Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 3024,
"has_wiki": false,
"homepage": null,
"languages": {
"Go": 2295071,
"CSS": 4364,
"HTML": 359,
"Shell": 1873,
"Python": 7687,
"Dockerfile": 3690,
"JavaScript": 13756,
"TypeScript": 861036
},
"pushed_at": "2026-07-25T11:40:52Z",
"created_at": "2026-07-17T12:56:05Z",
"owner_type": "User",
"updated_at": "2026-07-25T11:41:02Z",
"description": "OpenAI-compatible reverse proxy for higgsfield.ai with a pluggable account pool, registration pipeline, and dual delivery modes (standalone WebUI + CPA plugin).",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go",
"TypeScript"
]
},
"owner": {
"blog": null,
"name": "CodingSheep",
"type": "User",
"login": "greenSheep999",
"company": null,
"location": null,
"followers": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/301825685?v=4",
"created_at": "2026-07-09T16:44:53Z",
"is_verified": null,
"public_repos": 5,
"account_age_days": 17
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.7.2",
"kind": "patch",
"published_at": "2026-07-25T11:40:44Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-07-25T10:13:00Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-25T09:26:15Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-07-21T13:00:54Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-07-21T11:50:28Z"
},
{
"tag": "v0.5.13",
"kind": "patch",
"published_at": "2026-07-20T19:21:54Z"
},
{
"tag": "v0.5.12",
"kind": "patch",
"published_at": "2026-07-20T19:14:20Z"
},
{
"tag": "v0.5.11",
"kind": "patch",
"published_at": "2026-07-20T12:19:18Z"
},
{
"tag": "v0.5.10",
"kind": "patch",
"published_at": "2026-07-20T11:41:51Z"
},
{
"tag": "v0.5.9",
"kind": "patch",
"published_at": "2026-07-20T11:30:22Z"
},
{
"tag": "v0.5.8",
"kind": "patch",
"published_at": "2026-07-20T11:22:28Z"
},
{
"tag": "v0.5.7",
"kind": "patch",
"published_at": "2026-07-20T10:25:21Z"
},
{
"tag": "v0.5.6",
"kind": "patch",
"published_at": "2026-07-20T09:46:06Z"
},
{
"tag": "v0.5.5",
"kind": "patch",
"published_at": "2026-07-20T09:21:04Z"
},
{
"tag": "v0.5.4",
"kind": "patch",
"published_at": "2026-07-20T09:01:16Z"
},
{
"tag": "v0.5.3",
"kind": "patch",
"published_at": "2026-07-20T07:56:50Z"
},
{
"tag": "v0.5.2",
"kind": "patch",
"published_at": "2026-07-20T06:31:43Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-07-20T06:07:04Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-20T05:14:56Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-19T20:59:22Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-07-19T18:23:19Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-07-19T17:59:00Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-07-19T17:30:29Z"
}
],
"recent_commits": [
{
"oid": "970e4a9e9d0f961a33d0ff611de53be666923c29",
"body": "… (2026-07-25)\n\nMigration 030 seeded seedance-2-0 INTL rows by folding the token unit price × 5s × output area × 24fps / 1024 into a per-second number. That reproduces byteplus's own published /video number only when our fps/aspect assumptions match theirs exactly — and today they don't. Every resol\n[…]\nvolcengine.com in a follow-up before touching.\n\nIdempotent: pure UPDATE on primary key + OR IGNORE on the two new rows. Test locks the six updated values plus the two new rows' presence and one price.",
"is_bot": false,
"headline": "fix(pricing/seedance-intl): align per_second to byteplus.com live doc…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-25T11:40:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "632230ff661520069ba009d69e651a4c95e49f69",
"body": "…s feeds\n\nPrior state leaked internal retail decisions on an authenticated route we then also had to expose to /api/pricing anonymously for downstream ratio_sync to work. That double-bind is resolved:\n\n- GET /api/pricing (ANONYMOUS): observations only. tier() fixed_micros equals the raw provider scr\n[…]\nre per-tier discount signals, both of which only exist on the retail feed.\n\nReadFailure test switched from seeding decisions.err to observations.obsErr since the public feed no longer reads decisions.",
"is_bot": false,
"headline": "feat(api/pricing): split public official-only vs auth retail-override…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-25T10:13:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4b9cf3df3b1f61f1b13ea93160330ba1cf4c254",
"body": "tierLabelFor replaced tierLabel in bef220e; the old helper stuck around as dead code and staticcheck flagged it. Everything downstream already uses tierLabelFor / tierLabelFrom.",
"is_bot": false,
"headline": "fix(ci): drop unused tierLabel helper (staticcheck U1000)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-25T09:26:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09f8017c8df5566cd5b7f4e8efa9df08efd82d8f",
"body": "The gofmt job on main has been red since bef220e / fa2f59c — 10 files across pricing/domain/tests carry stale formatting (tab vs space in struct tags, alignment drift after adding fields). Running 'gofmt -w internal/' cleans them all up with no semantic change.\n\nSeparately, webui build was breaking \n[…]\nvery push, which meant the docker image on ghcr.io was stuck at the 07-21 build. That's why higgs.aibbq.xyz was returning 404 for /api/pricing — the code was in main but never landed in the container.",
"is_bot": false,
"headline": "fix(ci): gofmt 10 files + webui official_api array shape",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-25T09:17:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37d7298145b5f5fae470e73f789d6d8b2f5d2885",
"body": "GitHub push-protection was flagging the example webhook URL (all-zero tenant + all-X secret) as a leaked Slack webhook. It's obviously a placeholder but the scanner only looks at the URL shape. Replacing with plain '<paste ...>' text so future pushes don't get blocked by the same false positive.",
"is_bot": false,
"headline": "chore(config): use placeholder text instead of fake Slack webhook URL",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T05:31:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa2f59c4846f005dc7c53672f1363f09633b1551",
"body": "…provider aliases\n\nExtends official_price_observations from the 23-row INTL-Kling-only seed (migration 029) to 106 rows covering every alias in verified-models.json that maps to a real-provider public pricing page.\n\nCoverage (33 aliases visible in /api/pricing wire, i.e. estimated=false):\n Kuaishou\n[…]\now expects 12 kling-3 rows (8 INTL from 029 + 4 CN from 030) instead of 8. The anchor assertion is scoped to region='intl' so downstream discount-badge behavior stays locked to a single canonical row.",
"is_bot": false,
"headline": "data(pricing): backfill migration 030 — official prices for all real-…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T05:08:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6d0395d64a238408518960cd2768bf60ed0ffea",
"body": "…ros wire fields (§6.2)\n\nFollow-up to bef220e — documents the two carriers new-api front-end reads for discount badge computation: model-level official_price_micros (top-level int) and per-tier official_micros=NNNN (kv inside the tier() note, emitted only when fixed differs from raw). Both are duration-folded USD × 1e6. Wire regex unchanged.",
"is_bot": false,
"headline": "docs(pricing): document official_price_micros + per-tier official_mic…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T04:32:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bef220e62a9cf1f31bcfa661731eca3e44f05592",
"body": "…r discount badges\n\nnew-api front-end computes discount ratio as (fixed × group_ratio) / official. Until now higgsgo published the same number for both fixed and official (whole feed = raw provider prices, ratio always 1.0), so no discount rendered. This adds the machinery to publish a distinct offi\n[…]\n-level fallback 420_000\n- Model-level official_price_micros = 420_000 (cheapest = 720p × off × 5s duration fold)\n\nIf either side edits the regex or arithmetic, this file MUST be updated on both sides.",
"is_bot": false,
"headline": "feat(pricing): emit official_price_micros + per-tier note override fo…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T04:31:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab9025318d1102da1e1cef6e75c993b6c04d7019",
"body": "… not our retail\n\nAfter the 2026-07-24 semantics review with the operator, the wire contract for /api/pricing is inverted.\n\nBefore: /api/pricing published higgsgo's own decided retail prices (from model_price_decisions). /api/pricing/official-api published raw provider prices as a sibling market-dat\n[…]\n-INTEGRATION-FEEDBACK.md 5-item plan for building a separate model-price-adapter is obsoleted — the whole subsystem collapses into 'add higgsgo URL as a third preset alongside basellm and models.dev'.",
"is_bot": false,
"headline": "feat(pricing): flip /api/pricing semantics — publish official prices,…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T04:11:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d38170692bbf72d1b7f3f7f2b4977ed37e835118",
"body": "Response to PRICING-NEW-API-INTEGRATION-FEEDBACK.md — dan's readout after wiring the new-api model-price-adapter against the sample fixtures.\n\n- wire_dump_test.go: fixture observations now carry a real ObservedAt (2026-07-22 scrape date), so the dumped /tmp/higgsgo-wire-official-api.json no longer s\n[…]\nkey per integration so it can be rotated without touching consumer traffic.\n\n- PRICING-NEW-API-INTEGRATION-FEEDBACK.md: dan's original readout committed alongside as reference for future integrations.",
"is_bot": false,
"headline": "docs(pricing): address new-api integration feedback (§6.4)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T03:02:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6aebf19a2d3516bd11520608cf5e1f2df0a55bfc",
"body": "TestDumpWireResponse writes real /api/pricing + /api/pricing/official-api response bytes to /tmp when HIGGSGO_DUMP_WIRE=1 so an operator can hand a golden fixture to new-api's team without booting the full server. Skipped in CI by the env-var gate.\n\nUsed to validate the downstream contract before the first ratio_sync integration; the emitted billing_expr matches the DSL grammar in PRICING-DOWNSTREAM-CONTRACT.md §6.2 exactly.",
"is_bot": false,
"headline": "test(v1/pricing): wire-dump helper for new-api fixture handoff",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T02:34:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9af9070fc379229892c3a32eb6d7b27244a6d76f",
"body": "…e-batches admin\n\nThe operator pricing surface, driven by admin's PricingMatrix/PricingDecisions/FloorSuggestions/PurchaseBatches endpoints:\n\n- matrix-table.tsx: rebuilt column layout — Variant | Higgs (credits+unit cost) | 国内套餐 | 国内API | 海外套餐 | 海外API | 建议/自定义. Plan cells show ¥/$ monthly and per-cr\n[…]\nlValue (region + estimated + mode), PricingSuggestedValue, CreatePricingDecisionRequest, PricingDecisionWarning\n- app-sidebar / router / models route / locales: nav entry + route wiring + i18n strings",
"is_bot": false,
"headline": "feat(webui/pricing): 4-region matrix + suggested-price cell + purchas…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T02:31:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "070b018126a0dd1b58c6aef130d360e220c20b6c",
"body": "- migration 027 purges the 34 fabricated official_price_observations rows that shipped in 022-024's seed. These were transcribed from placeholder assumptions rather than from an operator-verified source and were the reason for a factual dispute with the operator; they are gone.\n\n- migration 028 adds\n[…]\nudio-kling, kling-o3-*, kling-omni-image*, kling-transition) intentionally absent — pending operator verification.\n\nCN Kling rows deferred until the operator verifies klingai.kuaishou.com/dev pricing.",
"is_bot": false,
"headline": "feat(pricing): region axis + verified Kling intl seed",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T02:30:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfbe53295199d9ecb43c6b829ccbae06852716df",
"body": "This ships the pricing subsystem end-to-end:\n\n- migrations 022-026: pricing_snapshots + model_cost_rules preserve every /job-sets/costs response losslessly; higgs_plan_rates + official_price_observations + model_price_decisions form the operator-facing four-layer comparison; purchase_batches records\n[…]\nd buys\n\n- PRICING-DOWNSTREAM-CONTRACT.md + PRICING-SOURCE-OF-TRUTH.md are the wire contract and internal storage doc respectively; new-api's controller/ratio_sync.go PricingItem parser stays untouched",
"is_bot": false,
"headline": "feat(pricing): 4-layer source-of-truth + downstream /api/pricing feed",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-24T02:29:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd2edbd4379c0b83ea378e04383295a5a7061999",
"body": "…ndle\n\n- when spec.UnlimJobSetType is set (from model-specs-extra.json) and Store.HasActiveUnlimFor returns true, switch the endpoint to /jobs/v2/<unlim_jst> and set use_unlim=true in the body; higgsfield then bills against the unlim window instead of subscription credits\n- lookup error is non-fatal\n[…]\ns through buildBody as image_url so the sora HTTP-URL variant lands on the same media rail as pre-uploaded IDs\n- buildbody_media_test + buildbody_unlim_test cover the four (media × unlim) matrix cells",
"is_bot": false,
"headline": "feat(proxy): route to _unlimited variant when account holds active bu…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:50:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb236986e39e41175a7d383d6a4c5f17b3395e3a",
"body": "- migration 021 adds grace_status / blocked_at / suspended_at / is_paused as derived signals for the replenish alerter; deliberately NOT gates for pool eligibility (status='active' stays the sole 入池 gate)\n- AccountStore grows four methods: HasActiveUnlimFor for the proxy service's route-to-_unlimite\n[…]\nkedAt/SuspendedAt/IsPaused; domain.UnlimActivation carries ID (server-side activation id, for POST /workspaces/unlim-activations/{id} claim) and IsClaimed (transient flag from upstream, not persisted)",
"is_bot": false,
"headline": "feat(accounts): upstream lifecycle columns + active-unlim lookups",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:50:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8ab72efb5c57dab00fd79a2daed89de51f3553f",
"body": "…playground\n\nmatches the mock surface expanded in the previous commit — the admin/cpaplugin/registrar/playground handlers all keep the compile-time contract with ports.AccountStore green",
"is_bot": false,
"headline": "test(api): widen AccountStore stubs across admin/cpaplugin/registrar/…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:46:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca7b95d98449065a692a8f29bd1d370fbe3c3142",
"body": "- add HasActiveUnlimFor/CountActiveUnlimByJST/UpdateUpstreamStatus/UpdateGraceStatus stubs across failover/metering/pollworker/pool_collector mocks so callers compile against the widened AccountStore surface\n- pool_unlim_free_quota_test.go: SQLite-level regression on CountActiveUnlimByJST grouping and the UpdateFreeQuota/UpdateUpstreamStatus write paths",
"is_bot": false,
"headline": "test: extend AccountStore mocks + unlim/free-quota SQLite coverage",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:45:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "860c116324a5d0feb23cf969e0e6cc70efa0fa43",
"body": "- FreeGensV2Enabled toggle (default on) so refresher pulls GET /user/free-gens/v2 and reconciles the per-job_set_type counters over the /user *_credits fields; v2 fetch failure is non-fatal (warn, no failover feedback)\n- UpdateUpstreamStatus writes blocked_at/suspended_at/is_paused (with is_pause_scheduled folded in) from the /user snapshot — informational signal for the replenish alerter, never a pool gate",
"is_bot": false,
"headline": "feat(refresher): free-gens/v2 calibration + upstream lifecycle capture",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:45:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b931a62023a59ff840ec39624dc71d1bf688de92",
"body": "- forward sr.ImageURL through proxy.MediaInput.URL rather than a stray userParams key so the media path handles both pre-uploaded IDs and URLs uniformly\n- enforce maxSoraJSONBody as a hard cap (read maxBody+1, reject when over) and wrap multipart reads in http.MaxBytesReader plus MultipartForm.RemoveAll\n- merge extra_body from multipart form into sr.Extra so URL-encoded callers get the same passthrough as JSON",
"is_bot": false,
"headline": "fix(videos): image_url via Media.URL + multipart body limit + extra_body",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-23T17:44:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb08d0b8c6b099bd90adfe99e4ad2c9d3451ca96",
"body": "perf(ci): cache Go/pnpm + parallel docker build",
"is_bot": false,
"headline": "Merge pull request #6 from greenSheep999/perf/ci-docker-cache",
"author_name": "CodingSheep",
"author_login": "greenSheep999",
"committed_at": "2026-07-21T13:00:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c874ca834fd9980b0bbdb1b4766a1d4a212bc85",
"body": "Two structural fixes to the release workflow. Baseline: v0.6.0\ndocker step took ~1h (canceled); reference claudego release is 9m.\n\n1. Dockerfile: three BuildKit cache mounts.\n - pnpm store -> webui install: no re-download on rebuild\n - GOMODCACHE -> go mod download: no re-fetch\n - go\n[…]\n- claudego release completed in 9m1s under the same platforms\n (linux/amd64, linux/arm64).\n - higgsgo v0.6.0 first-ever run reached 57m with docker step\n still in-progress before manual cancel.",
"is_bot": false,
"headline": "perf(ci): cache Go/pnpm + parallel docker build",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T12:54:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52fed442fb693da8ec84c94c55e84c3893eb758f",
"body": "feat: OpenAI/Sora-compatible /v1/videos surface",
"is_bot": false,
"headline": "Merge pull request #5 from greenSheep999/feat/openai-video-compat",
"author_name": "CodingSheep",
"author_login": "greenSheep999",
"committed_at": "2026-07-21T11:50:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6e2cffab4adcb1f70f16317e063c48480a411411",
"body": "Two independent problems, one PR because the release depends on both:\n\n1. Build step failed at go vet with pattern all:dist: no matching\n files found (webui/embed.go). CI checked out without ever running\n pnpm --dir webui build, so webui/dist did not exist. Add the same\n node/pnpm/build sequen\n[…]\nfake; kept TestIsSpilloverEligible which is the only\n thing that actually ran. A future integration test can\n reintroduce the fake.\n\nLocal go test ./... passes; staticcheck ./... is clean.",
"is_bot": false,
"headline": "ci: unbreak Build & unit tests + gofmt/staticcheck jobs",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T09:31:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d0c274307501dda102ea641395887d42ba05a166",
"body": "CI fixes for PR #5:\n\n - internal/api/v1/videos_openai_test.go was not gofmt-clean\n when the workflow agent generated it.\n - go.mod / go.sum lacked the plugins/register workspace\n dependency that go mod tidy resolves. Register build only\n activates under -tags=register but the module row still\n needs to be present for tidy to pass.\n\nBoth are purely mechanical - no code changes.",
"is_bot": false,
"headline": "chore(ci): gofmt videos_openai_test.go + go mod tidy",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T08:09:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "acb0b97767d6b1382e1c674e2fcb0304e28a1457",
"body": "Adds cmd/higgsgo/sora_uploader.go - a thin adapter that satisfies\nv1.SoraMediaUploader by borrowing any active higgsfield account\n(via AccountStore.List with Status=active) and delegating to\nupstream.Client.UploadImage.\n\nMedia is account-agnostic once committed, so we do not go through\nthe pool rout\n[…]\nes as 502.\n\nWithout this wiring, POST /v1/videos with a data-URI or multipart\nfile part returns a 400 \"requires SoraUploader wiring\". HTTP(S) URL\ninput_reference and pure text prompts work either way.",
"is_bot": false,
"headline": "feat(main): wire SoraMediaUploader for POST /v1/videos uploads",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T08:02:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7e5409b409447dfe38fdf7b3c74ae59111c70fb",
"body": "Three new routes on the public listener behind APIKeyAuth+RateLimit:\n\n POST /v1/videos - create job, Sora body shape\n GET /v1/videos/{id} - poll status\n GET /v1/videos/{id}/content - stream MP4 (reverse-proxied)\n\nHandler translates Sora body -> higgs-nativ\n[…]\n/8s), tier boundaries, extra_body\npassthrough, data-URI decode, multipart file upload, uploader\nwiring, poll ownership, content streaming with Range forwarding,\n409-not-ready, forbidden-fields golden.",
"is_bot": false,
"headline": "feat(api): POST /v1/videos + poll + content (OpenAI/Sora shape)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T08:02:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c80cbe7d143da727f77574b46ca3fa8f46dc0739",
"body": "Adds Client.UploadImage(ctx, account, contentType, body):\n 1. POST /media {content_type} -> {id, url, upload_url}\n 2. PUT presigned S3 URL with raw bytes (no auth header - S3 direct)\n 3. POST /media/{id}/upload {} -> flip status to uploaded\n\nErrors are wrapped with a phase label (media_reserve_\n[…]\n a data-URI or a\nmultipart file part (see docs/OPENAI-VIDEO-COMPAT.md Appendix C).\n\nTest uses httptest to emulate the three-step flow and asserts no\nAuthorization header leaks to the S3 presigned PUT.",
"is_bot": false,
"headline": "feat(upstream): UploadImage - 3-step higgsfield media protocol",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T08:01:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92fb1ba08d1770bbc18c526eb25f455ce69d605c",
"body": "New wire spec for POST /v1/videos, GET /v1/videos/{id}, and\nGET /v1/videos/{id}/content, sourced from new-api relay/channel/task/sora/\nadaptor.go and the 100b decision doc. Locks:\n\n - Resolution tier: shorter-side derivation (480p/720p/1080p/4k),\n matches Sora convention (portrait 1024x1792 -> 1\n[…]\nes untouched.\n - Appendix C: higgsfield media upload 3-step protocol\n (reserve /media -> PUT presigned S3 -> commit /media/{id}/upload),\n ported from higgsfield-register/src/upstream/media.mjs.",
"is_bot": false,
"headline": "docs: OpenAI/Sora video-compat spec (docs/OPENAI-VIDEO-COMPAT.md)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-21T08:01:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0061d338f1c9cc558ce76f18ef14ef408ff4050e",
"body": "…resolves\n\nv0.5.12's docker job failed with 'pattern all:dist: no matching files\nfound' because Dockerfile went straight to `go build` without\nproducing webui/dist first. Native binary jobs in release.yml already\nrun `pnpm --dir webui build` on the host before their go build; the\ncontainer build was\n[…]\nissing that step.\n\nAdd a node:22-alpine webui stage that runs pnpm install + pnpm build,\nthen COPY --from=webui the compiled dist into /src/webui/dist so\nwebui/embed.go's //go:embed all:dist finds it.",
"is_bot": false,
"headline": "fix(docker): build webui/dist before go build so //go:embed all:dist …",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T19:21:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "036e648a93da2157f1b4dc16303aedf123b27da3",
"body": "…ar-reclaim\n\nfix(registrar) + feat(api): reclaim orphaned running rows; add /v1/video/generations alias",
"is_bot": false,
"headline": "Merge pull request #4 from greenSheep999/feat/video-alias-and-registr…",
"author_name": "CodingSheep",
"author_login": "greenSheep999",
"committed_at": "2026-07-20T19:14:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b7c21d8ac43db6bb56fcf22a8e7bcd2a33ce362",
"body": null,
"is_bot": false,
"headline": "style: gofmt -w .",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T19:06:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9b8acc238bdcc7579a717d5108489f4f6fe16b2a",
"body": "Serve video generation on two paths against the same handler:\n * /v1/video/generations (singular; new-api / OneAPI shape, preferred)\n * /v1/videos/generations (plural; higgsgo legacy, kept for compat)\n\nHistorical background: higgsgo shipped its OpenAI-style public surface\nwith plural /v1/videos\n[…]\nd:\n go build ./... (silent OK)\n go build -tags=register ./... (silent OK)\n go test ./... (all green, including new alias test)\n go test -tags=register ./... (all green)",
"is_bot": false,
"headline": "feat(api): mount /v1/video/generations alias for new-api compat",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T18:54:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ebb4bed908070c8da411c4f0c8bdd99ebc1703d",
"body": "Registrations that were mid-flow when the previous higgsgo process was\nkilled stayed pinned to status='running' forever. Worker only claims\n`pending`, and admin Retry was a no-op on `running`, so a single ungraceful\nshutdown could leave a row wedged (observed live: id=3 stuck 22h).\nThe WebUI polls a\n[…]\nall.\n\nSingle-instance SQLite deploy means no live worker can own a `running`\nrow across a restart, so the unconditional flip is safe. If we ever\nmove to multi-replica, this needs a lease/lock instead.",
"is_bot": false,
"headline": "fix(registrar): reclaim orphaned running rows on boot",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T18:54:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7705a4609b94cc47898a3db3d39d14f36710d899",
"body": "CPA plugin (Mode B) exposes /internal/* to an upstream CPA platform\nthat would consume higgsgo as its account-pool backend. Every real\ndeploy sets modes.cpa_plugin=false so the /internal listener never\nstarts and the /admin/usage/aggregate view has no cpa_partner_id rows\nto show. The sidebar entry w\n[…]\nMode B back on, restoring the sidebar entry is a one-line\nrevert.\n\nBackend code untouched: internal/api/cpaplugin/ still compiles and\ntests still run so nothing regresses in the standard test surface.",
"is_bot": false,
"headline": "chore(webui): hide CPA plugin nav entry — mode is off in every deploy",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T12:19:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "421ce27a4e174d1190d31da3af9ef2b06ac029d9",
"body": "The three v0.5.7 fields (unlim_job_set_type, unlim_bundle_types,\nfree_quota_field) landed on ModelSpec + were consumed by the router,\nbut the Playground UI never exposed them so operators couldn't see\nwhich model has an unlim bundle available or a per-family free quota\ncounter. Adds:\n\n- api/v1 model\n[…]\np\n prefer_unlim in Settings.\n * 'free quota' (blue) — model consumes a /user free-quota\n counter; tooltip names the field.\n\nBackend tests: 26 packages still pass. WebUI: pnpm build clean.",
"is_bot": false,
"headline": "feat(webui): surface unlim + free-quota metadata as playground chips",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T11:41:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a7e335439baae92338599768d6a5f542425c300",
"body": "v0.5.8 corrected the endpoint from '?' to '/jobs/v2/cinematic_studio_2_5'\nbut forgot to update the version column, leaving the row internally\ninconsistent (version='v1-hyphen' with a v2-style endpoint). No\nconsumer relied on version for routing today so nothing broke, but\nfuture callers or dashboard\n[…]\nion could have picked\nthe wrong URL style. Now version matches the endpoint.\n\nFull sweep of verified-models.json confirms the other 128 aliases\nhave consistent version ↔ endpoint pairs. Data-only fix.",
"is_bot": false,
"headline": "data: sync cinematic-studio-2-5 version field (v1-hyphen → v2)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T11:37:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "017a5815b10f55dd836d4c0fc12dc07efeebbaaf",
"body": "ghcr.io tag validation rejects mixed-case names (\"invalid tag ...\nrepository name must be lowercase\"). ${{ github.repository_owner }}\ncarries whatever case the org was created with (greenSheep999 here),\nso every release since v0.3.0 has failed the Docker step while the\nbinary artifacts land fine.\n\nPrecompute owner_lc via tr in the meta step, reference the lowercased\nvalue in the tags block. No functional change to the binary /\nGitHub-release paths; only makes the Docker publish step green.",
"is_bot": false,
"headline": "ci(release): lowercase ghcr.io owner tag",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T11:36:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2a5ee53fb6160e9a0a238164f9c146c4d0bb41e",
"body": "…ller\n\nCloses the last unwired edge of the auto-pause loop. Before this the\nfailover pipeline was fully implemented but silent: refresher tick\nwould observe HTTP 401 (Clerk session expired) or 5xx on every dead\naccount, log a Warn, and move on. The controller — capable of\ncounting consecutive fails \n[…]\nefresher_ForwardsFailuresToFailover proves both wallet\nand user fails call RecordError; TestRefresher_NilFailoverIsSafe\nproves the nil-Failover path doesn't panic.\n\nAll 26 packages pass; go vet clean.",
"is_bot": false,
"headline": "fix(refresher): forward wallet/user fetch failures to failover contro…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T11:30:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "787cb376da59dc6a61568e3b1a5a0a35c27296a7",
"body": "Both models were mis-marked as dead in v0.5.7 because the tier-probe\nagent tested /jobs/<alias> (v1 hyphenated) on both and got 404. That\nwas the wrong endpoint — the tier probe never had the correct paths\nbecause verified-models.json shipped them with endpoint='?' from day\none (both were sealed wit\n[…]\n-up: the seed data has 2 more aliases with endpoint='?'\n(check verified-models.json for the pattern). They may or may not\nbe dead — need a similar log spelunking to confirm before assuming\neither way.",
"is_bot": false,
"headline": "fix(data): unearth cinematic-studio-2-5 + flux-kontext endpoints",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T11:22:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f6a8fde21047adde5c5946487f63aa99afb19172",
"body": "Wires the two dormant load_balance flags from v0.5.6 end-to-end.\nRefresher now pulls the required data on every tick; PickAndLock\nconsults it when the operator toggles the flag on in Settings.\n\nDB schema (migration 020):\n- new table account_unlim_activations (account_id, bundle_type,\n job_set_type,\n[…]\nFor pools\n >100 accounts we may want to gate the unlim call behind has_unlim.\n3. Free-quota values as NOT NULL DEFAULT 0 — a fresh row reads as\n 'no quota holders', matches the intended semantics.",
"is_bot": false,
"headline": "feat(load_balance): activate prefer_unlim + prefer_free_quota",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T10:25:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89133275ca4dff57ab0a9ebebfe3382810628aae",
"body": "Continues v0.5.5's collapse of route_strategy to load_balance/priority\nby moving the inner load_balance ordering knobs from hardcoded SQL to\noperator-editable settings. Regular operators still see one dropdown\n(load_balance vs priority) on each group; admins get a second Settings\ndialog to tune what\n[…]\nhenGetReflectsDBSource\n TestLoadBalanceSettings_PutRejectsHeadroomOutOfRange (below/above)\n TestLoadBalanceSettings_PutRejectsEmptyBody\n\nAll 26 backend packages still pass; webui build + lint clean.",
"is_bot": false,
"headline": "feat(load_balance): advanced settings — 6 operator knobs in Settings UI",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T09:46:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ca76efef4288d4a2947ebc68cda5d11ac815300",
"body": "Simplifies the operator UX from 6 mutually-exclusive route strategies\ndown to 2 concepts that reflect actual operator intent:\n\n * load_balance (round_robin) — auto everything. Composed ordering\n with no operator knobs: tier ASC (cheap-first) + LRU + least-loaded\n + jitter. Cheap models drain \n[…]\nbin).\n\nWebUI: create-dialog, edit-dialog, group-detail dropdowns all shrunk\nto 2 options labelled 'load_balance' + 'priority'. The internal DB\nvalue stays round_robin so no schema change on that side.",
"is_bot": false,
"headline": "feat(routing): collapse route_strategy to load_balance + priority",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T09:21:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a2a8b8456883155d0661ba95b86443914c8b55e",
"body": "Adds a new route_strategy value 'best_fit' that orders pool candidates\nby plan tier rank ascending, so cheap models (min_plan=starter) burn\nstarter accounts first and escalate to pro / plus / ultra-family only\nwhen the tighter tier is saturated or out of budget. Tiebreak inside\nthe same tier stays o\n[…]\nck_BestFit proves the escalation\nladder (starter → pro → plus) as each tier's per-account cap fills.\n\nNot the default. Operators opt in per-group via the WebUI or via\nPOST /admin/groups when creating.",
"is_bot": false,
"headline": "feat(pool): RouteBestFit strategy — closest-tier-first routing",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T09:01:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "97e6be889e8d52652c9a47060ff5f8d45fbd16d0",
"body": "…undles\n\nRan a 3-tier probe (starter/plus/pro) against all 129 aliases:\n- Zero tier-gate 402/403 JSON responses on any live model. All 127 live\n endpoints hit the same body-schema 422 across starter/plus/pro. The\n real gate lives at plan_type=free, not at model level.\n- 2 dead endpoints (404 acros\n[…]\nodel,\nand to prefer free_quota_field-non-zero accounts to burn free gens\nbefore charged credits.\n\nSource: /tmp/tier_probe_results.json (in-flight 3-tier probe report\ncommitted alongside as reference).",
"is_bot": false,
"headline": "data(models): full min_plan=starter matrix + dead endpoints + unlim b…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T07:56:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0960ab287a7b4fd7ae9032ecba6abf376c3c24ad",
"body": "Historical audit data (higgsfield-register/server/data/a-class-regression-v2.json,\nranAt=2026-07-17) shows seedream-v4-5 completed successfully on a\nstarter account (von7qxenjs@pixelpho.space, plan_type=starter), with\nwallet delta -1539 subscription + -270 credits. So the model was\nverified to run o\n[…]\nges/generations -d '{\"model\":\"seedream-v4-5\",...}'\n → picks starter/pro/plus in rotation (never free)\n → 3 completed, 2 pool_saturated (all 3 active seats busy)\n → no free-account 402 path any more",
"is_bot": false,
"headline": "fix(schema): correct seedream-v4-5 min_plan basic → starter",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T06:46:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "337a58a428e1f6b33711cdc8c27bdc03fbdcdc24",
"body": "Third review round found three latent gaps in model→account matching\nand one deterministic upstream-parse bug. All four addressed together\nbecause they share a diagnostic surface (production requests silently\npicking wrong accounts / crashing at upstream parse).\n\n1. min_plan routing (seedream-v4-5 →\n[…]\ner_source=mapping models (flux-2, nano-banana-2, z-image, etc.)\nhave been observed running on free/starter accounts in production and\nstay at the derived floor. Add more entries when new 402s surface.",
"is_bot": false,
"headline": "fix(pool): min_plan routing + RequiresUnlim wire-up + cost float parser",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T06:31:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "03a4cf5dbbd2b0da304c330d9c434a848f946380",
"body": "…p + migration tx\n\nSecond review pass on the post-v0.5.0 branch surfaced five follow-up\nitems. All fixed and covered by tests:\n\n1. F1 residual — sync path could enter lost-race branch even when the\n jobs row was never persisted (Jobs.Create failed) or when the CAS\n itself errored (transient DB f\n[…]\nrced), README.md (status → production, build/run instructions).\n\nCommitted the docs/reviews/2026-07-20-main-validation.md report that\ndrove this round so future audits can chain reference the fix set.",
"is_bot": false,
"headline": "fix(review-round2): close remaining F1 gaps + timeout CAS + global ca…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T06:07:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f0f77fa72718d7938c27fdab863980b5bdf6629b",
"body": "Review found that accounts.max_concurrent was persisted, exposed in the\nadmin API + WebUI, but PickAndLock never consulted it — the actual\nper-account cap came from PickParams.MaxConcurrentPerAccount only, or\nfell back to hardcoded 5. Operators could set values that appeared\nmeaningful in the UI but\n[…]\nalue of 1 blocks the second pick even under a loose group cap\n(10). TestAccountStore_PickAndLock_ZeroAccountCapIsUnlimited proves the\ndefault-zero path still admits three picks under a group cap of 3.",
"is_bot": false,
"headline": "fix(pool): enforce accounts.max_concurrent in PickAndLock (F4)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T05:14:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "09694691aef676739e340e77e3aa48ddca6f50de",
"body": "…(F1)\n\nIncludes fixup for migration 018 pre-index dedupe and sync-path unlock\ngating on CAS winner.",
"is_bot": false,
"headline": "Merge PR #1: terminal-transition idempotency via TryMarkTerminal CAS …",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T05:11:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "deba3249a2f7fa4b14564df016a078bd39298e7c",
"body": "Review found two blockers on the F1 CAS work:\n\n1. migration 018 CREATE UNIQUE INDEX would fail on any prod DB with\n pre-existing duplicate usage_events rows produced by the exact race\n this migration is closing — the ship path would break on deployments\n most in need of the fix. Added a DELETE\n[…]\nhanism —\n the loser now sets handedOff before unlock() so unlockOnce becomes a\n no-op, leaving slot release to the winner. Error paths keep the\n pre-CAS unlock() since no CAS ran on those exits.",
"is_bot": false,
"headline": "fixup(f1): pre-index dedupe + gate sync unlock on CAS winner",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T05:11:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd6198860cee2aa16f6828eca813c84421aca682",
"body": null,
"is_bot": false,
"headline": "Merge PR #3: /metrics auth + metering doc + react-hooks lint (F5/F6/F7)",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T05:08:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "92b39323df1806f02f7627dbf268c1f708f7eab4",
"body": "…sts (F2/F3)",
"is_bot": false,
"headline": "Merge PR #2: annotated catalogRefs parser + AppleDouble regression te…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T05:08:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e354cbe4dba08ae56111f42e97e28e0659c46a7d",
"body": "…ring doc + kill react-hooks lint",
"is_bot": false,
"headline": "chore(hardening): protect /metrics behind admin bearer + refresh mete…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T04:28:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a1e1d15338940ec362640b1d64970d07b65705e",
"body": "… tests\n\nRegistry today resolved body-template catalogRefs via a single flat map\nlookup, which silently dropped 32 of 40 annotated refs in the shipped\ndata/reference/body-templates/*.json — anything with a `→ item.…`\nextractor, a `literal enum: …` inline set, or a trailing annotation just\nfell throu\n[…]\nhe 4 SPA/server orphans and\n the 3 empty-by-default catalogs (reference_elements,\n marketing_brand_kits, marketing_products).\n\nVerified: go build ./..., go vet ./..., go test ./... all pass.",
"is_bot": false,
"headline": "feat(registry): annotated catalogRefs parser + AppleDouble regression…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T04:25:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "98377f1ce9cb08cac69255b0bac20ff605fe00be",
"body": "Two independent observers of the same job's terminal transition —\nthe sync request path in `internal/core/proxy/service.go` and the\nbackground pollworker in `internal/core/pollworker/worker.go` — both\ncalled `UpdateStatus` + `Meter.OnJobTerminal` + `Webhooks.Fire` on\nthe same job whenever the pollwo\n[…]\n pass\n go test -race ./internal/adapters/storage/sqlite/...\n ./internal/core/proxy/...\n ./internal/core/pollworker/... pass",
"is_bot": false,
"headline": "fix(jobs): terminal-transition idempotency via TryMarkTerminal CAS",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-20T04:20:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e33fbd39752424520ae23f0321cc4acfa46ac8b5",
"body": "…logs\n\nA cross-machine deploy that carries the data dir through tar cf from a\nmacOS APFS source leaves behind ._foo.json AppleDouble metadata files.\nloadBodyTemplates and loadCatalogs previously tried to json.Unmarshal\nthem and aborted the boot ('invalid character \\x00 looking for\nbeginning of value'). Skip anything whose name starts with '.' or\n'._' so the loader tolerates arbitrary hidden files.",
"is_bot": false,
"headline": "fix(loader): skip macOS AppleDouble/dotfiles in body-templates + cata…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T21:05:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05429c1708874c58fb2162d2161057bdee7b444e",
"body": "Wire the schema data that was captured months ago in higgsfield-register\nbut never crossed the repo boundary. Every request path can now default\nmissing params, and the WebUI can render dropdowns for catalog-backed\nfields instead of asking operators to guess UUIDs.\n\nData:\n- data/reference/body-templ\n[…]\nthe current dataset: 102/114 models get an\nExampleBody, 4 get Enums (style_id from the 5-item styles catalog).\nRemaining 12 models had no on-disk template — they still render via\nthe legacy heuristic.",
"is_bot": false,
"headline": "feat(schema): ship body-templates + catalogs, schema-driven playground",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T20:59:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e39abb9641466def3b37daea05d4b9d9d1d0d855",
"body": "Previously, when Upstream.CreateJob failed on the sync path (stale\nsession 401, body error 422, rate limit 429, 5xx), the request was\ncompletely invisible in the dashboard — Failover recorded the error but\nno jobs row or usage_events row was ever written. Operators only saw\nthe pool getting hammered\n[…]\nnd on the jobs backfill\nstep — 'cf' rows have no matching jobs row by design.\n\nThe async / poll-timeout paths already record via pollworker; this\npatch closes the last unmetered exit in the sync path.",
"is_bot": false,
"headline": "fix(proxy): record usage_event for sync CreateJob failures",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T18:23:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "19160297d46893eac50cbd8ae8bbc0b7d12eca1e",
"body": "Previously, metering.OnJobTerminal only wrote to usage_events. The jobs\ntable's actual_credits_h and charged_credits_h columns stayed NULL\nforever, so /admin/jobs and per-job UIs showed cost=0 on every\ncompleted job even though usage aggregation (which reads from\nusage_events) reported the correct t\n[…]\n, back-fill both columns\nvia UpdateStatus immediately after the usage_events insert. Wire it\nfrom main.go with the existing jobStore. Best-effort — errors are\nlogged and do not fail the metering path.",
"is_bot": false,
"headline": "fix(metering): back-fill actual/charged credits on jobs row",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T17:59:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29bfa44618c1079a8f3f0c4670856fbe3489931e",
"body": null,
"is_bot": false,
"headline": "fix(webui): add missing i18next dependencies",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T17:30:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "657ca5470e257589a314cdeb202d575a126f6338",
"body": null,
"is_bot": false,
"headline": "ci: fix pnpm build — use .npmrc for onlyBuiltDependencies + pin pnpm@10",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T17:28:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7d8f50ecfe0226653f95556610519bd09647e8c",
"body": null,
"is_bot": false,
"headline": "fix(webui): declare esbuild+oxlint in pnpm.onlyBuiltDependencies for CI",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T17:13:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0ed4aa210a2a9b562fd362651ffe7958c62578b1",
"body": null,
"is_bot": false,
"headline": "ci(release): add pnpm webui build step before Go compilation",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T16:54:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad2802159e8d4fd7771db70f928f3b1116eac82b",
"body": null,
"is_bot": false,
"headline": "docs+test: fix API_REFERENCE discrepancies + registrations test coverage",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T16:52:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3531c3e312e39c4c3af425b3c289d7db2a3784ef",
"body": "…f 401\n\nWhen optional=true and the Authorization header carries a token that\nfails apikey.Parse (e.g. an admin bearer), treat it as 'no key present'\nand continue to the next handler. Previously the middleware returned 401\nwhich caused the WebUI Models page to auto-logout (the SPA's request()\nwrapper clears the bearer on any 401).",
"is_bot": false,
"headline": "fix(middleware): optional APIKeyAuth skips non-sk-hg tokens instead o…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T16:52:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4eebfb26dbc002885fb913ab2608838138ebf2c5",
"body": "Pool collector and pollworker ListPending both crashed with:\n sql: Scan error on column index 17, name \"latency_ms\":\n converting NULL to int64 is unsupported\nwhenever the jobs table had a pending / running row (latency_ms\nis only stamped at the terminal transition — see UpdateStatus at\njob_store.g\n[…]\n,\nso both get the same treatment for safety.\n\nNo behavior change on rows with values set. Existing tests keep\npassing (latency + poll_count writers already gate on > 0 before\nincluding in the UPDATE).",
"is_bot": false,
"headline": "fix(sqlite/jobs): NULL latency_ms + poll_count in scanJob",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T05:23:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d8be442525cf7a92067abd98b14f219c16197f2",
"body": "Closes the actual gap that made 'not able to register in UI' true:\nthe Node driver required password + mailbox_config, but neither\nfield was in ports.RegistrationRequest, on the admin handler's\nbody, in the sqlite row, in the WebUI dialog, or on the bridge's\nplugin RegisterRequest. Every layer neede\n[…]\n+ OTP through a\nlive outlook mailbox — that requires an operator machine with\nPlaywright browsers installed and a valid Graph refresh token\nthat hasn't expired. The commit unblocks that operator test.",
"is_bot": false,
"headline": "feat(registrar): P4-3d — password + per-row mailbox creds + bulk import",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T03:02:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c217996557f8ca505b97805afa8c5fb354ea389",
"body": "The old port collided with sibling projects (claudego uses 5273, but\nits --port 5173 override took the same slot). Vite silently auto-\nincremented higgsgo's server to 5174/5175 while the browser tab we\nwere opening at :5173 kept serving the OTHER project's SPA. That's\nwhat looked like 'the page just\n[…]\ntrictPort: true — refuse to auto-increment. If 5373 is taken\n we now fail loudly ('Port 5373 is in use') instead of drifting\n to some other port that the developer's browser tabs don't know\n about.",
"is_bot": false,
"headline": "fix(webui/vite): move dev port from 5173 to 5373 + strictPort",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-19T02:02:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0afd18441e64d43981747735a38813ad50b7fad",
"body": "- overview-kpis.tsx: remove unused useTranslation in Tile.\n- code-examples.tsx: mark unused path param with underscore prefix.\n- playground.tsx: PlaygroundModel.model_alias doesn't exist; use id.\n\nDev server (Vite HMR) doesn't strict-check unused vars so this\nregressed silently. 'pnpm build' catches them via tsc -b.",
"is_bot": false,
"headline": "fix(webui): three TS errors blocking pnpm build",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T19:21:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba5f6b77c22025f0e129e07c0f7c1691892f843a",
"body": "The Registrations page was rendering everything correctly but the\n'New registration' button was hardcoded disabled with a title-only\nhint, so operators had no way to trigger the flow from the UI even\nunder -tags register builds. Follow-up to P4-3c: the backend now\nlands accounts on success but the U\n[…]\nied}, columns.actions.\n\nNo API changes — admin.enqueueRegistration + admin.retryRegistration\nwere already wired in webui/src/lib/api.ts from the P4-2 batch;\nthis commit just consumes them from the UI.",
"is_bot": false,
"headline": "fix(webui/registrations): enable Enqueue dialog + row-level Retry",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T19:12:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5035ada33e6261dc2b0b68f09753344fdba7e036",
"body": "…ANGELOG\n\nReflects the P4-1/2/3a/3b/3c commits that closed all five ROADMAP §5.4\nitems. Documentation-only: no code touched.\n\ndocs/ROADMAP.md §5:\n- §5.3 flipped from a ❌-heavy status list dated 2026-07-18 to a\n ✅-across-the-board state dated 2026-07-19, with commit hashes for\n every landed step (a\n[…]\nease-notes cut can bisect. 'Also in this window' captures\nthe card-footer button label fix that landed alongside.\n\nNo code changes; go test ./... and go test -tags register ./...\nstill pass unchanged.",
"is_bot": false,
"headline": "docs: P4 registration plugin end-to-end — ROADMAP §5, ARCH §11a.8, CH…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T19:01:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7645f28b8551bda19edf6613165aaffadce49a8",
"body": "… row\n\nCloses the loop: when the Node driver reports a completed\nregistration, storeAdapter.MarkCompleted now upserts a fully-populated\ndomain.Account before flipping the registrations row to success.\nWithout this, a green /register returned an account_id that pointed\nat nothing — the produced crede\n[…]\n ./... (slim)\n- go build -tags register ./... (full)\n- go test ./... (all)\n- go test -tags register ./... (all incl. new upsert_test.go)",
"is_bot": false,
"headline": "feat(registrar): P4-3c — successful registration lands a real Account…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:59:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b8899edab2fdcc9ee06cebde727d1b435b2d2507",
"body": "…egister\n\nEnd-to-end wire from the Go registrar all the way to a live Node\ndriver process. Runs (and shuts down cleanly) locally today; real\nsignup awaits a mailbox_config being wired via env.\n\nplugins/register/driver-node/index.mjs (new):\n- HTTP server on 127.0.0.1:<port>. Endpoints:\n GET /read\n[…]\nfield-register/src changes to expose\n waitForOtp with the exact call shape driver-node/index.mjs\n invokes it with. Documented in-index.mjs.\n- ARCHITECTURE.md §11a and ROADMAP §5.4 updates land next.",
"is_bot": false,
"headline": "feat(registrar): P4-3b — Node subprocess driver bridging higgsfield-r…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:51:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df62cbdb40efaf8bc580f88293835b9dc7f02166",
"body": "…mock\n\nGroundwork for the Node subprocess bridge: introduces a higher-level\nDriver interface that lets Flow.Execute delegate the whole\nregistration to a single Register() call instead of orchestrating\nsession-level DOM operations in Go.\n\nWhy this shape:\nThe existing higgsfield-register Node project \n[…]\n..\n\nNext: adapters/camoufox/driver_node.go spawns the Node subprocess\nand implements Driver.Register over HTTP. That commit will land\nalongside the Node driver in higgsfield-register/register-driver/.",
"is_bot": false,
"headline": "feat(registrar): P4-3b step 1 — Driver interface + Flow delegation + …",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:47:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bb21923df71011a1e9f245576856c80d8f7f27bd",
"body": "Two admin-list-shaped store methods that finally close the TODOs\nhiggsfield.storeAdapter carried from P4-2:\n- List: newest-first row scan with status / since / limit / offset\n filters pushed into SQL. Limit capped at 200 by the adapter.\n- ResetToPending: flips any row back to pending so admin Retry\n[…]\nox/adapter.go — actually driving\nthe Node subprocess is a separate P4-3b (Go ↔ Node JSON-RPC bridge)\nworth its own commit. This P4-3a lands the store extensions so\nthat work can proceed independently.",
"is_bot": false,
"headline": "feat(registrar): P4-3a — ports.RegistrationStore.List + ResetToPending",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:21:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "31ff48c6d314e9c2a1a0e2b360b3cb49d959878d",
"body": "… docs\n\nImplements ROADMAP §5.4 step 3: the -tags register build of\nhiggsfield.NewRegistrar now delegates to plugins/register through a\nstoreAdapter, instead of panicking on every method call. See\ndocs/PLUGGABLE.md §0 for the monorepo split this respects.\n\nWhy this path and not a main-module rewrite\n[…]\nthe admin surface returns\n real rows instead of the current [] placeholder.\n- ports.RegistrationStore.ResetToPending for Retry — today the\n storeAdapter.Retry path returns a 'not implemented' error.",
"is_bot": false,
"headline": "feat(registrar): P4-2 — higgsfield.go bridges to plugins/register per…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:14:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a854ef77c0524cf9fc7a76ac0a9dc539c628a898",
"body": "Adds the missing CRUD adapter for the registrations table that has\nbeen sitting in migration 001 since day one. Before this the admin\nPOST /admin/registrations handler had a Registrar interface, an\nendpoint, and a UI — but no way to persist a pending row.\n\nImplements ports.RegistrationStore end-to-e\n[…]\nield.go delegates to plugins/register or\n implements Deps directly in-tree.\n2. Wire a background worker in main.go that consumes NextPending.\n3. Provide at least one BrowserAutomator (mock for now).",
"is_bot": false,
"headline": "feat(registrar): P4-1 — SQLite RegistrationStore",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:05:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9f4b83c6e0a31ad0f834804cf80747d44778e63f",
"body": "P2-6's probe wiring accidentally regressed the card footer to\nicon-only. Small cards were fine but wide cards (@5xl/@7xl grid\nbreakpoints) had no reason to hide labels — the pre-fix layout had\n'Detail / Refresh / Health / More' labels visible whenever there was\nroom.\n\nFix: add @container/acccard to \n[…]\n or wider the\nlabels come back automatically; narrower cards keep the icon-only\ndegradation from P2-6 so text can't overflow.\n\nSame pattern applied to the More dropdown trigger for visual\nconsistency.",
"is_bot": false,
"headline": "fix(webui/accounts): restore footer button labels on wide cards",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T18:03:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3199e981a85749fe230e65237b1ef4661d9e8644",
"body": "Closes the audit → delivery loop that ran through July 2026 with two\ndocs updates:\n\nCHANGELOG.md gets an 'Audit → Delivery Cycle' section at the top of\n[Unreleased] that indexes all 12 fixes (P0-1 through P3-13) by\nsubsystem — Pool correctness, WebUI honesty, Documentation refresh.\nEach entry names \n[…]\np\nfor when they wonder 'why is there a jitter tail on every ORDER BY'\nor 'when did probe stop being a fake toast'. ROADMAP.md remains the\nauthoritative live status; this file is frozen at cycle close.",
"is_bot": false,
"headline": "docs: CHANGELOG audit-cycle section + AUDIT-CYCLE.md milestone",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:52:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb87a474148be58fa34363585c513e1bf49eb542",
"body": "Closes the last honesty gap the audit surfaced. Since P2-7 the WebUI\nhad stopped fabricating fake uptime numbers, but the per-slot bar\nstill fell back to generateEmptySlots because we had no backend\nsurface for time-series probe data. That surface exists now, and the\ndetail sheet consumes it.\n\nInter\n[…]\n in\ninternal/api/admin/model_health_test.go and\ninternal/core/regression/regression_test.go gain a minimal\nSlotsByJST implementation so the ports.ModelHealthStore compile-\ntime assertion still passes.",
"is_bot": false,
"headline": "feat(pool): P3-13 — real per-slot uptime data replaces WebUI placeholder",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:43:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "feec5d8e22594a30f68ebdbdc22d9a763811f7ff",
"body": "Before: an API key bound to multiple groups returned 400 ambiguous_group\nand forced the caller to pick one via the request body. That flat-out\nprevented an operator from expressing 'try primary, fall back to\noverflow' at the key-binding layer.\n\nNow: resolveGroup returns the ordered candidate list. M\n[…]\nssertions now check the returned\n candidate slice shape. MultiBinding test case flipped from\n 'ambiguous_group httpError' to 'sorted [g1, g2] list'.\n\nDocs: ROADMAP §10 and POOL-AND-CPA §7.3 updated.",
"is_bot": false,
"headline": "feat(pool): P3-10 — cross-group spillover for multi-binding API keys",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:22:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c588f763e9b7632c04799a410668fa396f96106",
"body": "Closes the last stored-but-not-enforced field from the audit table.\nBefore this, api_keys.monthly_quota + monthly_used were only checked\nin metering.Recorder AFTER a job had already been created upstream\nand returned to the caller. That meant a downstream integration that\nhit its cap could keep firi\n[…]\nefs.\n- ROADMAP §4 note updated: APIKey.MonthlyLimit moved from 'deferred'\n to 'done'; per-key regex + rate limits remain deferred (need\n domain.APIKey struct + migrations that aren't in scope here).",
"is_bot": false,
"headline": "feat(pool): P2-9 — enforce per-Key monthly quota pre-pick",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:13:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50142d34a7bbdf902f313c3cdbafe309b1a64194",
"body": "Before this change, in_flight_jobs measured 'account acquisition\nthrough CreateJob' only. The moment an async job's CreateJob call\nreturned, the proxy's async branch called unlock() and the slot was\nfree — even though upstream was still running the job for the next\n30-40 minutes. That defeated the g\n[…]\nps 1 → 0 on deadline\n even without contacting upstream.\n- HoldsInFlightWhileFetchTerminalRetries — counter stays at 1\n when FetchJob transiently fails, so retry logic doesn't\n double-book the slot.",
"is_bot": false,
"headline": "feat(pool): P3-11 — async job in_flight tracking across full lifecycle",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:07:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04bec6c541896663b6c9496694547904af3ec115",
"body": "Every RouteStrategy's ORDER BY now ends with ', in_flight_jobs ASC,\nRANDOM() LIMIT 1'. Fixes the hot-spot documented in the audit: when\nseveral accounts tied on the primary sort key (identical\nlast_used_at, same plan_type, same priority) the same row won\nconsecutive picks until its last_used_at comm\n[…]\nds three\n otherwise-identical accounts, runs 30 picks with immediate\n unlock, asserts picks land on at least 2 of 3 rows. Would fail\n deterministically on the previous natural-row-order tiebreaker.",
"is_bot": false,
"headline": "feat(pool): P2-8 — jittered LRU tiebreaker in PickAndLock",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T17:07:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d2c3fc6df0f0d0424ae9332211d9754d08efbbd7",
"body": "…state\n\nRemoves the mockUptime() function that fabricated 95-100% uptime for\nevery model that had no /admin/model-health row. Rows without real\nprobe data now show an em dash + a muted gray bar with 'No data'\ntooltips; the detail sheet says 'No probe data yet — run the\nregression ticker to populate'\n[…]\neries data (success/fail counts per hour)\n remains a P3 backend addition; today's model-health surface\n provides one aggregate uptime_pct per JST, not the per-slot\n detail the bar was designed for.",
"is_bot": false,
"headline": "feat(webui/models): P2-7 — replace mock uptime with honest 'no data' …",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:57:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b9357abd6146610296c543832947da073d82f6b",
"body": "Replaces the empty toast-only 'health' button with an actual upstream\ncall. POST /admin/accounts/{id}/probe now exercises the same JWT\nminter, per-account HTTP client (P1-5), and JA3 fingerprint the pool\nuses in production, so a green probe is a strong signal that the\naccount still works end to end.\n[…]\noes NOT feed the failover controller.\nIts job is 'give me an honest read of this account right now', not\n'let me sway the pool from the admin UI'. Real traffic still drives\nthe failover state machine.",
"is_bot": false,
"headline": "feat(admin): P2-6 — real account probe endpoint",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:57:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ef33fbcb8de180e2f17f0b913858853742352f0c",
"body": "Wires the three remaining stored-but-never-enforced group fields into\nthe request path so admin edits to\nallowed_models_regex / blocked_models_regex / monthly_credit_budget\nactually shape traffic. Closes the last audit gap flagged in\ndocs/ROADMAP.md P1-4 (with per-Key gates deferred to P2 — see note\n[…]\nefs.\n- ROADMAP §P1-4 records the split: group gates ✅ done, per-Key gates\n deferred to P2 (would require threading APIKey into GenerationRequest).\n- POOL-AND-CPA §2.3 pick-logic SQL comments updated.",
"is_bot": false,
"headline": "feat(pool): P1-4 — enforce group model regex + monthly budget",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:44:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "24c19c535564bda6bae215de68784d01df87b898",
"body": "Wires account.bound_proxy_url into the request path. Every account now\negresses through its own sticky SOCKS5/HTTP proxy instead of sharing\nthe process-level HIGGSGO_UPSTREAM_PROXY_URL client. Fixes the\ncorrelation risk documented in the audit: Cloudflare / DataDome can\nno longer link accounts via s\n[…]\nwas documented as 'sticky proxy NOT\n wired', now documents the live implementation + failure modes.\n- ROADMAP §1 marks bound_proxy_url as ✅ enforced; §P1-5 has the file\n refs for future maintainers.",
"is_bot": false,
"headline": "feat(upstream): P1-5 — per-account HTTP client honoring bound_proxy_url",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:39:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e0047564e967c5f3709665a212a4586a7fe36caa",
"body": "Mark the three P0 items complete in the priority table and expand each\nwith the concrete file:line where the fix lives. Keeps §1's\n'stored but never enforced' table honest: max_concurrent_jobs and\nmax_concurrent_per_account are now ✅ enforced.\n\nRemaining P0 items: none. P1 is next (resolver wiring, per-account\nHTTP client honoring bound_proxy_url, allowed/blocked_models regex,\nmonthly_credit_budget enforcement).",
"is_bot": false,
"headline": "docs(roadmap): P0-1, P0-2, P0-3 all landed",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:20:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf4000af5be4291020d89fb8747542bf1a38533d",
"body": "…p concurrency caps\n\nThree related fixes that had to land together because they share the\nPickAndLock / unlock code path. See docs/ROADMAP.md P0-2 and P0-3.\n\nP0-2: leak-safe in_flight_jobs\n- proxy/service.go: the three hand-rolled unlock() sites (async\n release, error release, sync-poll release) ar\n[…]\n proves the cap\n overrides the historical 5.\n- TestAccountStore_ResetAllInFlight — proves selective reset (rows\n at 0 unchanged) and idempotence.\n- Existing pool group + regression tests still pass.",
"is_bot": false,
"headline": "feat(pool): P0-2 + P0-3 — leak-safe unlock, boot reconciliation, grou…",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:19:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32aa2a53bb367db0cb5cfeda8ac7c91754be458b",
"body": "The account_group_members.priority column has been read by PickAndLock\nunder route_strategy = 'priority' since day one, but the UI had no way\nto see or change it — every membership landed on the DB default of 100.\nThis commit closes the loop.\n\nBackend:\n- ports.GroupStore.ListMembersWithPriority — ne\n[…]\ny-selected groups with desired priority,\n (2) re-call addGroupMember (=upsert) on already-selected groups\n whose priority changed, (3) remove deselected groups.\n- i18n keys added for both en and zh.",
"is_bot": false,
"headline": "feat(groups): P0-1 — per-group member priority editable in the WebUI",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:19:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb32f6e43b9ccbc65107572c4a82972a38b833dd",
"body": "- webui/dist/ is generated by 'pnpm build' and embedded into the Go\n binary via //go:embed at build time — committing it would only\n duplicate the working tree.\n- .claude/ is Claude Code local session state (worktree bookkeeping,\n cached agent output). Per-developer, not part of the repo.",
"is_bot": false,
"headline": "chore(gitignore): ignore webui/dist and .claude/",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1036ad2befa56c330a30736a572e451eb1e06bce",
"body": "- scripts/build.sh — local build mirror of the release workflow's\n ldflags trio so 'go run' vs 'docker build' vs release binaries all\n report the same version/commit/build_time.\n- scripts/seed-mock-usage.py — dev-only seeder that hangs synthetic\n jobs + usage_events off existing accounts/api_keys/groups so the\n WebUI dashboard, jobs, and usage pages have realistic data to\n render before any real traffic. --wipe removes ONLY the synthetic\n rows.",
"is_bot": false,
"headline": "chore(scripts): local build + dev-only mock-usage seeder",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7a2071c6cec59203ec46f4d0139e498f0800741",
"body": "Refreshed data/reference/verified-models.json (upstream metadata\ndrift for ~40 aliases: costs, plan gates, defaults, some new keys).\nscripts/dump-verified-models.mjs updated to match the newer upstream\nresponse shape.\n\nThis is the on-disk base for the model registry — see ARCHITECTURE\n§11a.4 for how it composes with extras + runtime overrides.",
"is_bot": false,
"headline": "chore(models): refresh verified-models snapshot + dump script",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea4dd8016c06716f84254362700b489535926309",
"body": "Feed internal/version at link time so /admin/version and the WebUI\nfooter display a real build identity instead of 'dev / none /\nunknown'.\n\n- release.yml computes LDFLAGS with -X for\n internal/version.{Version,Commit,BuildTime}\n and passes them as docker build-args for the docker/build-push\n st\n[…]\n- Dockerfile accepts VERSION / COMMIT / BUILD_TIME build args and\n applies the same -X flags.\n- docker-compose adds the same three args so a local 'docker\n compose build' produces a matching binary.",
"is_bot": false,
"headline": "chore(release): inject version + commit + build_time via ldflags",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "55625538a49c938ed1c761df3c1cf54ab90d263e",
"body": "Expose the new modules' knobs in the example + dev configs:\n\n- [pool.failover]\n fail_limit / judge_window / evict_window / cooldown /\n outage_guard — governs the failover controller's disable +\n throttle behavior (see ARCHITECTURE §11a.1).\n- [updates]\n check_enabled — gates only the outbound GitHub release check;\n /admin/version stays mounted regardless.",
"is_bot": false,
"headline": "chore(config): add [pool.failover] + [updates] sections",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df66a5b494ce4237fb2e468a7ef309f478d723ef",
"body": "Wires the modules landed in the previous ten commits into main.go,\nserver.go, middleware, and the shared storage / handler layer. Every\nindividual module was already tested in isolation; this commit is\nwhat turns them on.\n\nmain.go / server.go / middleware / config:\n- Construct SettingsStore, BearerM\n[…]\nel-specs-extra.json) —\n see ARCHITECTURE §11a.4 for the base < extras < overrides order.\n\nTests updated: e2e, refresher, regression, pool_collector,\npollworker, cpaplugin — all green (go test ./...).",
"is_bot": false,
"headline": "feat(wiring): plug post-v0.1 modules into the request path",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:01:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ac205e2041e261fb5615bd79ec5093c0f9499360",
"body": "Introduces the plugins/register sub-module and the top-level\ngo.work file that binds it to the main module for local development.\n\nLayout:\n higgsgo/\n ├── go.work ← binds both modules\n ├── go.mod ← github.com/greensheep999/higgsgo\n └── plugins/regist\n[…]\n(monorepo binding) while\nkeeping go.work.sum per-developer.\n\n'go build ./plugins/register/...' compiles cleanly. No tests yet;\nROADMAP §5.4 lists the outstanding work to reach end-to-end\nregistration.",
"is_bot": false,
"headline": "feat(plugins): monorepo split — register plugin as sibling Go module",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T16:00:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "39ba8d610770e3ab97d1d93a0cfa18463dc2d864",
"body": "internal/core/resolver/ implements the correct precedence for\nper-request effective config (Key > Group > Account > Global), but\ngrep -rn 'core/resolver' returns zero external importers in\nproduction code — it's currently dead weight.\n\nThis commit preserves the code untouched so:\n- The tests keep ru\n[…]\nnforce the six 'silent no-op' group fields\n(AllowedModelsRegex, BlockedModelsRegex, MaxConcurrentJobs,\nMaxConcurrentPerAccount, MonthlyCreditBudget, plus per-account\nbound_proxy_url) via this package.",
"is_bot": false,
"headline": "chore(resolver): commit unwired config-cascade engine as-is",
"author_name": "higgsgo-ops",
"author_login": null,
"committed_at": "2026-07-18T15:59:27Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 23,
"commits_last_year": 171,
"latest_release_at": "2026-07-25T11:40:44Z",
"latest_release_tag": "v0.7.2",
"releases_from_tags": true,
"days_since_last_push": 1,
"active_weeks_last_year": 2,
"days_since_latest_release": 1,
"mean_days_between_releases": 0.6
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/greensheep999/higgsgo",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/greensheep999/higgsgo",
"is_deprecated": false,
"latest_version": "v0.7.2",
"repository_url": "https://github.com/greensheep999/higgsgo",
"versions_count": 23,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-25T11:40:44Z",
"latest_version_yanked": null,
"days_since_latest_publish": 1
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"webui/tsconfig.json"
],
"toolchain_manifests": [
"go.mod",
"plugins/register/go.mod"
],
"largest_source_bytes": 69278,
"source_files_sampled": 393,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod",
"webui/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/go-chi/chi/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.3.1"
},
{
"name": "github.com/greensheep999/higgsgo/plugins/register",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260720192154-0061d338f1c9"
},
{
"name": "github.com/pelletier/go-toml/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.3"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.2"
},
{
"name": "github.com/prometheus/client_model",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/refraction-networking/utls",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.2"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.57.0"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.54.0"
},
{
"name": "@dnd-kit/core",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^6.3.1"
},
{
"name": "@dnd-kit/modifiers",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^9.0.0"
},
{
"name": "@dnd-kit/sortable",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^10.0.0"
},
{
"name": "@dnd-kit/utilities",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.2.2"
},
{
"name": "@hookform/resolvers",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.0"
},
{
"name": "@lobehub/icons",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^5.14.0"
},
{
"name": "@tabler/icons-react",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.45.0"
},
{
"name": "@tanstack/react-query",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^5.101.2"
},
{
"name": "@tanstack/react-router",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.170.18"
},
{
"name": "@tanstack/react-table",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^8.21.3"
},
{
"name": "class-variance-authority",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.7.1"
},
{
"name": "clsx",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.1"
},
{
"name": "cmdk",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "date-fns",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.0"
},
{
"name": "i18next",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^26.3.6"
},
{
"name": "i18next-browser-languagedetector",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^8.2.1"
},
{
"name": "lucide-react",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.25.0"
},
{
"name": "next-themes",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.4.6"
},
{
"name": "radix-ui",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.2"
},
{
"name": "react",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.7"
},
{
"name": "react-day-picker",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^10.0.1"
},
{
"name": "react-dom",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.7"
},
{
"name": "react-hook-form",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^7.81.0"
},
{
"name": "react-i18next",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^17.0.10"
},
{
"name": "recharts",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "3.8.0"
},
{
"name": "sonner",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.7"
},
{
"name": "tailwind-merge",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.6.0"
},
{
"name": "tailwindcss",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.3"
},
{
"name": "tw-animate-css",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.4.0"
},
{
"name": "vaul",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.2"
},
{
"name": "zod",
"manifest": "webui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.3"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 6,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "greenSheep999",
"commits": 50,
"avatar_url": "https://avatars.githubusercontent.com/u/301825685?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/23 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 6,
"reason": "4 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "970e4a9e9d0f961a33d0ff611de53be666923c29",
"ran_at": "2026-07-27T06:36:47Z",
"aggregate_score": 2.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T12:00:33Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-21T13:00:55Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/greenSheep999/higgsgo",
"host": "github.com",
"name": "higgsgo",
"owner": "greenSheep999"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"security": 29,
"vitality": 68,
"community": 24,
"governance": 47,
"engineering": 67
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 68,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"commits_last_year": 171,
"human_commit_share": 1,
"days_since_last_push": 1,
"active_weeks_last_year": 2
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "2/52 weeks with commits",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 2
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "171 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 171
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 23,
"latest_release_tag": "v0.7.2",
"releases_from_tags": true,
"days_since_latest_release": 1,
"mean_days_between_releases": 0.6
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "23 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 23
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.6 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.6
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 24,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 47,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 6,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "6/6 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 6,
"decided": 6
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/23 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "critical",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 24,
"inputs": {
"followers": 2,
"owner_type": "User",
"is_verified": null,
"owner_login": "greenSheep999",
"public_repos": 5,
"account_age_days": 17
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "2 followers of greenSheep999",
"points": 3.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 2,
"login": "greenSheep999"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "5 public repos, account ~0 yr old",
"points": 5.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 5
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/greensheep999/higgsgo"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 1
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 1 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 1
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "23 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 23
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 67,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 29,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 29,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 2.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/23 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "4 existing vulnerabilities detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 58,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.99,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 99,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 56,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"pnpm-lock.yaml"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"webui/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod",
"plugins/register/go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "go.mod, plugins/register/go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "go.mod, plugins/register/go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "webui/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "webui/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 69278,
"source_files_sampled": 393,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/393 source files over 60KB",
"points": 54.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 393,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-27T06:36:55.720436Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/greenSheep999/higgsgo.svg",
"full_name": "greenSheep999/higgsgo",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}