Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 05:37 UTC

fro-bot / space-bus

Space Bus — workspace agent bus for OpenCode. One control agent tasking per-project agents over the OpenCode server API, with an MCP facade for Claude Desktop.

TypeScriptMIT★ 1 зірка⑂ 0 форківз лип. 2026 р.Переглянути на GitHub ↗

fro-bot/space-bus має індекс здоров’я 67 зі 100, що відповідає смузі «Помірний». Найвищий показник — Engineering Quality (86/100), найнижчий — Community & Adoption (33/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

67
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

67
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Fro BotОсобистий обліковий запис
1 підписник7 публічних репозиторіївз бер. 2021 р.

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
npm@fro.bot/space-bus0.15.04 190225 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

74Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
2.8/36Ритм комітів — 4/52 тижнів із комітами
18/18Обсяг комітів — 111 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year111
human_commit_share0,58
days_since_last_push0
active_weeks_last_year4
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 21 релізів
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~0,9 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count21
latest_release_tagv0.15.0
releases_from_tagsні
days_since_latest_release5
mean_days_between_releases0,9
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

33У зоні ризику · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 1 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
48.3/80Щомісячні завантаження — 4 190 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@fro.bot/space-bus
dependents
ecosystemsnpm
total_downloads
monthly_downloads4 190
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

59Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0.3/22.5Розподіл комітів — головний контриб’ютор — автор 99% комітів
2.7/13.5Широта контриб’юторів — 2 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled2
top_contributor_share0,986
Як обчислюється оцінка
39.6/46.8Вирішення issue — закрито 85% issue
37.8/38.3Прийняття PR — злито 92/93 вирішених PR
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Використані вхідні дані
merged_prs92
open_issues4
closed_issues22
issue_closed_ratio0,846
closed_unmerged_prs1

Власність та опіка

37У зоні ризику
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
2.2/25Охоплення власника — 1 підписників у fro-bot
17.3/25Послужний список — 7 публічних репозиторіїв, вік облікового запису ~5 р.
Використані вхідні дані
followers1
owner_typeUser
is_verified
owner_loginfro-bot
public_repos7
account_age_days1 967
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 22 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@fro.bot/space-bus
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

86Відмінний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 7 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — biome.json
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні

Документація

90Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://www.npmjs.com/package/@fro.bot/space-bus
10/10Опис репозиторію
10/10Теми — 6 тем
0/10Wiki
Використані вхідні дані
topicsagent-orchestration, bun, mcp, opencode, plugin, typescript
has_wikiні
homepagehttps://www.npmjs.com/package/@fro.bot/space-bus
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

81Добрий · 16% загального індексу
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — немає даних
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate7,9
Виключено з оцінювання (немає даних або не застосовно): branch_protection, packaging, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
13.2/25Непрямі залежності без відомих сповіщень — уражено 1: @hono/node-server 1.19.15 (moderate 5.9)
40/40Немає задавнених сповіщень — жодне сповіщення не є публічним довше за 90 дн.
Використані вхідні дані
sourceosv
advisories1
affected_packages1
assessed_packages95
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Звірено з runtime-замиканням залежностей npm:@fro.bot/space-bus@0.15.0 — тим, що тягне за собою встановлення опублікованого пакета, — 95 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

64Помірний · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — AGENTS.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 58 з 58 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes6 683
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — biome.json
11/11Статична перевірка типів — tsconfig.json
0/10Відтворюване середовище
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
54/55Керовані розміри файлів — 1/54 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes95 488
source_files_sampled54
oversized_source_files1
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
0/40Придатні до запуску приклади
Використані вхідні дані
example_dirs
has_mcp_signalтак
api_schema_files

Ключові факти

1зірок GitHub
2контриб'юторів
111комітів за останні 12 місяців
0днів від останнього пушу
21релізів
1бас-фактор
4відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

OpenSSF Scorecard 7.9 / 10
7.9сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 05:37 UTC

10Binary-Artifactsno binaries found in the repo
н/дBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackagingpackaging workflow not detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
8Vulnerabilities2 existing vulnerabilities detected
Прямі залежності 2
РеєстрПакетОбмеження версіїМаніфест
npm@modelcontextprotocol/sdk1.29.0package.json
npmzod^4.4.3package.json
Усі залежності 7

Повний розв'язаний набір залежностей із графа залежностей GitHub: 2 прямих і 5 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
npm@modelcontextprotocol/sdk1.29.0пряма
npmzod^4.4.3пряма
npm@biomejs/biome2.5.2непряма
npm@changesets/cli2.31.1непряма
npm@opencode-ai/plugin1.18.2непряма
npm@types/bun1.3.14непряма
npmtypescript5.9.3непряма
Сповіщення про залежності 1

Встановлення npm:@fro.bot/space-bus@0.15.0 тягне 95 пакетів, прямих і транзитивних: 1 мають відомі сповіщення, з них 0 — прямі залежності.

ПакетВерсіяЗв'язокКритичністьСповіщеньВиправлено в
@hono/node-server1.19.15непрямапомірна12.0.5

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "agent-orchestration",
        "bun",
        "mcp",
        "opencode",
        "plugin",
        "typescript"
      ],
      "is_fork": false,
      "size_kb": 671,
      "has_wiki": false,
      "homepage": "https://www.npmjs.com/package/@fro.bot/space-bus",
      "languages": {
        "CSS": 9461,
        "TypeScript": 676331
      },
      "pushed_at": "2026-07-25T03:51:27Z",
      "created_at": "2026-07-03T01:21:11Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T06:06:47Z",
      "description": "Space Bus — workspace agent bus for OpenCode. One control agent tasking per-project agents over the OpenCode server API, with an MCP facade for Claude Desktop.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "fro.bot",
      "name": "Fro Bot",
      "type": "User",
      "login": "fro-bot",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/80104189?v=4",
      "created_at": "2021-03-05T11:46:20Z",
      "is_verified": null,
      "public_repos": 7,
      "account_age_days": 1967
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-19T08:38:41Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-18T18:34:56Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-13T08:21:20Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-13T05:24:16Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-12T08:12:51Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-11T23:12:18Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-07-11T20:27:22Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-11T17:05:47Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-11T03:11:19Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-07-10T23:42:06Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-10T21:45:41Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-07-06T05:12:04Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-05T19:20:01Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-07-05T13:38:57Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-04T18:44:36Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-04T15:32:14Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-04T15:04:08Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-04T14:02:43Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-07-04T02:57:01Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-04T00:21:24Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-03T20:17:25Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7fa38ad1023c9adbca43fd05fb22add34ef0bc3b",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#114)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-19T08:37:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f0a3aa261cce593a4148371412963c335f2e7ce",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(dev): update dependency @changesets/cli to v2.31.1 (#108)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-19T08:30:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe0cc42fbd11c201edfd0d11319ba5b07007ea0a",
          "body": "caller-generated OpenCode message IDs plus typed partial-failure handles enable safe reconciliation",
          "is_bot": false,
          "headline": "feat: add dispatch message correlation (#113)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-19T08:16:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "747d33745ca613c634e73987a0434036fbe2e989",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.19 (#105)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-18T19:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "303e8a9d6083f18a5d9d3138f1162fb5b29f84f4",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update bfra-me/.github to v4.16.37 (#103)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-18T18:54:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aede7357762cd63a47348c64b101d0111f7615b",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update GitHub Actions (#101)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-18T18:47:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "778311fed4f513d8690d21b0003972339dd4d896",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#111)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-18T18:33:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88023385c852c10557bfb8c14bb240b034a4a12e",
          "body": "Add bounded message reads, structured pending-question access, and explicit question replies with validation. Extend dispatch with a safe fail-closed blocked mode that returns blocked state instead of mutating when policy is set, while preserving default question-reply behavior.",
          "is_bot": false,
          "headline": "feat: add explicit session interaction APIs (#109)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-18T18:30:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f59950560d52830934f217c98e6c0876a7377680",
          "body": "Pass explicit --config via resolveRosterPath override instead of mutating process.env.SPACE_BUS_CONFIG.\n\nAdd regression tests in cli/config to pin behavior: --config resolves only for that invocation, keeps SPACE_BUS_CONFIG precedence/isolation intact when pre-set, and leaves ambient env untouched after command parsing.",
          "is_bot": false,
          "headline": "fix: avoid leaking CLI roster config (#110)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-18T18:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e20e01775918a01855eb5aba64d04bf966f4d51",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.88.0 (#98)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T21:09:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "387f9c8df8ff7a184d237608b277deaa4603238c",
          "body": "chore: load local development plugin",
          "is_bot": false,
          "headline": "chore: load the local development plugin (#99)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-13T09:26:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98c6a29fcb13c959c4068b1cd4feacbf1cb4d4aa",
          "body": "docs: capture MCP response-envelope contract",
          "is_bot": false,
          "headline": "docs: document MCP response-envelope contract (#97)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-13T09:09:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd1109521a332a96b20da5ffeea3d9938db4fcb",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#96)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T08:19:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b35b8394bfc51d48856cf6c1e35b1eb9393cf21a",
          "body": "fix(mcp): return structured registry mutation results",
          "is_bot": false,
          "headline": "fix(mcp): preserve successful registry mutations (#95)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-13T08:17:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69c1cec5af7b6430242969b5a8a136107e02ff31",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#91)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T05:22:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "721000dc4335c00a7c0b7c213eca38cd30dbdaa1",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.16 (#85)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T05:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dc0794ddbe012dd6df45514c0ade79f655d07b1",
          "body": null,
          "is_bot": false,
          "headline": "ci(renovate): skip artifacts update for bun and npm (#92)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-13T05:07:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e954643a75559570fc417b42a29d5444e63b8ead",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.87.1 (#94)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T04:21:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37b5adecbff361bf113f7619064453d065731f05",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.87.0 (#90)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-13T03:20:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d475e91bdf25774fc23034a4830beafb8a5180f1",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update bfra-me/.github to v4.16.36 (#89)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-12T23:11:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7444781080cc74ba6f777976da2a55566c588c1e",
          "body": "…session default (Phase B) (#88)\n\n* feat: per-call roster addressing — registry loader + roster param + result echo\n\n* feat: bus_registry management tool + MCP session default\n\n* chore: changeset for multi-roster addressing (Phase B)\n\n* fix: apply Phase B review findings — once-resolved paths, strict actions, session hygiene, registry-default routing\n\n* fix: build plugin-facing bus_registry args with tool.schema (zod version reconciliation)",
          "is_bot": false,
          "headline": "feat: multi-roster addressing — roster param, bus_registry tool, MCP …",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-12T22:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05aa9f7c8d2370f42dc5d61c57a7802f43e83d9c",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#87)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-12T08:11:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "989797672d4d65fbc3df1ff75978b12cd3f2af79",
          "body": "…ubpath (#86)\n\n* docs: multi-roster support brainstorm + plan\n\n* feat: roster registry — schema, node module, test isolation\n\n* feat: roster mutation module — create/edit spacebus.json\n\n* feat: discovery rosterPath + /registry library subpath\n\n* chore: changeset for multi-roster substrate (minor)\n\n*\n[…]\n because ensureServer had keyed its state dir/discovery\n  write off the uncanonicalized symlink path instead). Restored the fix\n  immediately after confirming.\n\n* docs: check off Phase A units in plan",
          "is_bot": false,
          "headline": "feat: multi-roster substrate — registry, mutation module, /registry s…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-12T07:44:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1264a93219d4731c79377350acb9669c1125567",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.85.1 (#76)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-12T05:26:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "033db105310789e56e18fae822e1995ada545c79",
          "body": "docs: compound service-persistence learnings (launchd env, TOCTOU, probe fallback)\n\nThree learnings from the 0.11.0 service-persistence arc (#80):\n- new: pin ambient env (PATH + XDG_STATE_HOME) into generated launchd units\n  — launchd's sparse env breaks shim-resolved binaries and splits state roots\n[…]\nx lstat-then-open with atomic O_NOFOLLOW + fchmod\n- update: fold the printJob probe (failure-conflated-with-absence) into the\n  reused-kill-helper-fallbacks doc as a second instance of the same family",
          "is_bot": false,
          "headline": "docs: compound service-persistence learnings (#83)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-12T04:15:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e3a788f7f406fad5b0c98664c5de119bf2977403",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#82)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-11T23:10:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1718a51c43a389f2e37091a73b1dc7ed39b169f",
          "body": "…daemon (#80)\n\n* docs: service-persistence requirements + implementation plan\n\n* feat: launchd provider — plist generation + launchctl runner (unit 1)\n\nImplements Unit 1 of the service-persistence plan: pure-ish Node-only\nplist generation, atomic owner-only writes, tamper-refusal checks, and\na seam-\n[…]\nO_WRONLY|O_APPEND|O_CREAT|O_NOFOLLOW) so the kernel refuses a\nsymlinked final component at open time, and fchmod the resulting fd\ninstead of chmod-by-path. ELOOP maps to the 'refusing symlink' result.",
          "is_bot": false,
          "headline": "feat: service persistence — launchd agent for reboot-durable managed …",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T23:06:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4fefad7d3732212fb114bd359fa9b4f306b48bd3",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#79)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-11T20:26:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3afbbb69894c2b2444450e26862b8a6e82ed89a1",
          "body": "…s dist) (#78)\n\n* docs: second same-day instance of the packaged-artifact blind spot\n\nThe browser-safety gate bundled from src/ and passed while the published\ndist/{core,contract,format}.js carried a node:module createRequire prelude\nthat broke Vite downstream (mothership#22; fixed in 0.10.1). Adds the\ndist-level-twin prevention rule.\n\n* docs: state the dist-prelude fix as proposed (#77 open), not shipped",
          "is_bot": false,
          "headline": "docs: second instance of the packaged-artifact blind spot (src gate v…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T20:23:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3b2631b9dbecd9233f251fcb340bed23b8c7f65",
          "body": "fix: build browser-safe subpaths (core/contract/format) with browser target\n\nThe published npm artifacts for dist/core.js, dist/contract.js, and\ndist/format.js carried Bun's node-target createRequire(node:module)\nprelude, breaking Vite bundling for consumers like Mothership (which had\nto ship a work\n[…]\nevel gate that runs\nbun run build and scans the published dist/*.js files directly for\nnode: imports -- the existing test only bundled from src/ and couldn't\ncatch a build.ts regression like this one.",
          "is_bot": false,
          "headline": "fix: browser-safe subpath artifacts must not carry a Node prelude (#77)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T20:21:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2464d843b8bec3b4a33450b85d723221fd0b383c",
          "body": "…pot (#75)\n\ndocs: capture OpenCode reserved-subpath loader collision + dogfooding blind spot\n\nTwo solutions docs from the 0.9.0 plugin-load failure (fixed in 0.10.0, #73):\n- integration-issues: exports[\"./server\"] is OpenCode's reserved plugin\n  entrypoint (resolved before main); publishing a librar\n[…]\nhain + guard.\n- workflow-issues: a source-file plugin ref bypasses npm entrypoint\n  resolution, masking the packaging bug for 0.6.0-0.9.0.\nCross-linked into the plugin tool-registration best-practice.",
          "is_bot": false,
          "headline": "docs: OpenCode reserved-subpath loader collision + dogfooding blind s…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T18:48:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1240d336af3871f24aa49434637ac50e8924373",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#74)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-11T17:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cb9245d2379511eb2a3dbf0621301a4140055f0",
          "body": "…on (#73)\n\n* fix: remap ./server subpath to plugin entry — OpenCode loader collision\n\n* fix: bump changeset to minor + automate negative-control guard test\n\n- ./server repoint is a shape change to a published subpath; README's\n  stability contract ships shape changes as minor. Migration note added\n  for direct /server importers (silent-failure warning).\n- Negative control is now an automated test: dist/server.js must fail\n  the loader's V1 shape check, proving the guard discriminates.",
          "is_bot": false,
          "headline": "fix: remap ./server subpath to plugin entry — OpenCode loader collisi…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T17:02:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d4ccb3b38a7844b72e770a6f7a5708f472f490b",
          "body": "…aims) (#71)\n\ndocs: capture async-foundation learnings (blocking-wait primitive + verify-claims)\n\nTwo best-practices learnings from the 0.9.0 async-delegation work:\n\n- NEW: blocking-wait-primitive-on-stateless-surface — designing a\n  block-until-attention primitive when the surface is stateless (no\n\n[…]\n status() behavior as new P0 bugs. 'Is this\n  a NEW bug?' is as empirically checkable as 'is this endpoint authed?' —\n  read what the base branch already did before accepting the diff\n  introduced it.",
          "is_bot": false,
          "headline": "docs: async-foundation learnings (blocking-wait primitive + verify-cl…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T04:01:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c79b8ff9ae46d31619e1979f653fee19476c1dc7",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#70)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-11T03:10:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51d0154f26b91545c9dec1715772428615589e28",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.85.0 (#69)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-11T03:07:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e57bffd785b4d3658b4817793a6342d511c1fdf",
          "body": "…it (0.9.0) (#68)\n\n* feat(core): normalized session state enum + deriveSessionState (#49 async foundation)\n\nAdd a single normalized lifecycle enum (running|blocked|complete|failed|\nnot_found) derived once in core and exported browser-safe on /contract, so\ncallers stop inferring state from raw busy/b\n[…]\nt #10). init was never used\nby the double; drop it from both the wrapper param and the inner call to\nmatch makeWaitFetch's one-param shape. The test still proves\ndeadline-independence (pollCount > 1).",
          "is_bot": false,
          "headline": "feat: async-delegation foundation — normalized session state + bus_wa…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-11T03:02:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0782b58d02c11ed7627880c5939bb1c48c4495c",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#64)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-10T23:41:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "930d6983b355da7aae81de79af30f90a8623d8ce",
          "body": "fix(server): reap orphaned child on stopServer's dead-wrapper branch (#63)\n\nstopServer's dead-wrapper branch (verifyIdentity fails — the recorded\nwrapper pid is gone/recycled) removed the discovery record but never\nsignaled the process group. Same orphan gap the supervision died-path\nreap closed: if\n[…]\nity). Half 2 (the\nzombie-leader tri-state guard) stays tracked in #63. Real wrapper+child\ntest: wrapper-only death, stop reaps the surviving child; 202 tests,\n10x isolation clean, negative-controlled.",
          "is_bot": false,
          "headline": "fix: reap orphaned child on stopServer's dead-wrapper branch (#63) (#66)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T23:38:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1fcd026685f81f770e5c7c0968c706bb2a4166b",
          "body": "docs: capture the reused-kill-helper fallback-audit learning (#62)\n\nNew best-practice doc from the died-path orphan-reap review: when reusing\na shared signaling/kill helper in a new caller, audit its fallback\nbehavior against the NEW caller's (often weaker) preconditions. signalGroup's\nbare-pid fall\n[…]\ne-leader edge as a follow-up (#63) rather than\nover-building.\n\nCross-linked into the stop→hung→died group-signaling lineage, with a\nreciprocal died-path-sibling pointer added to the stop-leak bug doc.",
          "is_bot": false,
          "headline": "docs: capture the reused-kill-helper fallback-audit learning (#65)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T23:25:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb5bc474f9f57f0247604cc3e9fe4b8722ce160c",
          "body": "* fix(server): reap orphaned daemon child on the supervision died path (#49)\n\nThe managed daemon is a harness wrapper + opencode child in one detached\nprocess group. The --foreground supervisor's died path exited fail-closed\nwhen the wrapper pid went away, but never signaled the group — so a\nwrapper\n[…]\ntion reap test (STUB_IGNORE_SIGTERM child\n  ignores SIGTERM), negative-controlled; annotate the died-path seam test\n  to document the reap wiring.\n\n201 tests, 10x isolation clean, no leaked processes.",
          "is_bot": false,
          "headline": "fix: reap orphaned daemon child on the supervision died path (#49) (#62)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T23:08:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40f3f9e61dd6991f0a2fedada31c1fea7b278a4d",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#58)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-10T21:44:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbb1059af040d379e5c450fc76b768d9675bb712",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update GitHub Actions (#51)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-10T21:41:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "209a3e03bdc2027379f7dcb34eb4327eb0552d27",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update bfra-me/.github to v4.16.35 (#53)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-10T21:38:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "679c449136d35527be3c45c07c2610f55fc7d287",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.15 (#55)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-10T21:29:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52105dce702d0c5ce908d3c15e86188f2f658b96",
          "body": "Two process/testing learnings from the foreground-supervision thread:\n\n- New best-practice doc: seam/mock-injected tests prove only promise-\n  level behavior; a claim about process-level behavior (exit latency,\n  timer/handle cleanup, signal handling) needs a negative-controlled\n  real-subprocess te\n[…]\nh. This standard supersedes the\n  narrower 'git show main:<path>' existence check — this session's flake\n  genuinely existed on main (~33% in isolation), which the existence\n  check would have missed.",
          "is_bot": false,
          "headline": "docs: capture review-gap learnings from #49 Layer B supervision (#61)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T21:25:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9b10b142405b58f62c49cd79de68bf8636036dc",
          "body": "* test(server): fix zombie-reap flake in SIGKILL-escalation test\n\nThe escalation test asserted isAlive(pid)===false instantly after\nstopServer returned. After the group SIGKILL, waitForGroupDeath\ncorrectly sees the group gone, but the specific child pid can briefly\nlinger as a reapable zombie (kill(\n[…]\nression),\nit just tolerates the microsecond reaping window. 25/25 in isolation.\n\nPre-existing flake, split from #49 Layer B per focused-PR discipline.\n\n* chore: empty changeset for test-only flake fix",
          "is_bot": false,
          "headline": "test: de-flake the SIGKILL-escalation test (zombie-reap race) (#60)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T20:57:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "869a003a9506dbb54f837d01759c58b2295d1321",
          "body": "…r B) (#59)\n\n* feat(cli): active --foreground supervision with fail-closed exit (#49 Layer B)\n\nspace-bus serve --foreground was a passive signal-waiter — it never\nchecked whether the managed daemon was still alive. A crash or host\nexit left the daemon gone, its discovery.json stale, and attachers\ndi\n[…]\nery cleaned' (may not hold\nunder EPERM on the hung path).\n\nAll prior signal tests injected a noop sleep, so none exercised a real\ntimer — this class of bug had zero coverage until the subprocess test.",
          "is_bot": false,
          "headline": "feat: active --foreground supervision with fail-closed exit (#49 Laye…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T20:46:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d85b7d373776642dc657c6367845fca57917c2c8",
          "body": "* fix(server): clean up stale discovery records on dead-pid reads (#49 Layer A)\n\nA managed daemon that dies by crash or host-process exit (not an\nexplicit stop) left discovery.json on disk pointing at a dead pid.\nEvery later resolver read that stale record and handed attachers a dead\nendpoint — the \n[…]\n Add the plan-required config.ts loadContext integration test: a stale\n  dead-pid record makes loadContext fail actionably AND removes the\n  file, proving the direct-attachLive caller path is cleaned.",
          "is_bot": false,
          "headline": "fix: clean up stale managed-daemon discovery records (#49 Layer A) (#57)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-10T17:28:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a94ef1550be4f6cd1755d6452ab53b0054ac2b32",
          "body": "The Library surface section listed only /core, /config, /contract, and\n/format, omitting two exports that already ship: /server (the Node-only\nmanaged-server lifecycle) and /attach (the browser-safe resolveManagedServer\nresolver added in 0.7.0). Add both, and include /attach in the browser-safe\nset to match what CI bundle-tests.",
          "is_bot": false,
          "headline": "docs: document /server and /attach subpath exports in README (#48)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-06T21:05:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce374f570fb55b11451b46397136e0c43d5aeb4d",
          "body": "…#47)\n\ndocs(solutions): capture the verify-claims-not-assertions orchestration lesson\n\nTwo misses this session, one meta-learning: the orchestrator acted on\nunverified claims and had to walk both back. A subagent called a\ngenuinely 1-in-3-flaky test 'pre-existing/unrelated' (a test added on\nthe bran\n[…]\nof checking the ground truth. Guidance: reproduce 'flaky', refute\n'pre-existing' with git, re-query PR/release state at each continuation\nboundary. Cross-links the empirical-claims and stop-leak docs.",
          "is_bot": false,
          "headline": "docs: capture the verify-claims-not-assertions orchestration lesson (…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-06T05:36:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd1c70fe4b457725906e0ccde728c9493b5acef5",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#45)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-06T05:11:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5dd75b9fd045d989156c4ffbbc92c10abed4ede9",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.83.1 (#41)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-06T04:42:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9338a6116ed9935d5a25774bfc055f24ce38276e",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update bfra-me/.github to v4.16.34 (#40)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-06T04:38:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3b901334980fe5dbf033e72972a6240812ceae6",
          "body": "docs(solutions): capture the managed-stop wrapper/child leak as a bug doc\n\nspace-bus stop signaled the harness WRAPPER pid and reported\nstopped:true while the opencode CHILD kept holding the port (a ~164MB\nuntracked orphan). Bug-track doc: symptoms, the wrapper/child process\ntopology root cause, the\n[…]\nal an unverified pid, and don't\naccept a flaky test (the zombie-reap race). Cross-links to the\nlifecycle best-practice doc (whose stop section now points back here)\nand the empirical-verification doc.",
          "is_bot": false,
          "headline": "docs: capture the managed-stop wrapper/child leak (#46)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-06T04:15:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b02aae760e5f4b97a749f4529c41935447b02d7",
          "body": "…naling) (#44)\n\n* fix(server): stop signals the process group so the wrapped server child dies\n\nharness/opencode serve is a thin node wrapper that spawns the real\nserver as a child holding the port; the managed lifecycle tracked and\nsignaled only the wrapper pid. stopServer SIGTERM'd the wrapper, sa\n[…]\n\nalready-gone are absorbed internally with a bare-pid fallback), so\nstopServer's catch never sees ESRCH — the old comment claiming an\nESRCH path reached it was stale. Comment-only; behavior unchanged.",
          "is_bot": false,
          "headline": "fix: managed-server stop leaked the opencode child (process-group sig…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-06T04:06:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "430e0f94b7dfabc0798fa4cd0bd61c8f27a93c47",
          "body": "…#43)\n\n* docs(solutions): capture four learnings from the managed-server + attach work\n\nFour best-practice/process learnings from this session, cross-linked:\n\n- managed-server-lifecycle-first-caller-spawns — the review-hardened\n  daemon supervision pattern (O_EXCL spawn lock, pid-identity kills,\n  t\n[…]\n\n'docs/solutions/best-practices/' while every existing doc uses the\nbare 'best-practices' — a mismatch that would make category-filtered\nlearning lookups silently miss them. Aligned to the convention.",
          "is_bot": false,
          "headline": "docs: compound four learnings from the managed-server + attach work (…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-06T02:56:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82d6e37ddff74fb8c33f8bca68bc64ae0f0cfaec",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#39)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-05T19:19:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f74fa32e83e18990ee3cff4240aab42ba1db6c",
          "body": "* feat(attach): browser-safe managed-server resolver (/attach subpath)\n\nExternal attachers (a Mothership webview) can resolve the managed\nserver's discovery file without any node:* imports: resolveManagedServer\n(workspaceDir, seams) reads the same on-disk discovery contract as\ndiscovery.ts through i\n[…]\ntics (leading slash preserved from the first part,\nslash runs collapsed, empty segments dropped). The discovery-path\nparity test against discovery.ts still passes; added 6 direct\nposixJoin unit tests.",
          "is_bot": false,
          "headline": "feat: browser-safe managed-server resolver (/attach) (#38)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-05T17:00:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "337a6a578ab3ad2c891f74ce11cef615cd75a039",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#36)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-05T13:37:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a456d734d5b21121047b26edf01dbac8e1c20ad",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.83.0 (#34)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T19:33:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f338abbc361193ba2e7d686ebecef44a238f6ed4",
          "body": "test: isolate XDG_STATE_HOME so the suite stops leaking real state dirs\n\nThe managed-server tests randomize roster paths but stateDirFor keys\noff XDG_STATE_HOME ?? ~/.local/state — so every run that wrote\ndiscovery/lock/provisional state hashed a fresh dir into the real home\n(791 accumulated in one \n[…]\nnever cleaned). A Bun test\npreload now forces XDG_STATE_HOME to a per-run temp dir and cleans it\nup on exit. Proof: real ~/.local/state/space-bus stays empty across a\nfull suite run. Test-only; patch.",
          "is_bot": false,
          "headline": "test: isolate XDG_STATE_HOME to stop state-dir leaks into $HOME (#35)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T19:02:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e98aff5eb843c290b67b70feba8854f660fa827",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#33)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T18:43:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6544439e3d2f0f929a4ff9d29ada199bb802ed5",
          "body": "* docs: managed-server brainstorm + plan\n\n* feat(discovery): roster schema split + discovery/lock/pid-identity primitives\n\nRoster server config becomes baseUrl XOR managed (existing rosters\nparse unchanged); new Node-only src/discovery.ts provides the\nstate-dir layout (keyed by roster-path hash), at\n[…]\n range,\nand rebuild the URL from a hardcoded 127.0.0.1 literal — no\nfile-derived string reaches the outbound request. The host was already\nregex-pinned; this closes the static-analysis taint path too.",
          "is_bot": false,
          "headline": "feat: managed bus server — lifecycle in the plugin (#32)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T18:41:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e17809f40db4078b932cbd0028158c393fb81a7",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#31)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T15:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dfd57c71555a4f30fac513a4c50f72b9b49fdbb",
          "body": "feat(deps)!: zod v4\n\nContract schemas are now zod-4 (looseObject replaces the deprecated\npassthrough — unknown-field semantics unchanged and test-pinned;\nz.url() replaces z.string().url()). MCP raw-shape registration rides\nthe SDK's native zod-4 path. Full lockfile regeneration was required:\nincremental install kept a stale nested zod@3 under the MCP SDK,\nbreaking tsc with AnySchema mismatches despite the SDK allowing ^4.",
          "is_bot": false,
          "headline": "feat: upgrade to zod v4 (#30)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T15:29:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "182ff452d4aaa81a1437b71160546a7906164550",
          "body": "docs(solutions): browser-safe library boundary cut pattern\n\nInjected-context validation (zod parse copies — validate-then-mutate\ncan't bypass), guards traveling from loader to consuming boundary,\nfilesystem facts as load-time flags, sentinel-pinned credential\nhygiene, and the Bun browser-target testing trap: builtins stub\nsilently and Node globals dodge import guards — safety tests count\nonly after negative controls prove they fire.",
          "is_bot": false,
          "headline": "docs(solutions): browser-safe boundary-cut pattern (#29)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T15:09:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe37b45a2d63585604a5f191b442db6aa0211012",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#28)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T15:03:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fda974ceb6f3491f5c159b25335dcd30ad1a327",
          "body": "* feat(tools): structured dispatch metadata on bus_task results\n\n{sessionId, project, mode} rides the plugin ToolResult metadata\nchannel and MCP structuredContent alongside the unchanged formatted\ntext, built by one shared helper so the surfaces can't drift.\nRenderers get the session id machine-read\n[…]\ndContent worked without it, but clients keying off\noutputSchema for discoverability couldn't see the fields; isError\npaths skip SDK validation so error returns stay schema-free.\n\n* style: biome format",
          "is_bot": false,
          "headline": "feat: structured dispatch metadata on bus_task (#27)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T15:00:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c175893587c66216233e709d916cba72fa659349",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#26)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T14:01:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83013cd67fa114451c97cdd1c25ff84dd83616ad",
          "body": "…) (#25)\n\n* feat(contract): extract OpenCode API schemas into src/contract.ts\n\nThe 19 zod schemas the bus maintains for the server API move to a\nzod-only module (experimental-labeled), preserving names, passthrough\nposture, and provenance comments; core imports from contract. First\ncut of the librar\n[…]\n: correct loadContext comments — no cwd fallback exists\n\nREADME example implied a current-directory default; mcp.ts gains the\nsingle-directory-per-process note so nobody 'fixes' it with\nprocess.cwd().",
          "is_bot": false,
          "headline": "feat: library surface — subpath exports, browser-safe core, snapshot(…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T13:57:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8de33f47dbe6874017ca25fc3c61278ded49f34",
          "body": "docs(plan): library-surface implementation plan (reviewed)\n\nFive units: contract extraction, core boundary cut (validated\nper-call context injection with parse-copy guard travel), snapshot\ncomposite, subpath packaging with a CI browser-safety probe (core/\ncontract/format bundle + config-isolation as\n[…]\nings integrated: single validation gate with copying parse,\nper-call context contract, fail-fast ordering pinned, smoke migrates\nlast, snapshot bypasses sequential probing, credential-scrubbed\nerrors.",
          "is_bot": false,
          "headline": "docs(plan): library-surface implementation plan (#24)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T10:19:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "885dbbf8518619e7ba9c8f4b7e7766bcf9240133",
          "body": "docs: ideation + reviewed requirements for the library surface\n\nIdeation pass (Mothership-support focus, 37 candidates, 5 survivors)\nand the brainstorm it seeded: subpath exports of a browser-safe core\n(roster + credentials injected, validated at the boundary), Node-side\nconfig module, bounded-concu\n[…]\nted:\nboundary validation + guard-travel requirements, R5 softened to\nwhere-practical migration, snapshot cap/error-sanitization rules,\nbyte-equivalence claim corrected, packaging follow-through named.",
          "is_bot": false,
          "headline": "docs: library-surface ideation + requirements (#23)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T10:04:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca3e2d9dcc27d3298c6d369f3c96262e4f322279",
          "body": "docs(solutions): template CI from the org's own repos, not adjacent ones\n\nWorkflow learning from the conversion's correction round: org-identity\nmarkers (renovate preset, review-bot inputs/pins, settings shape,\nnaming) must come from the org's own repos; outside templates only for\nwhat the org genuinely lacks. Convention drift passes every automated\ngate — the fix is sourcing discipline plus asking about provisioned\nsecrets instead of guessing.",
          "is_bot": false,
          "headline": "docs(solutions): org-template sourcing lesson (#22)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T03:29:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c414cf171fbaa187daf21eb8643e946402a24ebe",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#18)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T02:56:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83bdc757fc6ca73497b18ccda91f05086e433aee",
          "body": "useLiteralKeys off (bracket-notation env access is the repo\nconvention), noImportantStyles off for design-token assets, schema\nmigrated to the installed 2.5.2 (preset key). Zero diagnostics on a\nclean tree — lint output is now purely regression signal.",
          "is_bot": false,
          "headline": "chore(lint): signal-only biome output (#20)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T02:39:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "235deb53aabc68dee3237ae6cbc6d8569fcff438",
          "body": "Consumer-first section order (install → configure → tools → Claude\nDesktop → development), a field-by-field spacebus.json reference,\nthree badges, and the version-pin note generalized to lockstep-upgrade\nguidance.",
          "is_bot": false,
          "headline": "docs: shape the README for the npm listing (#19)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T01:08:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac6dc8f548e4d378ec367d3c98fd3219a93774e7",
          "body": "* refactor: shared toDispatchArgs validator; e2e version-injection test\n\nBoth adapters (MCP handler and plugin tool) narrow through one\nvalidator instead of casting past DispatchArgs' exclusivity —\nzero 'as DispatchArgs' remains. New test builds for real and asserts\ndist/mcp.js carries the shebang, \n[…]\nobservable error-precedence change. MCP handler\nfail-fast stays covered by the parity source-text guard — no stdio\nharness for one branch.\n\nVerified: typecheck clean; bun test 60/60; lint at baseline.",
          "is_bot": false,
          "headline": "refactor: shared dispatch-args validator + version-injection test (#17)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-04T00:46:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "991c9adb25155deab15b8e7a29ee512f607b1454",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#16)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-04T00:20:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfe5b4633a28e930d3298632986f23afc409d4ef",
          "body": "* chore: deferred-items sweep — real MCP version, stricter dispatch args\n\n- space-bus-mcp reports the package version (build-time define with a\n  'dev' fallback for direct-source runs) instead of a static 0.0.0\n- DispatchArgs is a discriminated union: bare {prompt} is a compile\n  error; project may \n[…]\nhe MVP build; the README and\nAGENTS.md now carry everything a contributor needs, and the planning\nhistory lives in docs/brainstorms and docs/plans.\n\n* chore: add changeset for the deferred-items sweep",
          "is_bot": false,
          "headline": "chore: deferred-items sweep (#15)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T22:33:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ef5a36fcc1dbc3746812e3044f81a9fbefdb766",
          "body": "…ngs (#14)\n\ndocs(solutions): npm trusted-publishing bootstrap + plugin scoping learnings\n\nTwo knowledge-track docs from the conversion: the new-package bootstrap\nconstraint (manual first publish before a trusted publisher can be\nconfigured; OIDC mechanics verified on the 0.1.0 release) and the\nOpenCode plugin registration/directory-scoping rules (tool map,\nctx.directory vs process.cwd(), lazy config, double-registration\nhazard — all probe-verified on the shared server).",
          "is_bot": false,
          "headline": "docs(solutions): trusted-publishing bootstrap + plugin scoping learni…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T21:12:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bf187ba68cb89510d56a35e9201416937db27c9",
          "body": "* docs: apply Fro Bot branding\n\nAdd branded social banner, styleguide, and design tokens; restyle README header with brand badges and banner while preserving all repo-specific content.\n\n- assets/banner.svg: parametric 1280x640 banner (title sized down to clear the avatar portal for the longer repo n\n[…]\n-bus\"\n- add <title> element to banner.svg for a11y (noSvgWithoutTitle)\n- format tokens.css quote style to satisfy biome\n\n---------\n\nCo-authored-by: fro-bot[bot] <fro-bot[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: apply Fro Bot branding (#12)",
          "author_name": "Fro Bot",
          "author_login": "fro-bot",
          "committed_at": "2026-07-03T20:52:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9696b44106a196416a35a2727a2a13439f0bcc8c",
          "body": null,
          "is_bot": false,
          "headline": "ci(renovate):enable automerge for fro-bot/agent in GitHub Actions (#13)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T20:43:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4d8f6cdd04c8b9e4990631605c9ef983075f917",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update fro-bot/agent to v0.82.0 (#10)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-03T20:34:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c0a65fa5d01208c254c8744570b804330baa572",
          "body": "docs(plan): plugin conversion complete — all seven units verified\n\nAE4 (operator workspace round-trip via file-path plugin), AE5 (0.1.0\npublished through CI trusted publishing with SLSA provenance), and AE6\n(npm-name resolution under harness, live round-trip) all passed.",
          "is_bot": false,
          "headline": "docs: mark plugin conversion plan complete (#11)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T20:26:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7fd8ae2dac7f2781d6ef16584c63669a5cf1968",
          "body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(🦋📦): version packages (#8)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-03T20:16:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e84b2562062684134c6513af0af83b93b9ad2d2e",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(dev): pin dependencies (#3)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-03T20:13:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc8129bf9eb6c27a0a26685de65626714385bacb",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update dependency npm to v11.18.0 (#5)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-03T20:03:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df3dc2d3c9a42757e078c99903523bcecb86a920",
          "body": "- Added 'Analyze' and 'CodeQL' to required status checks\n- Ensured stricter validation for branch merges",
          "is_bot": false,
          "headline": "feat: add required status checks for branches (#9)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T20:00:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdba36b7821bb3e8798d97c520d54253694b3f1c",
          "body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update GitHub Actions (#4)",
          "author_name": "fro-bot[bot]",
          "author_login": "fro-bot[bot]",
          "committed_at": "2026-07-03T19:50:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1744b88db2c474da07de770b88824cc6065bb815",
          "body": "feat(cutover): repo sheds control-board hosting — plugin is the only tool source\n\nThe operator workspace passed its live end-to-end gate through the\nplugin, so the transitional surfaces go: .opencode/tools wrappers,\nroot workspace.json/spacebus.json, and the MCP facade's repo-root\nfallback (SPACE_BU\n[…]\nnor).\n\nVerified: typecheck clean; bun test 51/51; lint clean; build OK;\nfixture-based smoke 11/11 PASS; MCP bin probe with and without\nSPACE_BUS_CONFIG (four tools / actionable error, protocol-clean).",
          "is_bot": false,
          "headline": "feat: complete the control-board cutover (#7)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T19:41:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78c85cb25658b29ed945e351b46c99b3ac61c0e3",
          "body": "…gin (#2)\n\n* feat(config): lazy per-call roster resolution from spacebus.json\n\nsrc/config.ts owns roster discovery: SPACE_BUS_CONFIG override (absolute\nor ~ only; URLs and bare-relative rejected; canonicalized) falling back\nto <directory>/spacebus.json, localhost guard and zod parse included.\ncore.t\n[…]\nity drift-guard asserting the plugin tool map matches the shared\ndescription constants and arg schemas (with a source-text check on the\nMCP registrations).\n\n51 tests, 0 fail; typecheck and lint clean.",
          "is_bot": false,
          "headline": "feat: convert space-bus into the distributable @fro.bot/space-bus plu…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T13:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad8eefe00c467ba342353d5bbd3d8cc6fbb61fc5",
          "body": "…trap\n\nExact copilot-delegate contracts inlined (release/ci workflow shapes,\nchangesets + package scripts, biome, renovate automerge guard, App-token\nrelease auth). Corrected Unit 7 against current npm docs: a trusted\npublisher can't be configured for a nonexistent package — first publish\nis a manual bootstrap, AE5 is satisfied by the second release. Fixed\nthe bin invocation (bunx --package=@fro.bot/space-bus space-bus-mcp).",
          "is_bot": false,
          "headline": "docs(plan): deepen with verified template contracts and publish boots…",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T06:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37b3fdd29779932aac945e39ed7be73324dc2623",
          "body": "Seven units: lazy roster resolution, plugin entry, packaging/build,\nCI workflow set, docs rewrite, reversible control-board cutover, first\npublish. Document review (coherence, feasibility, scope-guardian,\nadversarial, security-lens) findings integrated: no-caching roster\nreads, exact-path discovery, node build target, main-branch publish\ngate, fixture generation script, npm rollback + offline fallback.",
          "is_bot": false,
          "headline": "docs(plan): plugin conversion implementation plan (reviewed)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T06:20:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04e100f5c028805e1c7954531ce515d517e68ba2",
          "body": "Live probe on harness ee55e157: file-path plugin entries load and\nregister tools; per-session input.directory tracks the request's\nworkspace on a shared server (process.cwd() does not). The two P1\nunknowns from document review are settled empirically.",
          "is_bot": false,
          "headline": "docs(brainstorm): record verified plugin-loading probe results",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T06:06:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "293ccb760eb4320b0aaeaf392c0baad9b99a2b62",
          "body": null,
          "is_bot": false,
          "headline": "docs(brainstorm): plugin conversion requirements (reviewed)",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T06:01:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9c933834a3e136d116e37b95a9319219d415024",
          "body": "loadManifest rejects non-loopback baseUrl hosts at startup — Basic auth\nnever leaves the machine even if workspace.json is tampered with.\nfindSessionDirectory now errors when a session's directory matches no\nmanifest project instead of silently attributing it to the probing\nproject (wrong label + wrong directory header downstream).\n\nVerified: typecheck clean; smoke 11/11 PASS; negative probe with a\ntampered manifest fails fast naming the offending host; workspace.json\nrestored byte-identical.",
          "is_bot": false,
          "headline": "fix(security): localhost guard on baseUrl; refuse to guess session owner",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T05:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cc9166e2435db0179bd1e20b3c1c785b6646f09",
          "body": "- api(): never-throw choke point (synthetic 599 on network failure) +\n  30s AbortSignal timeout so a hung server fails fast\n- encodeURIComponent on all caller-supplied URL path segments\n- .opencode tools throw on core errors (plugin ToolResult has no\n  isError channel; thrown errors surface as tool \n[…]\nrrected\n\nVerified: typecheck clean; smoke 11/11 PASS; MCP stdio probe (four\ntools, isError path intact, stdout protocol-clean); dead-port probe\nconfirms status() degrades to ok:false without throwing.",
          "is_bot": false,
          "headline": "fix(review): apply validated safe-auto findings from review pass",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T05:36:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "64146a6d582b994af867cc5a407a5a16adefcb01",
          "body": "bus_task now takes optional sessionId: absent → new session (project\nrequired); present → steer the existing session (answer its pending\nquestion, else follow-up prompt), with a mismatch guard when a project\narg disagrees with the session's owner. One mechanism for start-vs-\ncontinue instead of two tools.\n\nVerified live: new dispatch, follow-up steer, question-reply steer, and\nmismatch guard; MCP tools/list shows exactly four; typecheck clean;\nsmoke PASS.",
          "is_bot": false,
          "headline": "refactor(bus): fold bus_reply into bus_task — four tools again",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T05:08:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b507b533786569373e46f51cf59323e1c856aa5",
          "body": "A delegate blocked on a question was indistinguishable from a working\none (busy: true either way) — dogfooding hit this twice. status() now\nchecks /question for the session and reports a preview + option labels;\nformatStatus renders a 'blocked: waiting on a question' line.\n\nVerified live: question-asking session shows blocked line with options,\nreply unblocks it and the field clears; typecheck clean; smoke PASS.",
          "is_bot": false,
          "headline": "feat(status): surface pending interactive questions in bus_status",
          "author_name": "Marcus R. Brown",
          "author_login": "marcusrbrown",
          "committed_at": "2026-07-03T05:04:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 21,
      "commits_last_year": 111,
      "latest_release_at": "2026-07-19T08:38:41Z",
      "latest_release_tag": "v0.15.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@fro.bot/space-bus",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@fro.bot/space-bus",
          "is_deprecated": false,
          "latest_version": "0.15.0",
          "repository_url": "https://github.com/fro-bot/space-bus",
          "versions_count": 22,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 4190,
          "first_published_at": "2026-07-03T19:44:51.948000Z",
          "latest_published_at": "2026-07-19T08:38:39.441000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 8
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 95488,
      "source_files_sampled": 54,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 6683
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 95,
        "malicious_count": 0,
        "assessed_package": "npm:@fro.bot/space-bus@0.15.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.29.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@changesets/cli",
            "direct": false,
            "version": "2.31.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opencode-ai/plugin",
            "direct": false,
            "version": "1.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 7,
        "direct_count": 2,
        "indirect_count": 5
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 92,
        "open_issues": 4,
        "closed_ratio": 0.846,
        "closed_issues": 22,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "marcusrbrown",
          "commits": 68,
          "avatar_url": "https://avatars.githubusercontent.com/u/831617?v=4"
        },
        {
          "type": "User",
          "login": "fro-bot",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/80104189?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.986
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yaml",
        "codeql-analysis.yaml",
        "fro-bot.yaml",
        "release.yaml",
        "renovate.yaml",
        "scorecard.yaml",
        "update-repo-settings.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7fa38ad1023c9adbca43fd05fb22add34ef0bc3b",
        "ran_at": "2026-07-25T05:37:32Z",
        "aggregate_score": 7.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T03:51:30Z",
      "oldest_open_prs": [
        {
          "number": 72,
          "created_at": "2026-07-11T10:03:40Z",
          "last_comment_at": "2026-07-11T10:03:45Z",
          "last_comment_author": "fro-bot"
        },
        {
          "number": 115,
          "created_at": "2026-07-19T17:34:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 116,
          "created_at": "2026-07-19T21:28:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 118,
          "created_at": "2026-07-20T18:31:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-19T08:37:20Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 6,
          "created_at": "2026-07-03T14:56:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 63,
          "created_at": "2026-07-10T23:04:27Z",
          "last_comment_at": "2026-07-10T23:05:55Z",
          "last_comment_author": "fro-bot"
        },
        {
          "number": 81,
          "created_at": "2026-07-11T22:09:48Z",
          "last_comment_at": "2026-07-11T22:11:38Z",
          "last_comment_author": "fro-bot"
        },
        {
          "number": 123,
          "created_at": "2026-07-25T01:46:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/fro-bot/space-bus",
    "host": "github.com",
    "name": "space-bus",
    "owner": "fro-bot"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 81,
        "vitality": 74,
        "community": 33,
        "governance": 59,
        "engineering": 86
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 111,
              "human_commit_share": 0.58,
              "days_since_last_push": 0,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "111 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 111
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 21,
              "latest_release_tag": "v0.15.0",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "21 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "packages": [
                "@fro.bot/space-bus"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4190
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,190 downloads/month across npm",
                "points": 48.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4190,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.986
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "merged_prs": 92,
              "open_issues": 4,
              "closed_issues": 22,
              "issue_closed_ratio": 0.846,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "85% of issues closed",
                "points": 39.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 85
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "92/93 decided PRs merged",
                "points": 37.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 92,
                      "decided": 93
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "fro-bot",
              "public_repos": 7,
              "account_age_days": 1967
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of fro-bot",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "fro-bot"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "7 public repos, account ~5 yr old",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 7
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@fro.bot/space-bus"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "22 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 22
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 86,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "agent-orchestration",
                "bun",
                "mcp",
                "opencode",
                "plugin",
                "typescript"
              ],
              "has_wiki": false,
              "homepage": "https://www.npmjs.com/package/@fro.bot/space-bus",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@fro.bot/space-bus",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 81,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 79,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 7.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@fro.bot/space-bus@0.15.0 runtime dependency closure — what installing the published package pulls in — 95 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@fro.bot/space-bus@0.15.0",
                  "assessed": 95
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 95,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 95,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 64,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 6683
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "58 of 58 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 58,
                      "sampled": 58
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 95488,
              "source_files_sampled": 54,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/54 source files over 60KB",
                "points": 54,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 54,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T05:37:49.504072Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/fro-bot/space-bus.svg",
  "full_name": "fro-bot/space-bus",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.