Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.26.0 · метрики 1.13.0 · 2026-07-22 19:06 UTC

globulario / sensei

Give your AI coding agent the project knowledge that lives only in your head — architectural invariants, failure modes, and intent, as a graph it consults before it edits.

GoAGPL-3.0★ 1 зірка⑂ 0 форківз лип. 2026 р.Переглянути на GitHub ↗

globulario/sensei має індекс здоров’я 53 зі 100, що відповідає смузі «Помірний». Найвищий показник — AI Readiness (82/100), найнижчий — Security (34/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

53
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

53
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

GlobularОрганізація
2 підписники15 публічних репозиторіївз жовт. 2020 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/globulario/senseiv1.3.0-91 день тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

69Помірний · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
1.4/36Ритм комітів — 2/52 тижнів із комітами
18/18Обсяг комітів — 388 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year388
human_commit_share0,91
days_since_last_push0
active_weeks_last_year2
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 6 релізів
36/36Свіжість релізів — останній реліз 1 дн. тому
27/27Ритм релізів — реліз кожні ~1,9 дн.
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Використані вхідні дані
releases_count6
latest_release_tagv1.3.0
releases_from_tagsні
days_since_latest_release1
mean_days_between_releases1,9

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

36У зоні ризику · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 1 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (AGPL-3.0)
18/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductні
has_pull_request_templateтак

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

48У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
15.6/46.8Вирішення issue — закрито 33% issue
26.7/38.3Прийняття PR — злито 67/96 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/17 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs67
open_issues2
closed_issues1
issue_closed_ratio0,333
closed_unmerged_prs29
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
3.4/25Охоплення власника — 2 підписників у globulario
20.2/25Послужний список — 15 публічних репозиторіїв, вік облікового запису ~5 р.
Використані вхідні дані
followers2
owner_typeOrganization
is_verified
owner_loginglobulario
public_repos15
account_age_days2 090

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 1 дн. тому
20/20Історія версій — 9 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/globulario/sensei
ecosystemsgo
any_deprecatedні
min_days_since_publish1

Інженерна якість

Чи наявні базові інженерні практики та документація?

71Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 8 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

34У зоні ризику · 16% загального індексу

Стан безпеки

34У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/17 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3,4
Виключено з оцінювання (немає даних або не застосовно): packaging. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

82Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — .cursor/rules/sensei.mdc, AGENTS.md, CLAUDE.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 90 з 91 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,989
agent_instruction_files.cursor/rules/sensei.mdc, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes4 395
Як обчислюється оцінка
18/18Розгортання однією командою — Makefile
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — editor/vscode/tsconfig.json
10/10Відтворюване середовище — Dockerfile, lockfile
10/10Підтверджена практика роботи з агентами — 57 з останніх 100 комітів створено агентом або з його зазначенням
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum, package-lock.json
has_dockerfileтак
typed_languageтак
bootstrap_filesMakefile
has_devcontainerні
has_linter_configні
typecheck_configseditor/vscode/tsconfig.json
agent_commit_share0,57
toolchain_manifestsexamples/orders-money-scar/go.mod, go.mod
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
54.6/55Керовані розміри файлів — 9/1 112 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes421 511
source_files_sampled1 112
oversized_source_files9
Як обчислюється оцінка
40/40Схема API (OpenAPI/GraphQL/proto) — editor/vscode/proto/awareness_graph.proto, proto/awareness_graph.proto
0/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalні
api_schema_fileseditor/vscode/proto/awareness_graph.proto, proto/awareness_graph.proto

Ключові факти

1зірок GitHub
1контриб'юторів
388комітів за останні 12 місяців
0днів від останнього пушу
6релізів
1бас-фактор
2відкритих issue
Goпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 3.4 / 10
3.4сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-22 19:06 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/17 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackagingpackaging workflow not detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Прямі залежності 11
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/emicklei/protov1.14.3go.mod
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogithub.com/scip-code/scip/bindings/go/scipv0.9.0go.mod
Gogithub.com/tree-sitter/go-tree-sitterv0.25.0go.mod
Gogithub.com/tree-sitter/tree-sitter-pythonv0.23.6go.mod
Gogithub.com/tree-sitter/tree-sitter-rustv0.23.2go.mod
Gogithub.com/tree-sitter/tree-sitter-typescriptv0.23.2go.mod
Gogolang.org/x/toolsv0.45.0go.mod
Gogoogle.golang.org/grpcv1.81.1go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 25844,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 9195412,
        "CSS": 45202,
        "Shell": 130907,
        "Python": 8081,
        "Makefile": 21136,
        "Dockerfile": 839,
        "JavaScript": 162130,
        "PowerShell": 3611,
        "TypeScript": 239333
      },
      "pushed_at": "2026-07-22T18:29:02Z",
      "created_at": "2026-07-10T16:37:13Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T05:10:06Z",
      "description": "Give your AI coding agent the project knowledge that lives only in your head — architectural invariants, failure modes, and intent, as a graph it consults before it edits.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://globular.io",
      "name": "Globular",
      "type": "Organization",
      "login": "globulario",
      "company": null,
      "location": "Canada",
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/73756200?v=4",
      "created_at": "2020-10-31T18:14:45Z",
      "is_verified": null,
      "public_repos": 15,
      "account_age_days": 2090
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-07-21T04:41:28Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-07-12T01:57:17Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:18:49Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2026-07-11T17:05:15Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T16:00:57Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-11T15:32:46Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9c2b6d83692d75e8f692b2231fd754456e633fc8",
          "body": null,
          "is_bot": false,
          "headline": "docs(architecture): define Sensei v2 direction",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T05:09:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d8aacd4ce829e099fd5df091f8ba08b6b19b9d8",
          "body": "Add the proportional-rigor command to the CLI reference (Gating group, with\nclasses A–D, the fail-closed laws, and an example) and the README command\noverview. Install instructions are already version-agnostic; the control-panel\npolish (actionable Unknown, distinct states, honest coverage) ships documented\nin the VS Code extension CHANGELOG.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: document `sensei rigor` (v1.3.0)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:47:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bd6643d85f7d6d4ca065b94896fee8347cbe84fb",
          "body": "Point the installer at the immutable v1.3.0 release asset and update the\nSHA256 (verified against the downloaded sensei-windows-amd64.zip and its\npublished sidecar). Version bumped across all three manifests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "winget: bump Globulario.Sensei to 1.3.0",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:42:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "332abf668ef4177757f347928cf5ab45402048a5",
          "body": "…t coverage\n\nSurface the issue #93 control-panel polish to marketplace users: a non-positive\ndimension now shows Known/Missing/Why/Next-evidence (owner-projected, rendered\nverbatim); unknown/unavailable/invalid/degraded/not_applicable each render\ndistinctly (glyph+text, never colour alone); and a compact grounding summary\nshows owner-defined coverage ratios with no fabricated denominators.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "vscode: extension v0.1.9 — actionable Unknown, distinct states, hones…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:30:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6451304a90bdaf1b624e01e4bc0d32f78f79ee0f",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T04:22:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ab3daa68d73bef49dcc7ca77bd39d070e453190",
          "body": "Phase 9 final polish — proportional rigor & actionable Unknown (closes #93)",
          "is_bot": false,
          "headline": "Merge pull request #94 from globulario/phase9-polish-actionable-unknown",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:21:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cfb1bd1d07c9bc3cf7fa77e98a9cea475f97b0d",
          "body": "…ble-unknown\n\n# Conflicts:\n#\tdocs/awareness/generated/awareness_graph_annotation_report.yaml\n#\tgolang/server/embeddata/awareness.transaction.tsv",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into phase9-polish-actiona…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:16:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef7c4a295d4e06bcc85e883c11131d19ee9ced5c",
          "body": "…ion points\n\nReviewer point 4 (rigor overlap): a file now owes the STRICTEST of every governed\nsurface whose prefix owns it, not the longest-prefix match — so a narrower but\nweaker surface can never trick classification into a lighter class than a broader\nstricter surface that also owns the file. Bo\n[…]\nistinct\n     from an unobserved numerator or denominator (unavailable).\n\nNo behavior change to the shipped manifest (it declares no overlapping prefixes);\nthis closes the gap before one is ever added.",
          "is_bot": false,
          "headline": "Phase 9 polish: harden rigor overlap + lock the four review-verificat…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:15:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13fd5f7fd0373b5b215c02e83a4521e4fb4cf5aa",
          "body": "Make proof rigor proportional to where the structural weight actually lives, so\nceremony stops landing uniformly. A new pure package golang/architecture/rigor\nclassifies a proposed CHANGE (never repository truth) by the GOVERNED SURFACES\nit touches — declared in docs/rigor_classes.yaml, bound to cod\n[…]\nnal rigor fails closed), their forbidden_fixes, and four required_tests.\nSeed + import-graph regenerated from the unioned corpus. No new RPC (16\ncontracts); certification and CP1–CP3 owners untouched.",
          "is_bot": false,
          "headline": "Phase 9 polish (2/2): proportional rigor (governed-surface classifier)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T04:09:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43e8b34d104c1ee1a131dcad5e943f824d8db24b",
          "body": "…erage\n\nMake Sensei's incompleteness legible without weakening any epistemic law. The\nverdict/state stays owner-decided; every addition is projection only.\n\nActionable incompleteness (§1): a new owner-projected DimensionExplanation\n(stable Kind + Known/Missing/WhyNotImprovable/NextEvidence) carried \n[…]\nnest explanation (Go + TS), explanation never\nchanges the owner verdict or severity, unknown never renders positive, and the\nno-denominator/zero-population coverage rules. Extension suite 90→95 green.",
          "is_bot": false,
          "headline": "Phase 9 polish (1/2): actionable Unknown, distinct states, honest cov…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T03:54:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3657e1afd7a89203c4afe26e99de306b8887b60b",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T03:20:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6e2a39d5e3d38e9aafa0a9ec92978b97e0ac409",
          "body": "Phase 9.7 CP3 — runtime-boundary truth travels the control panel (no doppelgänger)",
          "is_bot": false,
          "headline": "Merge pull request #92 from globulario/phase9.7-cp3-compose",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T03:18:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c12327a28300c51995ffd3ffde8dc81ef01c805",
          "body": "# Conflicts:\n#\tdocs/awareness/generated/awareness_graph_annotation_report.yaml\n#\tgolang/server/embeddata/awareness.transaction.tsv",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into phase9.7-cp3-compose",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:50:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8fc786397707786334c0a7eae3c48b5f0f2e23c",
          "body": "…oppelganger)\n\nCompose a runtimeboundary.RuntimeBoundaryAssessment into Sensei's Phase 9.5\ncontrol panel without any surface re-deriving runtime-boundary semantics.\nruntimeboundary stays the sole assessment owner; every other layer carries its\ntyped verdict verbatim.\n\nNew bridge `golang/architecture\n[…]\nforbidden_fix (recompute the verdict downstream), and two required_tests.\nSeed + import-graph regenerated from the unioned corpus.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Phase 9.7 CP3: runtime-boundary truth travels the control panel (no d…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:45:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a16e86b0535f263abb37f5e17058c55e130535d3",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T02:16:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f89e2a6a4695ad10d11826361537fab500cec295",
          "body": "Phase 9.7 CP2 — native probe witness (insufficiency proof)",
          "is_bot": false,
          "headline": "Merge pull request #91 from globulario/phase9.7-cp2-probe-witness",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:15:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd53a1cf33b15e128b38d107314b8f24923f522a",
          "body": "…tness\n\n# Conflicts:\n#\tdocs/awareness/generated/awareness_graph_annotation_report.yaml\n#\tgolang/server/embeddata/awareness.transaction.tsv",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into phase9.7-cp2-probe-wi…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:11:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92c4c673980f0b3dd69e425df4c614940f616024",
          "body": "…s provenance-only\n\nPre-review hardening against the four CP2 review questions:\n\nQ1 — the evidence-node anchor can never be mistaken for a contract or endpoint authority:\nthe observation no longer places EvidenceID in EndpointOrContractIdentity. All governed\ncrossing fields are now empty (caller/cal\n[…]\npty-everywhere, Q3 replay-inert, Q4\ncontested-retained). All green; gofmt clean; seed/import-graph fresh; CP1 untouched.\nRefs #88.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "harden(9.7/cp2): fully unresolve crossing identity; evidence anchor i…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:08:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "570148848a64fc915b88cb99b069c27d06ddc8b5",
          "body": "…path evidence ≠ crossing)\n\nPhase 9.7 Checkpoint 2 (issue #88): the bounded typed adapter that brings Sensei's own\nprobe/probeexec owner-path observations to the runtime-boundary court — and proves the\nkernel admits one real native witness and correctly rules it insufficient for a crossing.\n\nPlan-fi\n[…]\n certification. No CP1 change; no positive verdict from a probe.\nCorrectnessCertified unchanged; Phase 6 sole certifier. Refs #88.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(9.7/cp2): native probe witness — the insufficiency proof (owner-…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T02:00:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f12181f9dba615941421b97cfca920c14c79deb9",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T01:34:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "913b4d3242da33f9e33305930cd0fbda8b7dc1e5",
          "body": "Phase 9.7 CP1 — runtime-boundary assessment kernel (pure owner)",
          "is_bot": false,
          "headline": "Merge pull request #90 from globulario/phase9.7-cp1-runtime-boundary",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T01:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1ac479507f7e2922b5a17f703717e542ec9545c",
          "body": "…tale, unverifiable, and self-authorizing evidence\n\nPre-review hardening against the four CP1 review questions:\n\nQ4 — the assessment digest now binds the EXACT authority (identity digest), policy\n(policy digest), binding (binding digest), scope (repo/domain/boundary IRI), and\nevidence (admitted obse\n[…]\nauthorizing-observation-refused, digest-binds-policy/binding/evidence). All green;\ngofmt clean; seed/import-graph fresh. Refs #88.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "harden(9.7/cp1): bind policy/binding/evidence in the digest; reject s…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T01:30:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2e554b34f4939eba641cf6d9d64b41233cdc71f",
          "body": "…emetry-invents-architecture)\n\nPhase 9.7 Checkpoint 1 (issue #88): the pure, transport-neutral owner that assesses\nwhether a governed boundary was respected at runtime — without letting telemetry\ninvent or certify architecture.\n\nNew package golang/architecture/runtimeboundary (imports only stdlib + \n[…]\nitor, evidence ingestion, RDF emission, or mutation.\nCorrectnessCertified unchanged; Phase 6 remains the sole certifier. Refs #88.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(9.7/cp1): runtime-boundary assessment kernel (pure owner, no tel…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T01:20:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "981bef6179f0e66b29c00520cc372c68b42c0532",
          "body": "Reconcile Phase 9.5 (CP1–CP6) onto main + relicense AGPL-3.0",
          "is_bot": false,
          "headline": "Merge pull request #89 from globulario/integ/phase9.5-reconcile",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T00:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f15ab2bb0d048a5037752cd261fcc26ba885bc6",
          "body": "PR #86 was closed unmerged; its branch lived on a disjoint AGPL history that\nnever reached origin/main (which stayed Apache and merged frontier work in\nparallel). This grafts the Phase 9.5 control-panel work onto the real main,\npreserves main's frontier work, and relicenses the whole tree to AGPL-3.\n[…]\need/proto-contracts/\nimport-graph fresh, sensei check clean, reconciled server runs a gRPC round-trip.\n\nRetires the closed PR #86.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "reconcile: land Phase 9.5 (CP1–CP6) onto main + relicense AGPL-3.0-only",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-21T00:32:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41fb2207bf901252bf10c516984b9f4817f3b136",
          "body": "Frontier B — governed incident matching (`awareness_match_incident`)",
          "is_bot": false,
          "headline": "Merge pull request #84 from globulario/agent/awareness-match-incident",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T21:34:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8905ed032c92362550226b29b46e6c0adc3f2883",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T21:31:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81abae964c3d6206bb5ade03a3d55e2b6d56005f",
          "body": "…upplied diff\n\nDurable scar for the awareness_audit_diff v1 closure (#83): the read-only diff-audit projection must never invoke repository admission or read ambient working-tree state.",
          "is_bot": false,
          "headline": "Merge pull request #87: forbidden_fix — ambient admission vs caller-s…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T21:30:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04d2ce972378227ce7aeb041f0c68b25f499f341",
          "body": "…supplied diff\n\nDurable scar for the awareness_audit_diff v1 closure (PR #83): the read-only\ndiff-audit projection must never invoke repository admission or read ambient\nworking-tree state, because those are a different change subject and can produce\na verdict unrelated to the submitted evidence.\n\n-\n[…]\nne self seed + stamp (build-awareness-graph-self.sh):\n  +5 unique triples for the forbidden_fix. Self-seed drift --check is green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): record forbidden_fix — ambient admission vs caller-…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T21:22:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6f214644421bc1b41f00b2041766e1ad8f02ff8",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T21:14:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3923e28ddf18a1d436a4896fb55a3811fdb36ad2",
          "body": "…awareness_audit_diff)\n\nRead-only, non-authoritative projection over a caller-supplied diff; admission remains the separate verify_admission tool. Graph-commit identity bound into the result and enforced in both adapter and canonical evaluator. Phase 2 (typed FileObligation roles) deferred to a separate governed checkpoint.",
          "is_bot": false,
          "headline": "Merge pull request #83: Frontier A — governed multi-file diff audit (…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T21:14:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "386d293807fcd87000e4b7aaff7480c1331d146c",
          "body": "The adapter fails closed on a commitless authority, but EvaluateDiff still\ntrusted a successful checker response with an empty commit — yielding an\navailable/pass result unanchored to any rule snapshot. Put the lock on the\ncanonical door instead of every caller.\n\n- EvaluateDiff: a successful GetFile\n[…]\n returns a real commit and the test asserts it\n  reaches the result; a direct evaluator test proves empty commit -> cannot_verify.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(diffaudit): lock the graph-commit binding in the canonical evaluator",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T21:06:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93f4a93f142694b889b2864ddfe572357be12a66",
          "body": "The missing-commit guard was trapped inside `if expectedHead != \"\"`, so an\naudit with no pinned head could pass against an authoritative graph that\nexposes no source/build commit — and the result digest was not bound to the\nrule snapshot that produced it.\n\n- Require a non-empty graph commit as soon \n[…]\no the rule snapshot even when no head is pinned.\n- Test: add-file + omitted expected_head + missing graph commit -> cannot_verify.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(diffaudit): bind result identity to the graph commit unconditionally",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T20:57:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2a5d5aeabe37c4bb5dbe8a40e7ee9de8336db6f7",
          "body": "…plied diff\n\nHonor the governing contract (docs/design/frontier-awareness-audit-diff.md §2):\nawareness_audit_diff is a read-only, non-authoritative projection whose only\nchange subject is the caller-supplied diff. It must never impersonate\nrepository admission or read ambient working-tree state.\n\n- \n[…]\nm IRI-shaped\n  related_ids; whole-change companion checks stay dormant until the graph owner\n  returns typed file roles (Phase 2).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(diffaudit): make audit a read-only projection over the caller-sup…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T20:47:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab8a989a8b24d118e2934e70c97914340bee2512",
          "body": "…ompose admission.Verify, and monotonic-merge findings\n\nComplete the Checkpoint-2 refinements for awareness_audit_diff:\n\n- expected_head is now required and validated as a full hex SHA that\n  resolves to a real commit; the audit binds to a canonical snapshot\n  discovered via `git rev-parse --show-to\n[…]\n  a change-set block.\n- Domain/Task now flow onto AuditResult; tests updated for the new\n  testCurrentAuthority(commit) signature.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(diffaudit): require expected_head, bind graph authority commit, c…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T20:05:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "01bde2cc354166fa5c900bc7dd2f7762aae6de86",
          "body": "…y commit matching, whole-change composition checks, and safe validation recovery",
          "is_bot": false,
          "headline": "fix(diffaudit): enforce canonical repo root discovery, graph authorit…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:46:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a51be293a75156088e046f4c6849c7bb1572a00d",
          "body": "…k gate",
          "is_bot": false,
          "headline": "chore(awareness): register new meta principles to pass principle-chec…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:38:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23d9adfe8b7201077873b6d587bfd9a049a30332",
          "body": null,
          "is_bot": false,
          "headline": "merge: bring in latest master changes to resolve PR merge status",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:35:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ebf5d2ceb1ed78ac6c6df2538565b8066765725",
          "body": "… symlink escape checks, git show base snapshots, and validation checks",
          "is_bot": false,
          "headline": "fix(diffaudit): enforce strict hunk application, exact context match,…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:25:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15bdc2f1e75fa1656add61f5fd210397b5e302d5",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T19:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ef58845498f00ad49ae52059336d50b1fb1a497",
          "body": "Phase 9.6 - governed briefing-feedback leg",
          "is_bot": false,
          "headline": "Merge pull request #82: Phase 9.6 — governed briefing-feedback leg",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:21:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0a6161e2520d39bec429ef6d50b3ec40bd21adc",
          "body": "… SHA hex validation, and fresh import-graph",
          "is_bot": false,
          "headline": "fix(diffaudit): connect production BaseFileReader, add line matching,…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:18:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd7ecfffa470a51501635c15e1412cd1e64bd70b",
          "body": "- vendored VS Code proto matches the canonical proto byte-for-byte; the feedback\n  wire schema exposes no filesystem-root field (adds to the existing additive\n  field-7 + explicit-enum-mapping proofs).\n- static (AST/import) ownership boundary: golang/server consumes briefingfeedback\n  and NOT questi\n[…]\npromotion journals/receipts directly; VerifyCommittedPromotion stays owned\n  by questionpromotion, invoked through the canonical feedback owner.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: Checkpoint-3 wire-compat + static ownership-boundary proofs",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af970264a866b84d3aced09621496d3fb06979ca",
          "body": "…proofs\n\nClosure proofs over a real committed promotion:\n- consumer parity: owner ≡ server-style ≡ task-style projection fingerprints for\n  the same verified scope, differing only in consumer-binding task id/session/digest;\n- task file-set expansion changes results only via the verified broader file\n[…]\ncalls;\n- end-to-end RPC parity: field 7, prose, referenced ids, and status describe one\n  feedback world (EMPTY base + available feedback = OK).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(server): Checkpoint-3 parity, privacy, no-mutation, determinism …",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c372f86a3956d13945e9ab5fa903f3899662b47",
          "body": "…ning\n\nThree bounded hardenings:\n\n1. ValidateProjection enforces an exact unavailable/invalid identity matrix: only\n   the repository_context_absent carrier (no records, no task/session, exactly one\n   promotion_discovery_unavailable/unavailable finding) may blank an unavailable\n   projection's repo\n[…]\ner set at construction) instead of a mutable package global —\n   race-safe under parallel tests; production always uses briefingFeedbackToProto.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(briefingfeedback): Checkpoint-3 validation + canonical-path harde…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b92b140dd05f1c331a233e016fab7467a98ea7d",
          "body": "…e record\n\nAdd design §18 (Checkpoint 3): the final Phase 9.6 guarantee; the frozen closure\nlaws (single semantic owner, consumer parity, projection atomicity, explicit\nabsence, non-authority); the bounded-hardening description; the adversarial proof\nledger mapping every §13 matrix item (1–34) to an\n[…]\nion: update the 9.6 failure-mode evidence from govern-first\nto completed-implementation + tested, citing the production packages and the\nledger.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.6): Checkpoint-3 closure laws, adversarial ledger, closur…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef5eac01368823dcdf01468652ea2ccabd3ff6a7",
          "body": "…on, companion file obligations, and strict MCP validation",
          "is_bot": false,
          "headline": "fix(diffaudit): complete PR #83 repair with base content reconstructi…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2ab206a8f02bd08e890ecb49b56ce254a914268",
          "body": "…er precision and decision availability",
          "is_bot": false,
          "headline": "fix(diffaudit): address PR #83 architectural review feedback for pars…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:09:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "affc54e81e9a6fbf1de42e4afaa966c1517e83de",
          "body": "…audit_diff)",
          "is_bot": false,
          "headline": "feat(diffaudit): implement governed multi-file diff audit (awareness_…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T19:01:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88c763ee2c7b7818d0507e4d2a1f526568356d16",
          "body": null,
          "is_bot": false,
          "headline": "docs: open governed incident matching frontier",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:55:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3fbafb0109b7024f9888cea4d567d1863a8e13c",
          "body": null,
          "is_bot": false,
          "headline": "docs: open governed multi-file diff audit frontier",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:54:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdff72f740483fd84354558ed16a7a02a42a8943",
          "body": "…e, raw identity, atomic pair)\n\nClose three bounded Checkpoint-2 gaps without redesigning the accepted owner or\nwire schema.\n\n1. Unconfigured server emits EXPLICIT typed feedback. Remove the unconfigured\n   early-omission from resolveBriefingFeedback: an unconfigured server now\n   consumes the canon\n[…]\n + gRPC\ninternal); BuildInvalid reasons + no-raw-identity-leak. All existing configured\ntests green. Phase 9.4 / CorrectnessCertified untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(server): close Checkpoint-2 integration gaps (explicit unavailabl…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:49:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9707b890afb00db02d9f8b2955c9a07dae146eaf",
          "body": "Mechanically regenerated artifacts only (no hand edits):\n- import graph: the server package now depends on briefingfeedback (make import-graph).\n- self-seed: the Checkpoint-2 govern-first invariants/failure-modes/forbidden-fixes are\n  awareness-graph-owned triples; rebuild embeddata/awareness.nt + t\n[…]\nCI seed-freshness gate passes (scripts/build-awareness-graph-self.sh).\n- annotation report + code symbols/edges: regenerated alongside the seed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): regenerate import graph + self-seed for 9.6 ckpt 2",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:23:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6fad0dcc09bca27c95139de343421bb86b7a18ec",
          "body": "Wire the canonical briefing.feedback_projection/v1 into the server Briefing RPC\nas a thin consumer.\n\n- briefingFeedback(scope): selects exactly one path — repository context absent →\n  repository_context_absent; task-only (task text is not canonical task identity) →\n  canonical_task_scope_not_establ\n[…]\nerified promotion → structured\nrecord + exact provenance + governed referenced id + prose parity + digest preserved + no\nanswer-text/root leak).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(server): integrate governed briefing feedback into the Briefing RPC",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:20:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7ba0175af2ef1b1393e20b8c9ddf665ab40bab34",
          "body": "Add the immutable startup-owned repository context (root + domain) that\nidentifies the ONE filesystem repository whose committed promotions the server\nmay verify for briefing feedback.\n\n- server: briefingRepositoryContext{Root,Domain} + establishBriefingRepositoryContext,\n  a strict validator for th\n[…]\nlink-resolves-once for the strict server validator and the wrapper resolver, plus a\nproof that BriefingRequest carries no filesystem-root field.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(server): startup-owned briefing repository context",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T18:01:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9946fc09c43c6fb7626aee4ac41ef92574e075b",
          "body": "Extend BriefingResponse with an ADDITIVE field 7 (feedback) carrying the\ncanonical briefing.feedback_projection/v1 mirrored as closed typed wire\nmessages/enums — no existing field renumbered, clients ignoring field 7 keep\nworking. New messages: BriefingFeedbackProjection / VerifiedRecord / Finding;\n\n[…]\nhanged +\nfield 7, exhaustive explicit enum mapping, unknown-fails, digest preservation,\nno-root-leak, and refusal of a non-canonical projection.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proto): additive briefing-feedback wire contract + pure adapter",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T17:56:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1240e485c61453393badeb0bf03b2e60f505d7b3",
          "body": "Add BuildUnavailable(scope, reason): the narrow canonical owner operation that\nproduces a valid, deterministic feedback_unavailable projection for a typed\nUnavailableReason {repository_context_absent, repository_context_domain_mismatch,\ncanonical_task_scope_not_established, feedback_projection_inter\n[…]\nository identity that could not be established; only an ESTABLISHED projection\n(available/empty/degraded) requires a present canonical identity.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(briefingfeedback): canonical unavailable-projection constructor",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T17:51:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7df312ad60a63e8a13bd992c3e9b88495c98baad",
          "body": "Freeze the Checkpoint-2 design rulings (design §17): §17.1 server\nrepository-context identity (one immutable startup-owned repo-root + repo-domain\npair, never caller-selected or cwd-inferred; homeDomain is not repository\nidentity), §17.2 task-only honesty (natural-language task text is never\ncanonic\n[…]\non-authoritative), not \"authoritative\" — no runtime change.\n\nNo implementation in this commit. Phase 9.5 locked; CorrectnessCertified\nuntouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.6): freeze Checkpoint-2 rulings + govern-first records",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T17:51:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "53b7a71f97bc11537ac7de1fda0e2a35b35b405f",
          "body": "…ct, validation)\n\nRepair four bounded gaps in the accepted Phase 9.6 Checkpoint-1 owner without\nredesigning it. No server/protobuf/RPC/editor/GitHub/certification/completion\nwiring; CorrectnessCertified untouched.\n\n1. Cross-task relevance ruling frozen (design §16.3): a governed promotion is\n   reus\n[…]\nxisting briefing\ncompatibility tests updated for the canonical task identity and the honest\nfacility reclassification of shared-graph tampering.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(briefingfeedback): close Checkpoint-1 review gaps (identity, impa…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T17:26:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7c3f56d909390dbaa4fc37d961cc14be7378083",
          "body": "Mechanically regenerated artifacts only (no hand edits):\n- import graph: the new briefingfeedback package and tasksession's dependency\n  on it change the Go import graph (make import-graph).\n- self-seed: the Checkpoint-1 govern-first invariant, failure_mode, and two\n  forbidden_fixes authored earlie\n[…]\n  the CI seed-freshness gate passes (scripts/build-awareness-graph-self.sh).\n- annotation report + code symbols: regenerated alongside the seed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): regenerate import graph and self-seed for 9.6 ckpt 1",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T16:43:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "08133e7882528306a0c3d9257ce5f9482d809bdf",
          "body": "Migrate task-briefing promoted-knowledge collection onto the canonical\nbriefingfeedback owner, removing the semantic duplication of promotion\ndiscovery, verification, and scope filtering from tasksession.\n\ncollectPromotedKnowledge is now a thin adapter: it builds the owner's\ndeterministic feedback p\n[…]\nomain exclusion) continue to hold\nunder normal, -shuffle, and -race ordering. The deleted promotionInScope is\nsubsumed by the owner's admit law.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(tasksession): consume the canonical briefing-feedback owner",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T16:35:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d0774ac2d68f98fb1dc65801ef806fab9dc21355",
          "body": "Introduce golang/architecture/briefingfeedback, the SOLE canonical,\ndeterministic, read-only owner of the governed briefing-feedback projection\n(Phase 9.6 Checkpoint 1). It discovers committed promotions through the\nquestionpromotion boundary, admits a governed record only after\nVerifyCommittedPromo\n[…]\ndebris isolation,\ncontradiction semantics, determinism/digest, path parity, and the privacy\nboundary under normal, -shuffle, and -race ordering.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(briefingfeedback): canonical read-only governed-feedback owner",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T16:31:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "127905896ed550b432d1c5e1046da704145e3737",
          "body": "… candidate descriptor (9.6 ckpt 1)\n\nAdds the smallest typed boundary Phase 9.6 needs so briefingfeedback classifies promotion\nverification WITHOUT parsing error text, and routes relevance from untrusted metadata.\n\n- VerificationError{Class, ReasonCode, Cause} + closed VerificationFailureClass {inco\n[…]\nefect). Only VerifyCommittedPromotion establishes verified scope.\n\nNo feedback-specific policy added to questionpromotion; existing tests green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(questionpromotion): typed verification-failure class + untrusted…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T15:43:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d7490457d52eef64aae63ca4f203677f62ec91a",
          "body": "…rst records\n\nFreezes the two review rulings in docs/design/phase9.6-briefing-feedback.md: (16.1) the\nfuture server repository context is a startup-owned, immutable, never-caller-supplied\n--repo-root, absent → feedback_unavailable (implemented in Checkpoint 2); (16.2) empty\nrequested domain is not m\n[…]\noduction symbols + tests as the implementation lands in the following commits.\n\nGovern-first only — no implementation code. sensei check passes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.6): freeze checkpoint-1 review rulings + author govern-fi…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T15:27:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad2374a909ab557e55d4185e562888b4af447f1b",
          "body": "Opens Phase 9.6 BEFORE 9.5 — the briefing-feedback projection is an upstream semantic\nservice the later VS Code cockpit must consume, not reinterpret. Design contract only:\nNO production code, protobuf, server wiring, governed YAML, generated artifacts, or tests.\n\ndocs/design/phase9.6-briefing-feedb\n[…]\nthor\nat Checkpoint 1.\n\nDesign artifact only. Checkpoint 1 does not begin until reviewed. Phase 9.5 stays locked;\nCorrectnessCertified untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.6): open the governed briefing-feedback leg (design only)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T15:15:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "befa1d5e0ddc341709434fa75c9be185ad4a9f6b",
          "body": "Phase 9.4c — authoritative change-to-task binding (opening, design-first)",
          "is_bot": false,
          "headline": "Merge pull request #81 from globulario/phase9.4c-change-task-binding",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T14:58:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a015862ba40ce9ff1a84aff9327556cf5b659e7c",
          "body": "…ckpoint-3 composition\n\nThe new changebindingconsumer package, the compose runner, and the two 9.4c-ckpt3\ngoverning records change the self-seed, Go import graph, and derived annotation/symbol\nreports. Regenerate mechanically. Freshness + `sensei check` pass.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): rebuild seed + generated artifacts for the 9.4c che…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T14:51:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d254e1656600cedacdcf5e63a4173ba7268ad3a8",
          "body": "…4b decision (9.4c ckpt 3)\n\nPhase 9.4c Checkpoint 3 — the final Phase-9.4 implementation. An authoritative\ncompletion.change_task_binding/v1 is validated IN FRONT of the unchanged 9.4b completion\ndecision, proving the completion result belongs to the current repository, GitHub change,\nexact base/hea\n[…]\n a future Phase-6 certification could consider, not the certifier. No 9.4b decision\nchange, no new degraded path, no CorrectnessCertified write.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(changebindingconsumer): compose binding validation before the 9.…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T14:51:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "633e17116b63e14c57963ab0b00d42679eeb6e42",
          "body": "…ckpoint-2 producer\n\nThe new changebindingproducer package, the produce-change-binding command, and the two\n9.4c-ckpt2 governing records change the self-seed, Go import graph, and derived\nannotation/symbol reports. Regenerate mechanically. Freshness + `sensei check` pass.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): rebuild seed + generated artifacts for the 9.4c che…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T14:21:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a75c1ceb767a6c120aa8d54044638a534027c890",
          "body": "…iring + audit (9.4c ckpt 2)\n\nPhase 9.4c Checkpoint 2: the authoritative GitHub-side producer for\ncompletion.change_task_binding/v1. It constructs, self-validates, publishes, and audits a\nbinding; it does NOT consume the binding for enforcement (Checkpoint 3) and never touches\nthe 9.4b decision.\n\nNe\n[…]\nal-not-authoritative. -race/-shuffle clean; full\nrepo suite green; sensei check passes. No 9.4b decision change; CorrectnessCertified\nuntouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(changebindingproducer): authoritative GitHub producer + Action w…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T14:21:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "66be87864a39aaeac0b902e84e8fd77fd79362b9",
          "body": "…ckpoint-1 governance\n\nThe new changebinding package and the three 9.4c governing records + required_tests\nentries change the self-seed, the Go import graph, and the derived annotation/symbol\nreports. Regenerate mechanically. Freshness checks and `sensei check` pass.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): rebuild seed + generated artifacts for the 9.4c che…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:53:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f6324ac78aac5892a970eeef9eaa6b3948a5b3d3",
          "body": "…igest, strict parser, pure validator (9.4c ckpt 1)\n\nPhase 9.4c Checkpoint 1: the typed completion.change_task_binding/v1 identity object and\nits pure validation machinery. No producer, no Action, no CLI, no enforcement wiring; the\npackage reads no Git/filesystem/env/event/--task-dir/ambient state.\n\n[…]\nno --task-dir change, no 9.4b decision change, CorrectnessCertified\nuntouched. Full repo suite green; -race/-shuffle clean; sensei check passes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(changebinding): typed change_task_binding/v1 schema, canonical d…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:52:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f04a9cfa3bdeaffe3e2c38ef485fc106163df7c7",
          "body": "…(design only)\n\nOpens 9.4c on top of the closed 9.4a/9.4b. Design contract only — NO binding,\nvalidator, Action, or enforcement code.\n\ndocs/design/phase9.4c-change-task-binding.md operationalizes the frozen\ncompletion.change_task_binding/v1 forward-declaration: the typed binding fields\n(repository/c\n[…]\neze at Checkpoint 1.\n\nDesign artifact only. Checkpoint 1 does not begin until this opening contract is\nreviewed. CorrectnessCertified untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.4c): open the authoritative change-to-task binding slice …",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:30:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "130d07a9a0f99e853d5603feeb7c4a06a612474a",
          "body": "Phase 9.4b — completion gate: enforce + three outcome classes + policy opt-in (opening)",
          "is_bot": false,
          "headline": "Merge pull request #80 from globulario/phase9.4b-completion-enforce",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:29:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84aca89fc660cfa4e13d62603f5a9d56e93f28cc",
          "body": "…ckpoint-3 governance\n\nThe three new required_tests.yaml entries and the new completion sources change the\nself-seed, the Go import graph, and the derived annotation/symbol reports. Regenerate\nthem mechanically. Freshness checks (import-graph-check, self-seed --check) pass;\n`sensei check` valid.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): rebuild seed + generated artifacts for the 9.4b che…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:20:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "263597b78414a83328bf84b26c4d7e257ea415c3",
          "body": "…rsarial proofs (9.4b ckpt 3)\n\nCompletes 9.4b. Runtime (degraded-pass) classification now requires POSITIVE evidence\nthat owner invocation was attempted after a valid identity — it is no longer the\n\"not an identity error\" catch-all.\n\nStructural change (completion owner):\n- New typed ProjectionRuntim\n[…]\nproofs.\n\nAdvisory path, --task-dir identity source, and CorrectnessCertified untouched. Full\nrepo suite green; -race clean; sensei check passes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gate): harden runtime classification to positive evidence + adve…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T13:20:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3e1fc1dac838238da4204971ef6b723524c999a1",
          "body": "…ision\n\nThe new completion ownererror.go and cmd/awg decision/enforce sources change the\ninferred Go import graph. Regenerate so `make import-graph-check` is fresh. Self-seed\nreports owned triples current — no seed rebuild.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): regenerate Go import graph for the 9.4b enforce dec…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T12:53:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dc2b589d1b76546f920e5c559e501ebc75095da4",
          "body": "…e split (9.4b ckpt 2)\n\nMakes completion enforcement operational for explicitly opted-in domains while\npreserving advisory behavior everywhere else, and splits the ambiguous\nprojection-owner failure into typed identity vs runtime causes classified at origin.\n\nCause split (completion owner):\n- valida\n[…]\nepo identity→block, invalid policy→exit 2). cmd/awg,\ncompletion, and the full repo suite are green; -race clean. CorrectnessCertified\nuntouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gate): completion enforce decision + typed identity/runtime caus…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T12:53:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3fae833ad9dc06aca56a2470a6c86b89fe5c1804",
          "body": "…y loader\n\ncmd/awg's new completion_policy.go changes the inferred Go import graph. Regenerate\nthe generated artifact so `make import-graph-check` is fresh. Self-seed reports owned\ntriples current — no seed rebuild.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): regenerate Go import graph for the completion-polic…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:28:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b37ca491af9ada2dfbeb02109b4bf7452ead3ba0",
          "body": "The separate completion-policy configuration surface: a domain opts into completion\nenforcement through an explicit `completion:` section of .sensei/gate-policy.yaml,\nkept fully independent of the EditCheck `Rules` map. This checkpoint provides ONLY\nthe schema, loader, validation, and its typed resu\n[…]\n, and the\nadversarial require_completion-in-Rules fixture. `cmd_gate.go` is untouched. Full\ncmd/awg suite green. CorrectnessCertified untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gate): completion-policy schema + loader (Phase 9.4b checkpoint 1)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:26:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ae24476de2cd844750f9b5f6c912940796a2713",
          "body": "…ation plan\n\nOpens 9.4b (enforce + the three outcome classes + policy opt-in), now that 9.4a\nis merged. This operationalizes the already-frozen 9.4b definition and locked\ncompletion-policy semantics from phase9.4-contract.md into a concrete, reviewable\nplan: the enforce decision table, the identity-\n[…]\nts.\n\nDesign artifact only — no enforce code. 9.4c (change-to-task binding, action\nwiring, audit) stays locked. CorrectnessCertified stays false.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.4b): open the completion-enforce slice with its implement…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:11:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f84f93376e23a8a229fb2abdde2447f216c4ee84",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T05:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "871e41011de7222150282d8431ca270bcc6110e0",
          "body": "Phase 9.4a — advisory completion gate",
          "is_bot": false,
          "headline": "Merge pull request #78 from globulario/phase9.4a-completion-gate",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:07:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53e3b7bdd4ade1250b87d0da79c94441db91316a",
          "body": "Regenerated golang/server/embeddata/{awareness.nt,awareness.transaction.tsv} and the awareness-graph-owned docs/awareness/generated/ YAML from the authored corpus after a merge to master (GC-2). The stamp is committed WITH the seed (it certifies the digest); the commit is gated on build + embedded-seed integrity tests. No [skip ci] — the change is integrity-checked in-workflow before it lands.",
          "is_bot": true,
          "headline": "chore(awareness): auto-rebuild seed + stamp from authored corpus",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T05:02:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5dd64b8a35492241af50d58a1ef978166ad6a33e",
          "body": "…gate",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into phase9.4a-completion-…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:02:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcb6a2b61fb2a337aea10bf580871547f88925ff",
          "body": "…d-work\n\nfix(ledger): bounded verification repair + completion shared fixtures",
          "is_bot": false,
          "headline": "Merge pull request #79 from globulario/fix/ledger-verification-bounde…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T05:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "544c3bacfda9945c3eab79ff3246146eed800d34",
          "body": "…changes\n\nThe bounded ledger-verification repair added golang/architecture/ledger/verifyscope.go\nand new context imports across the ledger/admission/completion packages, which\nalters the inferred Go import graph. Regenerate the generated artifact so\n`make import-graph-check` is fresh. No hand-authored source changes; the self-seed\nfreshness check already reports owned triples current (no seed rebuild needed).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(awareness): regenerate Go import graph for the ledger verifier …",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T04:49:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d1e46f0266ce23732eb8afb6b8ed7ec4128231e7",
          "body": "The completion suite's dominant cost is not ledger verification (bounded in\nthe previous commit) but repeatedly reconstructing expensive governed worlds:\neach downstream test ran the full closure lifecycle (seed -> result transition\n-> dispose/promote/resolve -> certify -> optionally complete) just \n[…]\n(supporting evidence): the completion package drops from ~52s to\n~18s. No production semantics changed; this commit is test infrastructure only.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(completion): build canonical worlds once and clone per test",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T04:44:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0d6c24bc1e4cc84d2b5098f5a45c436823108e6",
          "body": "…oped digest memo\n\nLedger chain verification re-parses and semantically digests every payload on\nevery verification, and the completion read side re-verified the same immutable\nchain repeatedly — most acutely LoadRecordedAuthority, which verified the chain\nfive times (once per artifact). This bounds\n[…]\neline world construction\nis. That is addressed separately in the next commit. No global cache, no timeout\nchange, no test-fixture redesign here.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(ledger): bound redundant verification work with an evaluation-sc…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T04:22:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c2b116424d6c33a3b3b050ffc7628e4bf792368e",
          "body": "Applies the four blocking corrections plus the proof-strengthening the\narchitect required before 9.4a acceptance:\n\n1. Import graph — regenerate docs/awareness/generated/awareness_graph_go_import_graph.yaml\n   for the new cmd_gate_completion.go source so `make import-graph-check`\n   and the self-seed\n[…]\nrcement,\npolicy, the change-to-task binding, the CI action, and audit emission\nremain locked to Phase 9.4b/9.4c. CorrectnessCertified untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gate): correct the advisory completion gate (Phase 9.4a review)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T03:04:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2c3f523a9bc521cebdf3342906cf0023f90a02e",
          "body": "Phase 9.4a — the first, advisory-only slice of the CI/GitHub completion gate.\n`sensei gate --completion --task-dir <d>` consumes the canonical typed availability\nenvelope (completion.BuildCompletionProjectionEnvelope), validates its canonical\npublication form, and reports the availability, the closu\n[…]\ny\nclosure.completion_gate_fails_open_on_unavailability_and_closed_on_a_computed_verdict;\ncmd/awg is already high-risk covered; no governed YAML.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gate): add the advisory completion gate (Phase 9.4a)",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T02:43:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e7d55598d1c0f2291b2f86d34a316d5ea19cf6e",
          "body": "Phase 9.4 (contract) — governed CI/GitHub completion-gate opening contract",
          "is_bot": false,
          "headline": "Merge pull request #77 from globulario/phase9.4-contract",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T01:52:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed729b2d156bb621bcc7847cd8cca6c9cd0bf738",
          "body": "…he gate contract\n\nAddress the PR #77 review (five corrections), still design + governance only:\n\n1. Separate runtime unavailability from required-identity failure — three outcome\n   classes: identity-invalid (fail closed under enforce, never a degraded pass),\n   runtime-unavailable after identity (\n[…]\n_task_binding (repository / PR /\n   head-sha / one-task verification; no identity-by-convenience inference).\n\nRegenerates the self-seed + stamp.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(phase9.4): close the identity-bypass and typed-envelope gaps in t…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T01:47:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fced5d41b063eb8a9fe5973ee0ebaaad27916d55",
          "body": "…-gate contract\n\nOpening contract for Phase 9.4 (the CI/GitHub completion gate) — design +\ngovernance only, no gate logic. docs/design/phase9.4-contract.md records: the\ngrounding (the gate infrastructure already exists — sensei gate, the sensei-gate\naction, runtime-gate as the fail-closed-typed-verd\n[…]\n\nenforce-without-opt-in), asserted by phase9_contract_test.go. Regenerates the\nself-seed + stamp. No implementation; slices 9.5/9.6 stay locked.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(phase9.4): open Phase 9.4 with its governed CI/GitHub completion…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T01:30:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84cfc3839a1102a27a3f782c649529a5b6b57f34",
          "body": "…n-principles\n\nReapply the three architectural truth-preservation meta-principles (supersedes #69)",
          "is_bot": false,
          "headline": "Merge pull request #76 from globulario/meta/reapply-truth-preservatio…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T01:11:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebd06ba6866573e1e13eda406fb4cd21099cba07",
          "body": "…ples\n\nRe-authors, on a clean branch from the integrated Phase-9.3 main, ONLY the three\nmeta-principles from PR #69 (which carried incorrect ancestry as a giant PR),\nwithout its 199-commit history:\n\n- meta.existence_checks_must_not_substitute_for_cardinality_proofs\n- meta.omission_is_an_invisible_st\n[…]\nh conceptual anti-pattern\ncitations are already baselined; these are abstract shapes, not concrete repo\nforbidden_fix records).\n\nSupersedes #69.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(meta): reapply the three architectural truth-preservation princi…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T01:03:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e796c03c8bfea7f5175753b6c7a1e9c271085212",
          "body": "Integrate architectural-closure program through Phase 9.3",
          "is_bot": false,
          "headline": "Merge pull request #75 from globulario/integration/phase9.3",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T00:49:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3094c2c9dc9499f9be688c475bcd36e77782ffe6",
          "body": "…eta-principles.md)\n\nThe Sensei doc reframing (main commit 966af88) moved the meta-principle catalog\nout of README.md into docs/meta-principles.md and removed the README category\ntable, but the onboarding gate still required that table to sum to the pack —\nso main's own HEAD fails this gate. Retire only the README-table SUM check; the\nauthoritative total-count check across the onboarding docs is unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: retire the README principle category-table check (moved to docs/m…",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T00:32:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "59a39df50b4e41f9817d0aeb41eb039d99e580bd",
          "body": "Roll-up of the accepted architectural-closure spine (Phase 3 through Phase 9.3)\nonto current main. Integration proof, not a re-review: each slice PR carries its\nown accepted review history. Merges the exact accepted head\n65f8211920968044501079dc6d4cdb31ec21fce3.\n\nCo-Authored-By: Claude Fable 5 <nore\n[…]\nawareness_graph_annotation_report.yaml\n#\tdocs/awareness/high_risk_files.yaml\n#\tdocs/awareness/invariants.yaml\n#\tgolang/server/embeddata/awareness.nt\n#\tgolang/server/embeddata/awareness.transaction.tsv",
          "is_bot": false,
          "headline": "Integrate architectural-closure program through Phase 9.3",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-19T00:24:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65f8211920968044501079dc6d4cdb31ec21fce3",
          "body": "stringArg treated a PRESENT nil the same as an absent key (`!ok || v == nil`),\nso a JSON null — {\"repo\": \"...\", \"task\": null} — decoded to a present nil and\nsilently defaulted to the active task: exactly the malformed-identity fallback\nthe guard was meant to eliminate. Only an ABSENT key now default\n[…]\n are different worlds. Add explicit present-null rejection\nacross complete_task/inspect_terminal/recover_projections plus a stringArg\nunit test.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(completion): reject present-null identity in the MCP stringArg guard",
          "author_name": "davecourtois",
          "author_login": "davecourtois",
          "committed_at": "2026-07-18T23:39:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 6,
      "commits_last_year": 388,
      "latest_release_at": "2026-07-21T04:41:28Z",
      "latest_release_tag": "v1.3.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 2,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 1.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/globulario/sensei",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/globulario/sensei",
          "is_deprecated": false,
          "latest_version": "v1.3.0",
          "repository_url": "https://github.com/globulario/sensei",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-21T04:30:40Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 6
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "editor/vscode/proto/awareness_graph.proto",
        "proto/awareness_graph.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [
        "editor/vscode/tsconfig.json"
      ],
      "toolchain_manifests": [
        "examples/orders-money-scar/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 421511,
      "source_files_sampled": 1112,
      "oversized_source_files": 9,
      "agent_instruction_files": [
        ".cursor/rules/sensei.mdc",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 4395
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/emicklei/proto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.3"
        },
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "github.com/scip-code/scip/bindings/go/scip",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "github.com/tree-sitter/go-tree-sitter",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.25.0"
        },
        {
          "name": "github.com/tree-sitter/tree-sitter-python",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.23.6"
        },
        {
          "name": "github.com/tree-sitter/tree-sitter-rust",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.23.2"
        },
        {
          "name": "github.com/tree-sitter/tree-sitter-typescript",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.23.2"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.81.1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 67,
        "open_issues": 2,
        "closed_ratio": 0.333,
        "closed_issues": 1,
        "closed_unmerged_prs": 29
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "davecourtois",
          "commits": 366,
          "avatar_url": "https://avatars.githubusercontent.com/u/1697116?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "installer-test.yml",
        "release.yml",
        "seed-rebuild.yml",
        "sensei-selftest.yml",
        "vscode-extension.yml",
        "vscode-publish.yml",
        "winget-validate.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/17 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9c2b6d83692d75e8f692b2231fd754456e633fc8",
        "ran_at": "2026-07-22T19:06:43Z",
        "aggregate_score": 3.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T13:43:30Z",
      "oldest_open_prs": [
        {
          "number": 85,
          "created_at": "2026-07-19T18:57:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 96,
          "created_at": "2026-07-21T13:43:31Z",
          "last_comment_at": "2026-07-21T14:55:39Z",
          "last_comment_author": "davecourtois"
        },
        {
          "number": 99,
          "created_at": "2026-07-22T16:51:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 103,
          "created_at": "2026-07-22T18:28:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-22T18:03:46Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 88,
          "created_at": "2026-07-21T00:00:06Z",
          "last_comment_at": "2026-07-21T02:17:50Z",
          "last_comment_author": "davecourtois"
        },
        {
          "number": 95,
          "created_at": "2026-07-21T05:44:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/globulario/sensei",
    "host": "github.com",
    "name": "sensei",
    "owner": "globulario"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 34,
        "vitality": 69,
        "community": 36,
        "governance": 48,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 69,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "commits_last_year": 388,
              "human_commit_share": 0.91,
              "days_since_last_push": 0,
              "active_weeks_last_year": 2
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "2/52 weeks with commits",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "388 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 388
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 6,
              "latest_release_tag": "v1.3.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 1.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "6 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "merged_prs": 67,
              "open_issues": 2,
              "closed_issues": 1,
              "issue_closed_ratio": 0.333,
              "closed_unmerged_prs": 29
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "33% of issues closed",
                "points": 15.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 33
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "67/96 decided PRs merged",
                "points": 26.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 67,
                      "decided": 96
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/17 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "globulario",
              "public_repos": 15,
              "account_age_days": 2090
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of globulario",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "globulario"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "15 public repos, account ~5 yr old",
                "points": 20.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 15
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/globulario/sensei"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 1
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "9 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 34,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 34,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/17 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 82,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.989,
              "agent_instruction_files": [
                ".cursor/rules/sensei.mdc",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 4395
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursor/rules/sensei.mdc, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursor/rules/sensei.mdc, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 91 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 91
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "editor/vscode/tsconfig.json"
              ],
              "agent_commit_share": 0.57,
              "toolchain_manifests": [
                "examples/orders-money-scar/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "editor/vscode/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "editor/vscode/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "57 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 57,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 421511,
              "source_files_sampled": 1112,
              "oversized_source_files": 9
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "9/1112 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1112,
                      "oversized": 9
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "editor/vscode/proto/awareness_graph.proto",
                "proto/awareness_graph.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "editor/vscode/proto/awareness_graph.proto, proto/awareness_graph.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "editor/vscode/proto/awareness_graph.proto, proto/awareness_graph.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T19:06:57.545065Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/globulario/sensei.svg",
  "full_name": "globulario/sensei",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.26.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.