 115,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "templates/AGENTS.md",
                "templates/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 39823
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 54037,
              "source_files_sampled": 445,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/445 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 445,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package '{{PACKAGE_NAME}}' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T09:49:14.556607Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cyanheads/mcp-ts-core.svg",
  "full_name": "cyanheads/mcp-ts-core",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.