Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [
"mcp",
"mcp-server",
"model-context-protocol",
"ai",
"opentelemetry",
"cloudflare-workers",
"agent-native",
"framework",
"typescript",
"cyanheads"
],
"is_fork": false,
"size_kb": 8898,
"has_wiki": true,
"homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
"languages": {
"Shell": 102,
"Dockerfile": 9732,
"JavaScript": 109642,
"TypeScript": 3872892
},
"pushed_at": "2026-07-22T01:11:54Z",
"created_at": "2025-03-20T05:07:04Z",
"owner_type": "User",
"updated_at": "2026-07-24T18:42:03Z",
"description": "Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://caseyjhand.com",
"name": "Casey Hand",
"type": "User",
"login": "cyanheads",
"company": null,
"location": "Seattle, WA",
"followers": 175,
"avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4",
"created_at": "2014-12-29T13:01:12Z",
"is_verified": null,
"public_repos": 146,
"account_age_days": 4225
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.10.15",
"kind": "patch",
"published_at": "2026-07-19T12:24:31Z"
},
{
"tag": "v0.10.14",
"kind": "patch",
"published_at": "2026-07-06T08:08:16Z"
},
{
"tag": "v0.10.13",
"kind": "patch",
"published_at": "2026-07-05T18:04:33Z"
},
{
"tag": "v0.10.12",
"kind": "patch",
"published_at": "2026-07-05T08:45:52Z"
},
{
"tag": "v0.10.11",
"kind": "patch",
"published_at": "2026-07-05T05:59:38Z"
},
{
"tag": "v0.10.10",
"kind": "patch",
"published_at": "2026-06-30T09:19:32Z"
},
{
"tag": "v0.10.9",
"kind": "patch",
"published_at": "2026-06-20T07:52:14Z"
},
{
"tag": "v0.10.8",
"kind": "patch",
"published_at": "2026-06-19T23:56:33Z"
},
{
"tag": "v0.10.7",
"kind": "patch",
"published_at": "2026-06-19T21:26:53Z"
},
{
"tag": "v0.10.6",
"kind": "patch",
"published_at": "2026-06-11T20:27:22Z"
},
{
"tag": "v0.10.5",
"kind": "patch",
"published_at": "2026-06-11T16:51:26Z"
},
{
"tag": "v0.10.4",
"kind": "patch",
"published_at": "2026-06-11T01:20:20Z"
},
{
"tag": "v0.10.3",
"kind": "patch",
"published_at": "2026-06-10T23:14:46Z"
},
{
"tag": "v0.10.2",
"kind": "patch",
"published_at": "2026-06-10T17:48:09Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-06-08T14:46:42Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-06-05T12:16:41Z"
},
{
"tag": "v0.9.21",
"kind": "patch",
"published_at": "2026-06-02T09:05:28Z"
},
{
"tag": "v0.9.20",
"kind": "patch",
"published_at": "2026-06-02T03:44:02Z"
},
{
"tag": "v0.9.19",
"kind": "patch",
"published_at": "2026-05-31T11:08:20Z"
},
{
"tag": "v0.9.18",
"kind": "patch",
"published_at": "2026-05-31T10:18:08Z"
},
{
"tag": "v0.9.17",
"kind": "patch",
"published_at": "2026-05-31T05:42:27Z"
},
{
"tag": "v0.9.16",
"kind": "patch",
"published_at": "2026-05-30T03:28:09Z"
},
{
"tag": "v0.9.15",
"kind": "patch",
"published_at": "2026-05-30T02:47:15Z"
},
{
"tag": "v0.9.14",
"kind": "patch",
"published_at": "2026-05-29T11:58:20Z"
},
{
"tag": "v0.9.13",
"kind": "patch",
"published_at": "2026-05-29T01:58:44Z"
},
{
"tag": "v0.9.12",
"kind": "patch",
"published_at": "2026-05-29T00:42:33Z"
},
{
"tag": "v0.9.11",
"kind": "patch",
"published_at": "2026-05-28T08:26:20Z"
},
{
"tag": "v0.9.10",
"kind": "patch",
"published_at": "2026-05-27T04:33:29Z"
},
{
"tag": "v0.9.9",
"kind": "patch",
"published_at": "2026-05-24T10:13:49Z"
},
{
"tag": "v0.9.8",
"kind": "patch",
"published_at": "2026-05-24T09:30:02Z"
},
{
"tag": "v0.9.7",
"kind": "patch",
"published_at": "2026-05-23T16:45:02Z"
},
{
"tag": "v0.9.6",
"kind": "patch",
"published_at": "2026-05-23T10:27:23Z"
},
{
"tag": "v0.9.5",
"kind": "patch",
"published_at": "2026-05-23T08:40:15Z"
}
],
"recent_commits": [
{
"oid": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
"body": "…fields, expectedStatuses opt-out",
"is_bot": false,
"headline": "chore(release): 0.10.15 — Retry-After honoring, canonical HTTP error …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:20:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac3b9e5aee765fdbacc4415b997ab0f9925284d7",
"body": "Dependency arrows of note: @biomejs/biome 2.5.2 -> 2.5.4 (biome.json\nschema migrated via 'bunx biome migrate'), @cloudflare/vitest-pool-workers\n^0.18.0 -> ^0.18.4, @opentelemetry/semantic-conventions ^1.41.1 -> ^1.43.0,\nhono ^4.12.27 -> ^4.12.30, vite 8.1.3 -> 8.1.5, vitest/@vitest/coverage-istanbul\n[…]\n'\ncasts; fixed across 7 test files by extracting the cast to a local\nbefore the property access (behavior-preserving). The remaining 2 test\nfiles carry only Biome's it.each argument-list reformatting.",
"is_bot": false,
"headline": "chore(deps): bun update; biome 2.5.4 migration; typescript 7 held",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:18:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53ed7cd01b96c3d45a6b9c81f4a0d6dd53f4009d",
"body": "…l-defs-analysis 1.4\n\ngit-wrapup: tag-annotation format overhauled to a flat-bullet headline\ndigest — no Keep-a-Changelog section headers, no gates line, deps\ncapped at one line naming only what earns it; notable changes get\ntheir own bullet, minor/internal items share one grouped bullet.\norchestrat\n[…]\ns (naming taxonomy, parameter vocabulary, tool overlap,\ninstructions drift, length outliers).\n\nfield-test-fix.md, fix-wrapup-release.md, maintenance-release.md updated\nto reference the new tag format.",
"is_bot": false,
"headline": "docs(skills): field-test 2.7, git-wrapup 1.8, orchestrations 1.7, too…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:17:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c00f24e7bb63d33f562e0d701faacb162badcdb",
"body": "The 0.10.13 agent-notes told downstream maintenance agents to add a\ntrustedDependencies entry alongside the @socketsecurity/bun-security-scanner\ndevDependency. No such entry exists in that release — the instruction\nwould send an adopting agent looking for something that isn't there.",
"is_bot": false,
"headline": "docs(changelog): drop trustedDependencies from 0.10.13 notes (#281)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:17:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "685203b8c8ab1c8be4e4df458fc9001295924de9",
"body": "…ror fields (#256, #279)\n\nfetchWithTimeout gains options.expectedStatuses: number[] — a listed\nnon-2xx status logs at debug instead of error; the thrown, status-mapped\nMcpError is unchanged. Also stops double-logging: the catch block now\nre-throws a FetchHttpError-tagged McpError as-is instead of re\n[…]\nside the\npre-existing statusCode/responseBody aliases (kept, identical values) so\na consumer can read either helper's error the same way.\n\nskills/api-utils/SKILL.md documents both changes (2.4 → 2.5).",
"is_bot": false,
"headline": "feat(network): expectedStatuses log opt-out; canonical status/body er…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:17:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0d6143cc8c91701025dbe292b8521de24244b1fd",
"body": "Parses an upstream Retry-After hint (RFC 9110 §10.2.3 delta-seconds\nor HTTP-date) off McpError.data.retryAfter and waits that long instead\nof blind exponential backoff. The honored delay is not jittered. When\nthe requested wait exceeds maxDelayMs, the error is treated as\nnon-transient and fails fast with the original error rather than\nburning an attempt that can't succeed in time.",
"is_bot": false,
"headline": "feat(network): withRetry honors Retry-After (#285)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-19T12:16:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "352addd4d50a55cd73c04c64e7a86bad0fa0c671",
"body": "Split the dense post-snippet block into shorter paragraphs, cut a redundant sentence, and tighten wording. Facts and code samples unchanged.",
"is_bot": false,
"headline": "docs: condense README intro prose",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T09:26:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d6a6235c923aaabfd4b172cad81a919a38e6b482",
"body": "…oc fixes\n\nVersion bumps across package.json, server.json, README, CLAUDE.md, AGENTS.md; changelog 0.10.14; regenerated CHANGELOG.md rollup and docs/tree.md.",
"is_bot": false,
"headline": "chore(release): 0.10.14 — Docker build, linter null guard, canvas + d…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:05:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "738a6bb9bd6431b49f012ddc504f7b23332011db",
"body": "…262)\n\nA bare-token curl 404s on the multi-arch OCI indexes docker buildx pushes; the manifest-list Accept header is missing. docker manifest inspect resolves them and exits non-zero when the tag is genuinely absent.",
"is_bot": false,
"headline": "docs(release-and-publish): verify GHCR via docker manifest inspect (#…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:05:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f40d4383847f5ce21f3f9e67ee0a95b9c8bbbbe",
"body": "…minated union (#249)\n\nOUTLINE_VARIANT and outlineOnOverflow JSDoc and the techniques, add-tool, and design-mcp-server skills advertised a z.discriminatedUnion output that tool() rejects (schema-is-object lint and enrichment .extend() are ZodObject-only). Document the flat z.object with a kind discriminator and presence-based optional arms, rendered per field presence in format(). Docs and JSDoc only; no runtime change.",
"is_bot": false,
"headline": "docs(overflow): correct outline output to a flat object, not a discri…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:05:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb9a6321d856dac49592da1511695db6f22eba19",
"body": "…overy (#264)\n\nMirror the missing_table precedent from query(): the source-table-not-found throw in DuckdbProvider.importFrom now sets reason missing_table plus a recovery hint. The sibling import_same_canvas and import_view_clash throws gain recovery hints too.",
"is_bot": false,
"headline": "fix(canvas): importFrom missing-table NotFound carries reason and rec…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:05:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "13dbdbdbefa7b7a87ec76640a328c5eb4787f58e",
"body": "… entry (#265)\n\nA null or undefined entry in a tools/resources/prompts array threw a TypeError and aborted validateDefinitions; only the prompts path survived. Harden the three shared sub-linters (lintEnrichmentContract, lintCappedListTruncation, lintHandlerBody) to early-return on a non-object def, and guard each per-definition loop before dispatch, emitting one definition-invalid error per bad entry. Adds src/linter/rules/definition-rules.ts.",
"is_bot": false,
"headline": "fix(linter): surface definition-invalid instead of crashing on a null…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:05:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a546e8e4db6d71236bce5049dd938ebc38f5f13",
"body": "The build stage ran every dependency lifecycle script; better-sqlite3 prebuild-install falls back to node-gyp (absent in oven/bun) and exits 127, failing the build. Match the production stage with --ignore-scripts: the build only runs tsc, which needs type declarations, not native bindings. templates/Dockerfile mirrors it.",
"is_bot": false,
"headline": "fix(build): install with --ignore-scripts in Docker build stage (#267)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-06T08:04:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e82602fdbf699318a63a740bca990d3ca0061e92",
"body": "…ization",
"is_bot": false,
"headline": "chore(release): 0.10.13 — supply-chain guard, coverage, config modern…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T18:01:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29e3ceb99a7453a83f620f5e08e8f0e617566ed8",
"body": "AGENTS.md and CLAUDE.md note that init now scaffolds bunfig.toml, LICENSE, and .gitattributes. .github/FUNDING.yml trims to the active github and buy_me_a_coffee entries; LICENSE copyright year 2025 → 2026 (still Apache-2.0).",
"is_bot": false,
"headline": "docs: sync consumer-path list; trim FUNDING; LICENSE year 2026",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T18:01:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53aca5fc19253a53c30aa365e3bac7c591b6f8c3",
"body": "…lish-docs-meta 2.11\n\napi-workers documents the @duckdb/node-api Worker stub alias. git-wrapup and orchestrations add the changelog-link final line to tag bodies. polish-docs-meta covers manifest.json author identity plus author/packageManager/engines metadata guidance.",
"is_bot": false,
"headline": "docs(skills): api-workers 1.6, git-wrapup 1.7, orchestrations 1.6, po…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T18:00:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7940d011996224e29aaf1dc506352cbfb0cb9d87",
"body": "init now copies an Apache-2.0 LICENSE and a .gitattributes (LF normalization, binary-asset and machine-generated markers) into newly scaffolded servers.",
"is_bot": false,
"headline": "feat(templates): scaffold LICENSE and .gitattributes",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T18:00:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5f5027b6404f6ef5fa4d3d16f2b36b73f8d34b2",
"body": "tsconfig.json extends a deduped tsconfig.base.json; the base moves target/lib ESNext → ES2025 (plus ESNext.TypedArrays). Dockerfile and templates/Dockerfile pin oven/bun:1.3.14 and add BuildKit install-cache mounts. .gitattributes overhauls the lockfile and linguist-generated markers and the git-arc\n[…]\nommit gains a POSIX shebang. Stricter-tsconfig script fixes: devdocs.ts explicit return, lint-mcp.ts conditional packageJson spread, tree.ts entries() iteration. typedoc drops the scripts entry point.",
"is_bot": false,
"headline": "build: modernize tsconfig, Dockerfile, and tooling config",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T18:00:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4e0fbfd49e4365027c17e8ae8e8623e47bddb49b",
"body": null,
"is_bot": false,
"headline": "chore: drop Smithery deployment config",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T17:59:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69433f431c6e695df623a831b57561d1f34d1821",
"body": "wrangler.toml becomes wrangler.jsonc (schema-referenced, inline comments). An alias maps @duckdb/node-api to examples/duckdb-stub.ts so wrangler's esbuild step stops failing on DuckDB's native bindings — the DataCanvas provider's lazy import() is statically reachable from the Worker entry but never executes there.",
"is_bot": false,
"headline": "build(workers): migrate wrangler config to JSONC; stub @duckdb/node-api",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T17:59:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "114edd0339601adcc4294ffab99e024c7ce236c0",
"body": "bunfig.toml adds a 3-day minimumReleaseAge hold on fresh publishes and an [install.security] Socket scanner; package.json declares the @socketsecurity/bun-security-scanner devDependency and trusts it. devcheck's Outdated gate now skips versions bun holds by release age (Update == Current, marked *),\n[…]\n .github/SECURITY.md adds a disclosure policy.\n\npackage.json also drops the unused main/types fields, adds a prepare hook-path script, bumps packageManager to bun@1.3.14, and sets the author identity.",
"is_bot": false,
"headline": "chore(security): minimumReleaseAge hold + Socket install scanner",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T17:59:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e301d1fe4e54c48702db126410acbeedbcb99554",
"body": "…/services",
"is_bot": false,
"headline": "test: expand unit coverage; move DuckDB smoke suite under tests/smoke…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T17:58:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ebbb12bfe2a8e37cbbccface856c59a9ae758c98",
"body": "…separator",
"is_bot": false,
"headline": "chore(release): 0.10.12 — canvas error contracts, enrichment trailer …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T08:44:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c415f70563ad2bef2ae6eda735f136151f24269",
"body": "…h (#261, #254)\n\nCanvasRegistry's not-found throws (acquire, touchOrThrow, touchWithTable, touchWithSqlTables) and DuckdbProvider.requireCanvas() now carry data.reason 'canvas_not_found', the canvasId, and a default recovery.hint, so consumer-declared canvas_not_found error contracts populate on the\n[…]\ny-structured McpError unchanged instead of reclassifying it to DatabaseError, preserving register_as_clash and export_path_* ValidationError codes and data across all four provider catch sites (#254).",
"is_bot": false,
"headline": "fix(canvas): structured canvas_not_found errors, McpError pass-throug…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T08:44:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07928d739c5ab069b8ca38c5339a2517bb0906c3",
"body": "Clients that concatenate adjacent content[] text blocks with no join (Claude Desktop, claude.ai) rendered the trailer glued onto the last domain line. Markdown collapses consecutive blank lines, so clients that insert their own separator render at most one blank line either way.",
"is_bot": false,
"headline": "fix(tools): lead enrichment trailer with a blank-line separator (#257)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T08:44:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e0c35f0558e3375079acc9212ffb7937b7ece8c9",
"body": "…ics, dep refresh",
"is_bot": false,
"headline": "chore(release): 0.10.11 — scaffold devcheck fix, security-flag semant…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:56:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf33b280dfaf83378157eafb3961dfbb3cfea0a3",
"body": "…overy discipline\n\nAdds the Reference tool shape to the taxonomy (decoder ring for opaque domain vocabulary — codes, enums, identifier formats; the standing target of recovery routing; implement first) with its own subsection. API probing gains unknown-param and omission-semantics probes, and the st\n[…]\nfalse, guidance } instead of throwing, zero-hit behavior is specced at design time, and design docs settle verbatim recovery strings under a no-dead-ends rule (each names the concrete next tool call).",
"is_bot": false,
"headline": "docs(skills): design-mcp-server 2.19 — reference tools, probe and rec…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:51:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8199830341c44d465e6c02bbd98e7224ae512d2e",
"body": "@biomejs/biome 2.5.1 → 2.5.2 (biome.json $schema follows), @cloudflare/vitest-pool-workers ^0.16.20 → ^0.18.0, @cloudflare/workers-types 4.20260630.1 → 5.20260705.1, @opentelemetry/* 0.219→0.220 and 2.8→2.9 sets, @opentelemetry/instrumentation-pino ^0.65.0 → ^0.66.0, @supabase/supabase-js ^2.109.0 →\n[…]\nte 8.1.0 → 8.1.3.\ntemplates/package.json pins @biomejs/biome 2.5.2 and @types/node 26.1.0 so a fresh scaffold's Biome CLI matches the shared config's $schema and devcheck passes out of the box (#260).",
"is_bot": false,
"headline": "chore(deps): bun update --latest; align template biome/types pins (#260)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:46:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8ff580bcbf7110eb5539d859339c768a02a657c",
"body": "…263)\n\n0.9.0 removed the startup lint gate — createApp() no longer invokes validateDefinitions — but three comment sites still described it: the errors-contract and format-parity JSDoc in toolDefinition.ts and the startup-fatal error comment in app.ts. All three now state the current mechanism (bun run lint:mcp, gated in devcheck). These ship in the published .d.ts, so hover docs previously contradicted actual behavior.",
"is_bot": false,
"headline": "docs(src): stale startup-linter JSDoc corrected to build-time lint (#…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:46:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4fc2f05c948da905d86127aceadc95e6046ba11",
"body": "… as-built\n\nRoot protocol: definition linting described as build-time (bun run lint:mcp / devcheck), not startup — schema-serializable and format-parity notes corrected; init copy list completed (devcheck.config.json, tests, scripts/, skills/, never-overwrite + in-place upgrade); ContentCollect/Cont\n[…]\n(devcheck removed; techniques and api-mirror added; bun run list-skills), commands table moved npm→bun and gains lint:mcp / lint:packaging / list-skills rows, security frontmatter scoped the same way.",
"is_bot": false,
"headline": "docs(protocol): sync CLAUDE.md/AGENTS.md and template counterparts to…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:45:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0736c339d407ed94df2c285971e2049f2da1260",
"body": "git-wrapup 1.6: create annotated tags with --cleanup=whitespace (default strip deletes #-leading markdown lines; verbatim breaks SSH signature parsing and leaks the signature block into the release body), verify the tag reads as signed in the end-state check, and scope the changelog security flag to\n[…]\nruns the project gates, and three transformation rows corrected (TS 5.5 inferred type predicates, enum-value serialization caveat, walrus example).\napi-utils 2.4, polish-docs-meta 2.10: version bumps.",
"is_bot": false,
"headline": "docs(skills): tag-signature safeguards, code-simplifier corrections",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:45:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "18abb9cd5b3312619179ee6186cb4d303b091b77",
"body": "The security frontmatter field flags a vulnerability or hardening fix in this project's own code. A dependency or transitive CVE bump is routine maintenance: it stays under ## Dependencies with the flag false, so the Security badge answers \"does the shipped code have a vuln\" rather than tripping on every dep refresh. Tightened in both changelog templates and the build-changelog JSDoc.",
"is_bot": false,
"headline": "docs(changelog): scope security flag to source-code fixes only",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-07-05T05:45:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8373752be1f3395fb2f05c224bbd512b88b4165",
"body": null,
"is_bot": false,
"headline": "chore(release): 0.10.10 — js-yaml v5 migration, dependency refresh",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-30T09:16:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c34bf3dc3b3dd43cfc68fc94448df9dc96eefc2",
"body": null,
"is_bot": false,
"headline": "docs(skills): remove Contributing from readme reference",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-30T09:16:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a95a408dd2a77eff8501f3e4952bc65bcc1bae3d",
"body": null,
"is_bot": false,
"headline": "docs(readme): remove Contributing section",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-28T08:20:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c5b9ccb6e01cc88a0064b2e94f5ab9b669bee85",
"body": "…uards\n\n@cloudflare/workers-types 4.20260619.1 → 4.20260620.1",
"is_bot": false,
"headline": "chore(release): 0.10.9 — devcheck dep-specifier and plugin-manifest g…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-20T07:47:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af5d2643d70b08990fb3f292c74b579663da67ad",
"body": "…manifests (#246, #240)\n\ncheck-dependency-specifiers (new ALL_CHECKS step, --no-dep-specifiers): hard-fails on latest/*/dist-tag specifiers in package.json's four dep sections and bun.lock's workspaces map, never the packages section. latest fails everywhere; */next/beta/canary/rc fail in dependenci\n[…]\nnstall arg (an unscoped arg for a scoped package 404s). Gated by devcheck.config.json packaging.pluginManifests (default on); the Packaging gate now also runs when a plugin manifest is present. (#240)",
"is_bot": false,
"headline": "feat(devcheck): guard floating dep specifiers and plugin marketplace …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-20T07:46:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c3de075e7b090a669334e8e4378de9e5fcb20f98",
"body": "…assification",
"is_bot": false,
"headline": "chore(release): 0.10.8 — ctx.content collector, canvas invalid_sql cl…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T23:53:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "669ae01e52082d23bf3417f2756b83d8aff9324d",
"body": "…(#239)",
"is_bot": false,
"headline": "feat(context): add ctx.content collector for non-text content blocks …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T23:53:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1761990cd6080eab5d4c62421c9e6999b69953d2",
"body": "…ith binder detail (#236)",
"is_bot": false,
"headline": "fix(canvas): classify SELECT-shaped prepare failures as invalid_sql w…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T23:53:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "267e6da839c3b7dddd0e50463019ada1a106a1c1",
"body": "…eeds it (#233)",
"is_bot": false,
"headline": "docs(telemetry): correct OTEL_SERVICE_NAME default — createApp name s…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T23:53:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa1faca2c84607ea2e53887a4cdee69c5f6dec49",
"body": "…x, dep refresh\n\nFresh-scaffold devcheck fixes (#242 #243), check-skill-versions worktree-deletion guard (#237), and the DuckdbProvider.describe() Binder Error fix (#235); seven skill version bumps (#238). Dependency refresh: biome 2.4.16 -> 2.5.0 (biome migrate applied to biome.json), node-cron 4.2\n[…]\nuler test moved to vi.mock for the frozen ESM namespace), and the resolutions block trimmed to one js-yaml pin (bun audit clean). Version bumped across package.json, server.json, CLAUDE.md, AGENTS.md.",
"is_bot": false,
"headline": "chore(release): 0.10.7 — devcheck scaffold guards, canvas describe fi…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:24:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7d73e49c18598a3db6a72d60d141a17c9a06edb",
"body": "…244)\n\nThe #157 body-size tests assert only an eventual 413, which passes even when the whole over-limit body is buffered via arrayBuffer() first. This adds an instrumented-stream test asserting the cap bounds buffering — cancels the stream shortly after the limit on a no-Content-Length body. Marked test.fails: the current buffer-then-check code does not satisfy it, so the suite stays green while #244 is open; implementing the streaming cap flips it red as the signal to restore test.",
"is_bot": false,
"headline": "test(transport): stage streaming body-cap regression as test.fails (#…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:24:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e5e164216ada101b985998c12fae3d023ca20079",
"body": "…ver isolation note\n\ngit-wrapup v1.4: tag annotations may carry one concise context line under the subject (one or two lines, never paragraph blocks); restate the Bash-git rule without the obsolete git-mcp-server rationale. orchestrations v1.4: parallel sub-agents drive git through the shell against their own working directory.",
"is_bot": false,
"headline": "docs(skills): allow one tag-annotation context line; drop git-mcp-ser…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:24:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe9e8b48439374b5c9fc551eb8872009fc20e900",
"body": "…y drift (#238)\n\nSeven external skills carried body changes that shipped pre-0.9.18 with no metadata.version bump, so the version-gated maintenance Phase A sync never propagated them to consumers. Bumped: api-auth 1.1->1.2, api-errors 1.6->1.7, api-services 1.3->1.4, api-telemetry 1.0->1.1, field-test 2.5->2.6, report-issue-local 1.5->1.6, tool-defs-analysis 1.2->1.3. Mirrors in .claude/skills and .agents/skills already match.",
"is_bot": false,
"headline": "chore(skills): bump metadata.version on seven skills with shipped bod…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:23:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "200454465ad226087acd70a71a5de9621a5ae2bf",
"body": "…oin (#235)\n\ndescribe({ tableName }) pushed an unqualified table_name predicate into a query joining information_schema.tables t with duckdb_tables(), both exposing table_name — DuckDB raised a Binder Error (ambiguous column) on every filtered call. Qualified the pushed filters with the t alias (t.table_name, t.table_type, t.table_schema); the table_type arm was latent but qualified for consistency.",
"is_bot": false,
"headline": "fix(canvas): qualify describe() filters against the duckdb_tables() j…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:23:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ecccb7e85cfe939574346987b110a8e4ae5f5de0",
"body": "git diff --name-only HEAD lists a deleted skill and git show HEAD:<path> still returns the blob, so the loop reached readFileSync on a path no longer on disk and crashed with ENOENT — hit on every maintenance pass that prunes an upstream-removed skill. Added an existsSync guard before the read; a deleted file has no body to compare and cannot violate the policy.",
"is_bot": false,
"headline": "fix(scripts): skip worktree-deleted SKILL.md in the version gate (#237)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:23:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71f4c5818d574962a6f0c0a91273509cfa79dd69",
"body": "TODOs/FIXMEs, Tracked Secrets, and Framework Antipatterns shell out to git grep / git ls-files, which exit 128 (not a finding) on a fresh scaffold before git init — devcheck reported it as a failure. Added a shared isGitRepo() helper that returns null from those getCommand()s when .git is absent; check-framework-antipatterns.ts also self-guards for direct invocation.",
"is_bot": false,
"headline": "fix(scripts): guard git-dependent devcheck checks outside a repo (#243)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:23:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e9b8a17d22f9a44bfe1a4207d077df4cc4179e2",
"body": "build-changelog.ts --check exited via a thrown buildRollup() when changelog/ held only template.md and no <major.minor>.x/ version files — a fresh scaffold's own shipped state, surfacing as a stack trace on the first devcheck. Now exits 0 under --check when collectVersionFiles() is empty; a manual changelog:build still throws on an empty tree.",
"is_bot": false,
"headline": "fix(scripts): skip changelog sync cleanly on a fresh scaffold (#242)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-19T21:23:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d491a2789a3f20d0e3ea5496a8a84c53081f3da",
"body": "…e preamble (git-wrapup v1.3)",
"is_bot": false,
"headline": "docs(skills): tag annotations are sections+bullets only — no narrativ…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T20:32:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c78d58aaafb9cacd17323633f93c09a1ea72f43f",
"body": "…lated to #230; clean-mcpb ships by init copy/script sync, not node_modules reference",
"is_bot": false,
"headline": "docs(changelog): correct 0.10.6 entry — orchestrations bullet is unre…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T20:30:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65ce31ab46f45575c2f09358acfe32f99bbbb1a8",
"body": "…ity lint (#230, #231)",
"is_bot": false,
"headline": "feat(packaging): 0.10.6 — bundle cleaner, post-bundle content + ident…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T20:24:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3e3c7551f0f00e43f79e55272fe69989b23ae76",
"body": null,
"is_bot": false,
"headline": "docs(skills): orchestrations v1.3 — Phase 4 close-loop wording",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T20:24:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b8955b8164ca51b09b787b79f5cde879ac6eb5a",
"body": "…ndings attribution, linter-claim wording",
"is_bot": false,
"headline": "docs(changelog): correct 0.10.5 entry — skill version 1.5, fixture/bi…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:56:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f4222e37bd18d26b2f37c187a2e2d5f24c46e3a",
"body": "New ./testing/vitest subpath exports mcpTest (test.extend with ctx + storage fixtures) and McpTestFixtures interface. vitest >=4.0.0 added as an optional peer dependency. packaging guards updated: export-map allowlist gains ./testing/vitest; optional-peer-deps test adds an integration-entrypoint exe\n[…]\nino ^0.64.0 → ^0.65.0; @opentelemetry/resources ^2.7.1 → ^2.8.0; @opentelemetry/sdk-metrics ^2.7.1 → ^2.8.0; @opentelemetry/sdk-node ^0.218.0 → ^0.219.0; @opentelemetry/sdk-trace-node ^2.7.1 → ^2.8.0.",
"is_bot": false,
"headline": "feat(testing): 0.10.5 — mcpTest fixture-based Vitest subpath (#227)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:50:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a1362c22cc9038c1e1aef17c9d262ef6b7765cb2",
"body": "lintCappedListTruncation checked allowlist.includes(name) without guarding against non-array truncationAllowlist values; guard added.",
"is_bot": false,
"headline": "chore(linter): Array.isArray guard for the truncation allowlist check",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:49:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d44bee496c12fdfdaa011f1efbcfd0fb5fe2c8e2",
"body": "… cases (#229)\n\nFifth vitest project 'typecheck' over tests/types/**/*.test-d.ts, using tsc checker with ignoreSourceErrors. maxWorkers: 4 required by vitest's uniform-sequence-group rule. New test:typecheck script. Three .test-d.ts files: error-contract (ReasonOf, TypedFail, TypedRecoveryFor, createFail, createRecoveryFor, HandlerContext), handler-context (HandlerContext inference), and tool-builder (output type inference).",
"is_bot": false,
"headline": "chore(tests): vitest typecheck project with @ts-expect-error negative…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:49:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dbbec769c5bd2baa13452419568870b3028458cd",
"body": "r2Buckets and d1Databases miniflare bindings added to the worker-runtime fixture. Per-provider test files exercise set/get/delete/list/TTL through the worker handler. skills/api-workers v1.3 documents the binding pattern.",
"is_bot": false,
"headline": "chore(tests): R2/D1 emulated workerd storage suites (#228)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:49:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0760ea0a627008344836ffad7a27e185bfff40da",
"body": "R2 rejects list() limits above 1000; limit+1 now clamped to R2_MAX_LIST_LIMIT=1000. At the cap, the response's truncated flag covers has-more detection instead of the +1 probe.",
"is_bot": false,
"headline": "fix(storage): clamp R2 list +1 page probe at the 1000-key cap (#228)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:49:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "54fd2e650dbde7474c170947873d503376cb2619",
"body": "….3 floors (#216)\n\nAbortSignal.any for fetchWithTimeout external-signal composition and retry sleep cancellation. Uint8Array.toBase64/fromBase64 replaces chunked string-based encoding in the workerd/browser branch; Buffer fast-path stays primary. globalThis.performance.now direct delegation in nowMs\n[…]\nre extends AsyncDisposable — custom backend implementations must add [Symbol.asyncDispose]. TextToSpeechResult.audio and SpeechToTextOptions.audio type changed from Buffer|string to Uint8Array|string.",
"is_bot": false,
"headline": "refactor(utils,services): platform-native sweep under Node>=24/Bun>=1…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T16:48:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ffa740dda1ec7f793efe305e9cad953ae50b15d2",
"body": "…rom peers",
"is_bot": false,
"headline": "docs(changelog): fast-check was added to devDependencies, not moved f…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T01:22:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "95c4927058f500771a797617abf425b3193c824c",
"body": "…ync (#217)\n\nPackaging (#217):\n\n- exports map: default condition added to all 18 JS entries\n\n- HEALTHCHECK in Dockerfile and templates/Dockerfile (bun-native fetch, no curl dep)\n\n- tsconfig.base.json, tsconfig.json: importHelpers removed (no-op at ESNext, tslib never declared)\n\n- tsconfig.test.json \n[…]\nerage thresholds raised (stmts 88->91, branches 79->83, fns 90->92, lines 89->92)\n\nSkills:\n\n- api-testing v1.4: output schema assertions via expect.schemaMatching\n\n- api-canvas v1.6: see canvas commit",
"is_bot": false,
"headline": "chore(build,test): 0.10.4 — packaging hygiene, test infra, template s…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T01:19:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d0ad33f93e4241bf5a3f14da20b131f3f6b6000c",
"body": "…Found, catalog deny layer, approxSizeBytes (#221, #222, #223, #224, #226)\n\n- inferSchemaFromRows: all inferred columns now nullable: true; sample cannot prove NOT NULL (#221)\n\n- query() non-registerAs path: streamAndReadUntil(rowLimit+1) replaces runAndReadAll+slice; adds truncated flag to QueryRes\n[…]\nSystemCatalogs: new export; opt-in QueryOptions/RegisterViewOptions.denySystemCatalogs flag (#224)\n\n- describe(): LEFT JOIN duckdb_tables() to populate TableInfo.approxSizeBytes for base tables (#226)",
"is_bot": false,
"headline": "feat(canvas): inferred-nullable fix, streaming cap, missing-table Not…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-11T01:18:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dfeb9ff6de473a04837319999a718e7676b2a8bd",
"body": "…on, sampling removed, server identity, completable args\n\nVersion: 0.10.2 → 0.10.3\nDependency: @types/node ^25.9.2 → 25.9.3 (pinned to patch)",
"is_bot": false,
"headline": "chore(release): 0.10.3 — elicit wired on the wire, URL-mode elicitati…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T23:12:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "07d71331263b1db5ade50df0608912df8a83c110",
"body": "…tures\n\ngit ls-files lists files deleted from the worktree but not yet staged. The audit\ncrashed when trying to read those paths. Added existsSync() filter so uncommitted\ndeletions don't break the audit during development.",
"is_bot": false,
"headline": "chore(scripts): skip worktree-deleted files in audit-open-index-signa…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T23:11:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44d6bda1e971ed14e89ddba0719f3137d0144e96",
"body": "…#213, #218)\n\nCreateAppOptions gains optional title, websiteUrl, description, icons (typed against\nImplementation['icons']). All four are forwarded to the McpServer constructor's\nserverInfo and to buildServerManifest so initialize and /.well-known/mcp.json stay\nconsistent. Explicit description wins \n[…]\nervices and createMcpServerInstance\nbut the registerAll() call was a no-op. The roots/ directory and its test are gone.\nRoots is also deprecated by SEP-2577. RootsRegistry was never publicly exported.",
"is_bot": false,
"headline": "feat(app): server identity fields, remove RootsRegistry placeholder (…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T23:11:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc7e7b02e607eb1c7694fc8c049d5371e353dc71",
"body": "…mpt title (#214)\n\nprompt() args fields may be wrapped with completable() — re-exported from the main\nentry so consumers don't need a direct SDK import. The SDK auto-installs\ncompletion/complete handling and advertises the completions capability when any\nregistered prompt has a completable argument.\n[…]\nResourceTemplate constructor second argument; triggers the\nsame automatic completions capability advertisement.\n\nresource-registration.ts also carries the #211 elicit notifier wiring (file atomicity).",
"is_bot": false,
"headline": "feat(prompts,resources): completable args, resource complete map, pro…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T23:11:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee720eb0c63cb25938796bf1dee3da15bc54521f",
"body": "…, #212, #220)\n\nctx.elicit was never defined at runtime — the extra-sniffing approach misread the\nSDK's RequestHandlerExtra shape. Now wired via registration-time notifier closures:\nelicitInput and getClientCapabilities bound to the per-server Server instance in\nboth tool-registration.ts and resourc\n[…]\nicitFn with a default no-op .url()\nstub so tests exercising form-mode elicitation don't need to supply .url explicitly.\n\nsrc/core/index.ts also carries the #214 completion re-exports (file atomicity).",
"is_bot": false,
"headline": "feat(context): wire ctx.elicit, add URL-mode, remove ctx.sample (#211…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T23:10:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "43b072e45ea9344b4a4dcf6de720959d8935a36e",
"body": "…irror-CLI recipe description, cap-field list",
"is_bot": false,
"headline": "docs(changelog): correct 0.10.2 entry — scaffold stanza paths/user, m…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T17:50:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "75c2b0bc10d1f7efb44f40565d2ed14074864518",
"body": "… rules, scaffold data dirs\n\nhono ^4.12.24 → ^4.12.25\n@cloudflare/vitest-pool-workers ^0.16.13 → ^0.16.14\n@cloudflare/workers-types 4.20260608.1 → 4.20260610.1\n@supabase/supabase-js ^2.108.0 → ^2.108.1\nsanitize-html ^2.17.4 → ^2.17.5",
"is_bot": false,
"headline": "chore(release): 0.10.2 — per-table canvas TTL, canvas/truncation lint…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T17:46:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6aa8b05262127d4b7ca429eb37307e447b780a96",
"body": "…rror-CLI Docker recipe (#199, #195)",
"is_bot": false,
"headline": "feat(templates): writable SQLite data dirs in scaffold Dockerfile, mi…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T17:46:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "772939b251f95fa23ddf4de2aef52d198b334eec",
"body": "…rich.truncated (#209, #197)",
"is_bot": false,
"headline": "feat(linter): canvas-consumer and truncation-disclosure rules, ctx.en…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T17:46:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a058c5efbad6b7e63779510ad706434f987a8d5a",
"body": "…pillover (#140)",
"is_bot": false,
"headline": "feat(canvas): per-table TTL on registerTable, query registerAs, and s…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-10T17:46:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "158747a30ee6c82246925f2c55190e8223d2d8fc",
"body": "…scaffold/packaging fixes",
"is_bot": false,
"headline": "chore(release): 0.10.1 — canvas SQL gate fail-closed, pragma_* deny, …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:45:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a641fe30dec6ebfb21cd919d74968e1ce2bf3dbc",
"body": "…ons (#210)",
"is_bot": false,
"headline": "fix(canvas): fail closed on non-SELECT and deny pragma_* table functi…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:45:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4fe4cc7ec1b5ef3b974f7c8418c867b860ee8d3",
"body": null,
"is_bot": false,
"headline": "fix(scheduling): actionable error when node-cron peer is missing (#200)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:45:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9bc402edbe765de8bdae29594baff47eb892e0cd",
"body": "…uard (#207)",
"is_bot": false,
"headline": "fix(packaging): anchor .mcpbignore dev patterns, add bundle-content g…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:44:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b2a055524862a95b1f015ecb05c9ba4db0dbfea2",
"body": null,
"is_bot": false,
"headline": "fix(templates): ship repository object in manifest (#206)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:44:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a59dea547837af557f39d34a5b9c1b6e3741b951",
"body": null,
"is_bot": false,
"headline": "fix(templates): run scaffold scripts via Bun, drop tsx (#205)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-08T14:44:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e6cd672ee25a8f9e24234b4bfb3dc93fd919e73",
"body": "@cloudflare/vitest-pool-workers ^0.16.11 → ^0.16.13\n@cloudflare/workers-types 4.20260602.1 → 4.20260605.1\n@supabase/supabase-js ^2.106.2 → ^2.107.0\nopenai ^6.41.0 → ^6.42.0",
"is_bot": false,
"headline": "chore(release): 0.10.0 — outline-on-overflow, stringbool env booleans",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-05T12:13:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ac4cc9089157bdfb7f1065ca2994160e59e316d",
"body": "…202)\n\ntemplates/Dockerfile now accepts an APP_VERSION build arg and stamps\norg.opencontainers.image.version in the OCI label block; also declares\norg.opencontainers.image.source (filled with the repo URL at scaffold\ntime). release-and-publish skill updated to pass --build-arg APP_VERSION\nto docker buildx for both amd64/arm64 platforms. Scaffolded servers only\n— existing servers pick this up on re-scaffold.",
"is_bot": false,
"headline": "fix(templates): stamp OCI image.version and source on built images (#…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-05T12:13:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15d8d2b7eea4e77301d5737d4b84e4ecd9f02b7d",
"body": "New /utils exports: outlineOnOverflow(), OUTLINE_VARIANT, selectSections(),\nformatOutline(), DEFAULT_OUTLINE_BUDGET_BYTES. When a document-shaped\npayload exceeds a serialized-byte budget, returns a section outline\n(top-level keys + per-section size) and a re-call notice instead of\ntruncating. Agent \n[…]\nte cache, when to choose\nit over spillover() or capped-list disclosure).\n\ndesign-mcp-server and add-tool skills updated with overflow guidance.\nCLAUDE.md, AGENTS.md, docs/tree.md updated for new dirs.",
"is_bot": false,
"headline": "feat(utils): outline-on-overflow for oversized document payloads (#204)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-05T12:13:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63655562b73a7694d85c5cb6ce2564b40195453f",
"body": "Replaces the hand-rolled envBoolean preprocess in src/config/index.ts\nwith Zod z.stringbool(). Accepts true/false/1/0/yes/no/on/off\n(case-insensitive); rejects unrecognized values at startup instead of\nsilently coercing them to false. Real booleans pass through (Workers\n[vars]). yes/on/y/enabled now\n[…]\nin src/, which coerces \"false\" to true. Scanner now\nskips comment lines to avoid false-positives on doc mentions. Server-\nconfig docs (api-config skill, templates) updated to recommend\nz.stringbool().",
"is_bot": false,
"headline": "feat(config): parse env booleans via Zod stringbool (#201)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-05T12:12:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db1bc01d26a51e50bd2a27342ccc7a695f85c110",
"body": null,
"is_bot": false,
"headline": "chore(release): 0.9.21 — HTTP transport per-request log context fix",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T09:04:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18ddb7eb9322592f8af3d01f893e28b0d06cf3ee",
"body": "…ions skill",
"is_bot": false,
"headline": "docs(templates): expand First Session onboarding, document orchestrat…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T09:04:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a367b9c7edfff97e419f834335912ed63eca6284",
"body": null,
"is_bot": false,
"headline": "docs(skills): mark orchestrations workflows as audience: external",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T09:04:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4fd7c11e126b727e120a847383015725f0ceb2c3",
"body": null,
"is_bot": false,
"headline": "fix(transport): derive per-request context in HTTP handlers (#194)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T09:04:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b24ebb00efd4d556a310236a7631483c1c9d5408",
"body": "…ication routing",
"is_bot": false,
"headline": "chore(release): 0.9.20 — query-string redaction, lint fix, HTTP notif…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T03:42:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "908cadf8a147f5a11c86abdf7134a1d3befb71cd",
"body": "…anvas, design-mcp-server",
"is_bot": false,
"headline": "docs(skills): add MCP-side list-filtering guidance to add-tool, api-c…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T03:42:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "664e10f2bbd43d26535f305162b92940abc5fbde",
"body": "…135)",
"is_bot": false,
"headline": "fix: route list-changed notifications via request scope under HTTP (#…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T03:42:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4ab379de4de2acfe1c4d30c4fd417f60afcce41",
"body": "…ns (#191)",
"is_bot": false,
"headline": "fix(linter): scope error-contract rules to throw sites, not compariso…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T03:41:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3109bb5993ff1eb7d7627b4814bf086a4e7ff577",
"body": "… and logs (#190)",
"is_bot": false,
"headline": "fix(security): redact query-string secrets in fetchWithTimeout errors…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-06-02T03:41:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f72213a81ba556d899d3ab112c99a537028ecad",
"body": "…orkflow gate markers\n\nAdds scripts/release-github.ts (bun run release:github): reads package.json version, derives tag subject, runs gh release create with --verify-tag --notes-from-tag --title 'v<VERSION>: <subject>', attaches dist/*.mcpb when manifest.json exists, and handles the release-already-\n[…]\ny fail-fast on data.retryable === false (#174), ctx.fail auto-populates data.retryable from contract entry, Gate after column in workflow phase tables (#183), MirrorService design-mcp-server guidance.",
"is_bot": false,
"headline": "feat(scripts): 0.9.19 — release:github script, withRetry fail-fast, w…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T11:07:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aa7601461e0ea4543c0b5fe8db5c5c8970a61b54",
"body": "New bullet in the output-design section of design-mcp-server/SKILL.md: when to mirror a bulk upstream instead of paginating it live, with corpus-size thresholds (in-memory / MirrorService / external store) and a pointer to api-mirror.",
"is_bot": false,
"headline": "docs(design-mcp-server): add MirrorService bulk-upstream design guidance",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T11:07:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f625b576d2d0f79cd41dfabadb141559548fbf3",
"body": "Every phase row in skills/orchestrations/workflows/*.md now has a Gate after column: barrier (with a terse reason) or gate-free. The orchestrator can derive spawn/round structure directly from the table without re-deriving the barrier positions each run.\n\nskills/orchestrations/SKILL.md adds a one-line pointer tying the new column back to the 'Barriers only where gates sit' principle.",
"is_bot": false,
"headline": "feat(orchestrations): Gate after column in workflow phase tables (#183)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T11:06:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f825f53b7b2f58d39bea80315c3b1a54c88a77b7",
"body": "defaultIsTransient now checks error.data.retryable === false and returns non-transient immediately, even when the error code is in the transient set (Timeout, ServiceUnavailable, RateLimited). This closes the gap for deterministic upstream failures surfaced as HTTP 200 with an error body — they no l\n[…]\ncontract entry's retryable field as a base default. Caller-supplied data.retryable overrides per-occurrence; reason is always forced last. Contract entries that omit retryable inject no key onto data.",
"is_bot": false,
"headline": "feat(utils): withRetry fail-fast on data.retryable === false (#174)",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T11:06:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a458781a006bf8d1909704cd504740c46fc972b9",
"body": "… gate (#123)",
"is_bot": false,
"headline": "feat(devcheck): 0.9.18 — skill-version gate (#99), open-indexed-named…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T10:17:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "72ec04223613586ac432f68c99947a6075725538",
"body": "…e3 peer dep\n\nNew Tier 3 primitive: `defineMirror()` + `sqliteMirrorStore()` under\n`@cyanheads/mcp-ts-core/mirror`. Provides the source-agnostic machinery\nfor a persistent, self-refreshing local mirror of a bulk upstream dataset\n(embedded SQLite + FTS5): cross-runtime store, volatile cursor / durabl\n[…]\npply only the ingester (sync generator) and schema. Node/Bun only;\n`bun:sqlite` built-in on Bun, `better-sqlite3` optional peer on Node.\n\n`@cloudflare/workers-types` 4.20260530.1 → 4.20260531.1 (dev).",
"is_bot": false,
"headline": "feat(services): 0.9.17 — MirrorService, /mirror subpath, better-sqlit…",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-31T05:41:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52a7122c5ba6def233f6e71900537e886a9d9c09",
"body": "The httpError test built a Response with status 204 and an empty-string body; 204 is a null-body status that rejects any body, so the suite failed under current runtimes. Default the helper body to null.\n\nAdd behavior coverage for untested paths: a new resource-rules suite, landing-rules validation \n[…]\nraversal, sanitization security edge cases, scheduler lifecycle (listJobs/destroyAll/not-found), error factories, tokenCounter, and JSON/YAML error truncation. Branches 83.0% to 83.9%; no src changes.",
"is_bot": false,
"headline": "test: fix null-body httpError helper, expand suite coverage",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-30T14:16:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6002abf68947d859e1523e607fae3f6084e416bf",
"body": "…tools\n\nenrichmentTrailer.render was an arrow property, so its parameter was\nvariance-strict under strictFunctionTypes — a concrete tool's narrow\nrender value no longer assigned to the type-erased AnyToolDefinition,\nbreaking createApp({ tools }) typecheck for every tool declaring an\nenrichment block (even with no trailer literal). Switch to method\nsyntax for bivariant params, matching format and handler.\n\nType-only; no runtime change. (#180)",
"is_bot": false,
"headline": "fix: 0.9.16 — restore AnyToolDefinition assignability for enrichment …",
"author_name": "cyanheads",
"author_login": "cyanheads",
"committed_at": "2026-05-30T03:27:15Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 33,
"commits_last_year": 1289,
"latest_release_at": "2026-07-19T12:24:31Z",
"latest_release_tag": "v0.10.15",
"releases_from_tags": false,
"days_since_last_push": 3,
"active_weeks_last_year": 34,
"days_since_latest_release": 5,
"mean_days_between_releases": 4.2
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@cyanheads/mcp-ts-core",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"agent",
"agent-native",
"ai",
"ai-agent",
"bun",
"cloudflare-workers",
"declarative",
"framework",
"mcp",
"mcp-server",
"mcp-framework",
"model-context-protocol",
"observability",
"opentelemetry",
"tools",
"typescript"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
"is_deprecated": false,
"latest_version": "0.10.15",
"repository_url": "https://github.com/cyanheads/mcp-ts-core",
"versions_count": 142,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 44618,
"first_published_at": "2026-03-12T12:17:08.098000Z",
"latest_published_at": "2026-07-19T12:24:09.144000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 29,
"stars": 147,
"watchers": 2,
"fork_history": {
"days": [
{
"date": "2025-04-01",
"count": 1
},
{
"date": "2025-04-27",
"count": 1
},
{
"date": "2025-05-12",
"count": 1
},
{
"date": "2025-05-14",
"count": 2
},
{
"date": "2025-05-17",
"count": 1
},
{
"date": "2025-07-09",
"count": 1
},
{
"date": "2025-07-23",
"count": 1
},
{
"date": "2025-09-03",
"count": 1
},
{
"date": "2025-10-02",
"count": 1
},
{
"date": "2025-10-14",
"count": 1
},
{
"date": "2025-10-16",
"count": 1
},
{
"date": "2025-10-30",
"count": 1
},
{
"date": "2025-11-17",
"count": 1
},
{
"date": "2025-12-04",
"count": 1
},
{
"date": "2025-12-24",
"count": 1
},
{
"date": "2026-01-02",
"count": 1
},
{
"date": "2026-01-04",
"count": 1
},
{
"date": "2026-01-14",
"count": 1
},
{
"date": "2026-02-20",
"count": 1
},
{
"date": "2026-03-16",
"count": 2
},
{
"date": "2026-03-28",
"count": 1
},
{
"date": "2026-04-28",
"count": 1
},
{
"date": "2026-06-01",
"count": 1
},
{
"date": "2026-06-05",
"count": 1
},
{
"date": "2026-06-17",
"count": 1
},
{
"date": "2026-06-28",
"count": 1
},
{
"date": "2026-07-03",
"count": 1
}
],
"complete": true,
"collected": 29,
"total_forks": 29
},
"star_history": null,
"open_issues_and_prs": 59
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 54037,
"source_files_sampled": 445,
"oversized_source_files": 0,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"templates/AGENTS.md",
"templates/CLAUDE.md"
],
"agent_instruction_max_bytes": 39823
},
"dependencies": {
"manifests": [
"package.json",
"templates/package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "@hono/node-server",
"direct": false,
"version": "1.19.15",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.9,
"advisory_ids": [
"GHSA-frvp-7c67-39w9"
],
"fixed_version": "2.0.5",
"advisory_count": 1,
"oldest_advisory_days": 3
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"moderate": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 115,
"malicious_count": 0,
"assessed_package": "npm:@cyanheads/mcp-ts-core@0.10.15",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@hono/mcp",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.3.1"
},
{
"name": "@hono/node-server",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.10"
},
{
"name": "@modelcontextprotocol/ext-apps",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.7.4"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "@opentelemetry/api",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.9.1"
},
{
"name": "dotenv",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "hono",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.30"
},
{
"name": "jose",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^6.2.3"
},
{
"name": "pino",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^10.3.1"
},
{
"name": "zod",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.3"
},
{
"name": "@cyanheads/mcp-ts-core",
"manifest": "templates/package.json",
"ecosystem": "npm",
"version_constraint": "^{{FRAMEWORK_VERSION}}"
},
{
"name": "pino-pretty",
"manifest": "templates/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.3"
},
{
"name": "zod",
"manifest": "templates/package.json",
"ecosystem": "npm",
"version_constraint": "{{ZOD_VERSION}}"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@cyanheads/mcp-ts-core",
"direct": true,
"version": "^{{FRAMEWORK_VERSION}}",
"ecosystem": "npm"
},
{
"name": "@hono/mcp",
"direct": true,
"version": "^0.3.1",
"ecosystem": "npm"
},
{
"name": "@hono/node-server",
"direct": true,
"version": "^2.0.10",
"ecosystem": "npm"
},
{
"name": "@modelcontextprotocol/ext-apps",
"direct": true,
"version": "^1.7.4",
"ecosystem": "npm"
},
{
"name": "@modelcontextprotocol/sdk",
"direct": true,
"version": "^1.29.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/api",
"direct": true,
"version": "^1.9.1",
"ecosystem": "npm"
},
{
"name": "dotenv",
"direct": true,
"version": "^17.4.2",
"ecosystem": "npm"
},
{
"name": "hono",
"direct": true,
"version": "^4.12.30",
"ecosystem": "npm"
},
{
"name": "jose",
"direct": true,
"version": "^6.2.3",
"ecosystem": "npm"
},
{
"name": "pino",
"direct": true,
"version": "^10.3.1",
"ecosystem": "npm"
},
{
"name": "pino-pretty",
"direct": true,
"version": "^13.1.3",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "^4.4.3",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "{{ZOD_VERSION}}",
"ecosystem": "npm"
},
{
"name": "@biomejs/biome",
"direct": false,
"version": "2.5.4",
"ecosystem": "npm"
},
{
"name": "@cloudflare/vitest-pool-workers",
"direct": false,
"version": "^0.18.4",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workers-types",
"direct": false,
"version": "5.20260706.1",
"ecosystem": "npm"
},
{
"name": "@duckdb/node-api",
"direct": false,
"version": "^1.5.4-r.1",
"ecosystem": "npm"
},
{
"name": "@hono/otel",
"direct": false,
"version": "^1.1.2",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/exporter-metrics-otlp-http",
"direct": false,
"version": "^0.220.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/exporter-trace-otlp-http",
"direct": false,
"version": "^0.220.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/instrumentation-http",
"direct": false,
"version": "^0.220.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/instrumentation-pino",
"direct": false,
"version": "^0.66.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/resources",
"direct": false,
"version": "^2.9.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/sdk-metrics",
"direct": false,
"version": "^2.9.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/sdk-node",
"direct": false,
"version": "^0.220.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/sdk-trace-node",
"direct": false,
"version": "^2.9.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/semantic-conventions",
"direct": false,
"version": "^1.43.0",
"ecosystem": "npm"
},
{
"name": "@socketsecurity/bun-security-scanner",
"direct": false,
"version": "^1.1.2",
"ecosystem": "npm"
},
{
"name": "@supabase/supabase-js",
"direct": false,
"version": "^2.110.6",
"ecosystem": "npm"
},
{
"name": "@types/bun",
"direct": false,
"version": "^1.3.14",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "26.1.1",
"ecosystem": "npm"
},
{
"name": "@types/papaparse",
"direct": false,
"version": "^5.5.2",
"ecosystem": "npm"
},
{
"name": "@types/sanitize-html",
"direct": false,
"version": "^2.16.1",
"ecosystem": "npm"
},
{
"name": "@types/validator",
"direct": false,
"version": "^13.15.10",
"ecosystem": "npm"
},
{
"name": "@vitest/coverage-istanbul",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/ui",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "better-sqlite3",
"direct": false,
"version": "^12.11.1",
"ecosystem": "npm"
},
{
"name": "bun-types",
"direct": false,
"version": "^1.3.14",
"ecosystem": "npm"
},
{
"name": "chrono-node",
"direct": false,
"version": "^2.10.0",
"ecosystem": "npm"
},
{
"name": "clipboardy",
"direct": false,
"version": "^5.3.1",
"ecosystem": "npm"
},
{
"name": "defuddle",
"direct": false,
"version": "^0.19.1",
"ecosystem": "npm"
},
{
"name": "depcheck",
"direct": false,
"version": "^1.4.7",
"ecosystem": "npm"
},
{
"name": "diff",
"direct": false,
"version": "^9.0.0",
"ecosystem": "npm"
},
{
"name": "execa",
"direct": false,
"version": "^9.6.1",
"ecosystem": "npm"
},
{
"name": "fast-check",
"direct": false,
"version": "^4.9.0",
"ecosystem": "npm"
},
{
"name": "fast-xml-parser",
"direct": false,
"version": "^5.10.1",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "^7.0.5",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "^7.0.6",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "^5.2.1",
"ecosystem": "npm"
},
{
"name": "linkedom",
"direct": false,
"version": "^0.18.13",
"ecosystem": "npm"
},
{
"name": "node-cron",
"direct": false,
"version": "^4.6.0",
"ecosystem": "npm"
},
{
"name": "openai",
"direct": false,
"version": "^6.46.0",
"ecosystem": "npm"
},
{
"name": "papaparse",
"direct": false,
"version": "^5.5.4",
"ecosystem": "npm"
},
{
"name": "partial-json",
"direct": false,
"version": "^0.1.7",
"ecosystem": "npm"
},
{
"name": "pdf-lib",
"direct": false,
"version": "^1.17.1",
"ecosystem": "npm"
},
{
"name": "repomix",
"direct": false,
"version": "^1.16.1",
"ecosystem": "npm"
},
{
"name": "sanitize-html",
"direct": false,
"version": "^2.17.6",
"ecosystem": "npm"
},
{
"name": "tsc-alias",
"direct": false,
"version": "^1.9.0",
"ecosystem": "npm"
},
{
"name": "tsc-alias",
"direct": false,
"version": "^1.9.1",
"ecosystem": "npm"
},
{
"name": "typedoc",
"direct": false,
"version": "^0.28.20",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^6.0.3",
"ecosystem": "npm"
},
{
"name": "unpdf",
"direct": false,
"version": "^1.6.2",
"ecosystem": "npm"
},
{
"name": "validator",
"direct": false,
"version": "^13.15.35",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.1.5",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "^4.1.10",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "^4.1.9",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 66,
"direct_count": 13,
"indirect_count": 53
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 13,
"open_issues": 59,
"closed_ratio": 0.768,
"closed_issues": 195,
"closed_unmerged_prs": 13
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "cyanheads",
"commits": 1544,
"avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4"
},
{
"type": "User",
"login": "caseybreen",
"commits": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/26234849?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.995
},
"quality_signals": {
"has_ci": false,
"has_tests": true,
"ci_workflows": [],
"has_docs_dir": true,
"linter_configs": [
"biome.json"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 1,
"reason": "9 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
"ran_at": "2026-07-25T09:49:09Z",
"aggregate_score": 3.7,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-19T12:23:34Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-05-23T02:12:04Z",
"ci_last_conclusion": null,
"oldest_open_issues": [
{
"number": 66,
"created_at": "2026-04-24T21:00:39Z",
"last_comment_at": "2026-05-22T00:35:02Z",
"last_comment_author": "cyanheads"
},
{
"number": 75,
"created_at": "2026-04-28T04:08:52Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 77,
"created_at": "2026-04-28T23:53:32Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 78,
"created_at": "2026-04-28T23:53:33Z",
"last_comment_at": "2026-06-07T18:16:07Z",
"last_comment_author": "xlyoung"
},
{
"number": 79,
"created_at": "2026-04-28T23:53:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 94,
"created_at": "2026-05-01T23:25:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 106,
"created_at": "2026-05-03T07:02:02Z",
"last_comment_at": "2026-05-03T08:11:29Z",
"last_comment_author": "cyanheads"
},
{
"number": 107,
"created_at": "2026-05-03T07:39:42Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 110,
"created_at": "2026-05-03T22:45:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 139,
"created_at": "2026-05-17T18:23:11Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 142,
"created_at": "2026-05-21T15:01:15Z",
"last_comment_at": "2026-06-11T22:37:44Z",
"last_comment_author": "cyanheads"
},
{
"number": 151,
"created_at": "2026-05-23T16:12:48Z",
"last_comment_at": "2026-06-02T10:26:46Z",
"last_comment_author": "cyanheads"
},
{
"number": 152,
"created_at": "2026-05-23T18:12:07Z",
"last_comment_at": "2026-05-23T18:18:18Z",
"last_comment_author": "cyanheads"
},
{
"number": 162,
"created_at": "2026-05-28T09:05:08Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 163,
"created_at": "2026-05-28T10:14:45Z",
"last_comment_at": "2026-05-28T12:41:51Z",
"last_comment_author": "cyanheads"
},
{
"number": 164,
"created_at": "2026-05-28T23:27:45Z",
"last_comment_at": "2026-05-31T05:42:50Z",
"last_comment_author": "cyanheads"
},
{
"number": 187,
"created_at": "2026-06-01T06:12:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 188,
"created_at": "2026-06-01T06:13:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 193,
"created_at": "2026-06-02T03:33:33Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 196,
"created_at": "2026-06-02T10:26:36Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/cyanheads/mcp-ts-core",
"host": "github.com",
"name": "mcp-ts-core",
"owner": "cyanheads"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"security": 47,
"vitality": 93,
"community": 56,
"governance": 55,
"engineering": 70
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 93,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 88,
"inputs": {
"commits_last_year": 1289,
"human_commit_share": 1,
"days_since_last_push": 3,
"active_weeks_last_year": 34
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "34/52 weeks with commits",
"points": 23.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 34
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1289 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1289
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 33,
"latest_release_tag": "v0.10.15",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 4.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "33 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 33
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~4.2 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 4.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 5,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 5 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 5
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 56,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"forks": 29,
"stars": 147,
"watchers": 2,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "147 stars",
"points": 35.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 147
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "29 forks",
"points": 12.1,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 29
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "2 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 2
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"packages": [
"@cyanheads/mcp-ts-core"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 44618
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "44,618 downloads/month across npm",
"points": 62,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 44618,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 55,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 18,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.995
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"merged_prs": 13,
"open_issues": 59,
"closed_issues": 195,
"issue_closed_ratio": 0.768,
"closed_unmerged_prs": 13
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "77% of issues closed",
"points": 35.9,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 77
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "13/26 decided PRs merged",
"points": 19.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 13,
"decided": 26
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 64,
"inputs": {
"followers": 175,
"owner_type": "User",
"is_verified": null,
"owner_login": "cyanheads",
"public_repos": 146,
"account_age_days": 4225
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "175 followers of cyanheads",
"points": 16.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 175,
"login": "cyanheads"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "146 public repos, account ~11 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 146
}
},
{
"code": "account_age_years",
"params": {
"years": 11
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@cyanheads/mcp-ts-core"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "142 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 142
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 70,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 50,
"inputs": {
"has_ci": false,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "biome.json",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"mcp",
"mcp-server",
"model-context-protocol",
"ai",
"opentelemetry",
"cloudflare-workers",
"agent-native",
"framework",
"typescript",
"cyanheads"
],
"has_wiki": true,
"homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "10 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 10
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 47,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 37,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 12,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 6,
"scorecard_aggregate": 3.7
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "9 existing vulnerabilities detected",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Matched the npm:@cyanheads/mcp-ts-core@0.10.15 runtime dependency closure — what installing the published package pulls in — 115 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@cyanheads/mcp-ts-core@0.10.15",
"assessed": 115
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 88,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 115,
"unassessed_packages": 0,
"affected_by_severity": "moderate 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
"points": 13.2,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "@hono/node-server 1.19.15 (moderate 5.9)"
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 115,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 74,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"templates/AGENTS.md",
"templates/CLAUDE.md"
],
"agent_instruction_max_bytes": 39823
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "biome.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 54037,
"source_files_sampled": 445,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/445 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 445,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch npm package '{{PACKAGE_NAME}}' from its registry"
],
"report_type": "repository",
"generated_at": "2026-07-25T09:49:14.556607Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cyanheads/mcp-ts-core.svg",
"full_name": "cyanheads/mcp-ts-core",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}