Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 2042,
"has_wiki": true,
"homepage": null,
"languages": {
"Shell": 281,
"Python": 1173735,
"Makefile": 2545,
"Dockerfile": 4950
},
"pushed_at": "2026-07-24T18:38:40Z",
"created_at": "2026-03-17T16:55:12Z",
"owner_type": "Organization",
"updated_at": "2026-07-03T06:12:34Z",
"description": "Provides the underlying framework to enhance langchain and add loading configurations",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": "https://www.bwell.com",
"name": "b.well",
"type": "Organization",
"login": "icanbwell",
"company": null,
"location": "Baltimore, MD",
"followers": 39,
"avatar_url": "https://avatars.githubusercontent.com/u/12889347?v=4",
"created_at": "2015-06-15T04:11:59Z",
"is_verified": null,
"public_repos": 84,
"account_age_days": 4057
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "2.0.91",
"kind": "patch",
"published_at": "2026-07-24T18:38:40Z"
},
{
"tag": "2.0.90",
"kind": "patch",
"published_at": "2026-07-24T17:04:32Z"
},
{
"tag": "2.0.89",
"kind": "patch",
"published_at": "2026-07-23T04:27:36Z"
},
{
"tag": "2.0.88",
"kind": "patch",
"published_at": "2026-07-03T06:12:53Z"
},
{
"tag": "2.0.87",
"kind": "patch",
"published_at": "2026-07-03T04:16:23Z"
},
{
"tag": "2.0.86",
"kind": "patch",
"published_at": "2026-06-17T15:09:24Z"
},
{
"tag": "2.0.85",
"kind": "patch",
"published_at": "2026-06-17T04:56:55Z"
},
{
"tag": "2.0.84",
"kind": "patch",
"published_at": "2026-06-16T19:03:42Z"
},
{
"tag": "2.0.83",
"kind": "patch",
"published_at": "2026-06-12T13:36:31Z"
},
{
"tag": "2.0.82",
"kind": "patch",
"published_at": "2026-06-11T04:42:43Z"
},
{
"tag": "2.0.81",
"kind": "patch",
"published_at": "2026-06-10T14:38:20Z"
},
{
"tag": "2.0.80",
"kind": "patch",
"published_at": "2026-06-10T06:25:02Z"
},
{
"tag": "2.0.79",
"kind": "patch",
"published_at": "2026-06-09T21:20:59Z"
},
{
"tag": "2.0.78",
"kind": "patch",
"published_at": "2026-06-09T20:23:12Z"
},
{
"tag": "2.0.77",
"kind": "patch",
"published_at": "2026-06-09T16:33:22Z"
},
{
"tag": "2.0.76",
"kind": "patch",
"published_at": "2026-06-09T05:06:15Z"
},
{
"tag": "2.0.75",
"kind": "patch",
"published_at": "2026-06-08T19:42:40Z"
},
{
"tag": "2.0.74",
"kind": "patch",
"published_at": "2026-06-08T03:27:13Z"
},
{
"tag": "2.0.73",
"kind": "patch",
"published_at": "2026-06-04T20:52:45Z"
},
{
"tag": "2.0.72",
"kind": "patch",
"published_at": "2026-06-04T14:21:21Z"
},
{
"tag": "2.0.71",
"kind": "patch",
"published_at": "2026-06-04T04:54:54Z"
},
{
"tag": "2.0.70",
"kind": "patch",
"published_at": "2026-06-03T13:34:54Z"
},
{
"tag": "2.0.69",
"kind": "patch",
"published_at": "2026-06-03T02:54:28Z"
},
{
"tag": "2.0.68",
"kind": "patch",
"published_at": "2026-06-03T02:14:51Z"
},
{
"tag": "2.0.67",
"kind": "patch",
"published_at": "2026-06-03T00:28:22Z"
},
{
"tag": "2.0.66",
"kind": "patch",
"published_at": "2026-06-02T19:54:48Z"
},
{
"tag": "2.0.65",
"kind": "patch",
"published_at": "2026-06-01T19:02:21Z"
},
{
"tag": "2.0.64",
"kind": "patch",
"published_at": "2026-05-30T03:21:31Z"
},
{
"tag": "2.0.63",
"kind": "patch",
"published_at": "2026-05-29T22:14:01Z"
},
{
"tag": "2.0.62",
"kind": "patch",
"published_at": "2026-05-29T19:26:29Z"
},
{
"tag": "2.0.61",
"kind": "patch",
"published_at": "2026-05-29T18:34:44Z"
},
{
"tag": "2.0.60",
"kind": "patch",
"published_at": "2026-05-29T15:01:56Z"
},
{
"tag": "2.0.59",
"kind": "patch",
"published_at": "2026-05-29T05:18:07Z"
},
{
"tag": "2.0.58",
"kind": "patch",
"published_at": "2026-05-29T03:48:21Z"
},
{
"tag": "2.0.57",
"kind": "patch",
"published_at": "2026-05-29T02:13:11Z"
},
{
"tag": "2.0.56",
"kind": "patch",
"published_at": "2026-05-28T22:02:15Z"
},
{
"tag": "2.0.55",
"kind": "patch",
"published_at": "2026-05-28T21:33:51Z"
},
{
"tag": "2.0.54",
"kind": "patch",
"published_at": "2026-05-28T15:31:35Z"
},
{
"tag": "2.0.53",
"kind": "patch",
"published_at": "2026-05-27T23:27:11Z"
},
{
"tag": "2.0.52",
"kind": "patch",
"published_at": "2026-05-27T18:26:15Z"
},
{
"tag": "2.0.51",
"kind": "patch",
"published_at": "2026-05-27T16:30:12Z"
},
{
"tag": "2.0.50",
"kind": "patch",
"published_at": "2026-05-27T15:36:02Z"
},
{
"tag": "2.0.49",
"kind": "patch",
"published_at": "2026-05-27T05:39:31Z"
},
{
"tag": "2.0.48",
"kind": "patch",
"published_at": "2026-05-25T03:21:11Z"
},
{
"tag": "2.0.47",
"kind": "patch",
"published_at": "2026-05-22T20:40:28Z"
},
{
"tag": "2.0.46",
"kind": "patch",
"published_at": "2026-05-22T19:19:45Z"
},
{
"tag": "2.0.45",
"kind": "patch",
"published_at": "2026-05-21T16:56:17Z"
},
{
"tag": "2.0.44",
"kind": "patch",
"published_at": "2026-05-21T15:00:29Z"
},
{
"tag": "2.0.43",
"kind": "patch",
"published_at": "2026-05-21T04:51:25Z"
},
{
"tag": "2.0.42",
"kind": "patch",
"published_at": "2026-05-21T04:37:16Z"
},
{
"tag": "2.0.41",
"kind": "patch",
"published_at": "2026-05-18T03:45:00Z"
},
{
"tag": "2.0.40",
"kind": "patch",
"published_at": "2026-05-14T16:26:50Z"
},
{
"tag": "2.0.39",
"kind": "patch",
"published_at": "2026-05-14T04:09:58Z"
},
{
"tag": "2.0.38",
"kind": "patch",
"published_at": "2026-05-12T18:28:24Z"
},
{
"tag": "2.0.37",
"kind": "patch",
"published_at": "2026-05-11T19:27:03Z"
},
{
"tag": "2.0.36",
"kind": "patch",
"published_at": "2026-05-06T17:28:26Z"
},
{
"tag": "2.0.35",
"kind": "patch",
"published_at": "2026-05-06T00:26:47Z"
},
{
"tag": "2.0.34",
"kind": "patch",
"published_at": "2026-05-05T02:57:43Z"
},
{
"tag": "2.0.33",
"kind": "patch",
"published_at": "2026-05-04T16:16:23Z"
},
{
"tag": "2.0.32",
"kind": "patch",
"published_at": "2026-04-25T03:02:38Z"
},
{
"tag": "2.0.31",
"kind": "patch",
"published_at": "2026-04-23T02:08:08Z"
},
{
"tag": "2.0.30",
"kind": "patch",
"published_at": "2026-04-22T22:08:48Z"
},
{
"tag": "2.0.29",
"kind": "patch",
"published_at": "2026-04-21T20:17:00Z"
},
{
"tag": "2.0.28",
"kind": "patch",
"published_at": "2026-04-21T19:13:37Z"
},
{
"tag": "2.0.27",
"kind": "patch",
"published_at": "2026-04-21T17:34:40Z"
},
{
"tag": "2.0.26",
"kind": "patch",
"published_at": "2026-04-21T15:59:29Z"
},
{
"tag": "2.0.25",
"kind": "patch",
"published_at": "2026-04-20T23:24:15Z"
},
{
"tag": "2.0.24",
"kind": "patch",
"published_at": "2026-04-19T18:16:12Z"
},
{
"tag": "2.0.23",
"kind": "patch",
"published_at": "2026-04-18T23:04:14Z"
},
{
"tag": "2.0.22",
"kind": "patch",
"published_at": "2026-04-17T19:10:35Z"
},
{
"tag": "2.0.21",
"kind": "patch",
"published_at": "2026-04-17T15:53:47Z"
},
{
"tag": "2.0.20",
"kind": "patch",
"published_at": "2026-04-16T02:42:47Z"
},
{
"tag": "2.0.19",
"kind": "patch",
"published_at": "2026-04-15T18:55:10Z"
},
{
"tag": "2.0.18",
"kind": "patch",
"published_at": "2026-04-15T14:03:50Z"
},
{
"tag": "2.0.17",
"kind": "patch",
"published_at": "2026-04-14T22:47:16Z"
},
{
"tag": "2.0.16",
"kind": "patch",
"published_at": "2026-04-14T05:07:52Z"
},
{
"tag": "2.0.15",
"kind": "patch",
"published_at": "2026-04-14T03:48:20Z"
},
{
"tag": "2.0.14",
"kind": "patch",
"published_at": "2026-04-14T02:49:08Z"
},
{
"tag": "2.0.13",
"kind": "patch",
"published_at": "2026-04-13T03:08:29Z"
},
{
"tag": "2.0.12",
"kind": "patch",
"published_at": "2026-04-12T21:00:30Z"
},
{
"tag": "2.0.11",
"kind": "patch",
"published_at": "2026-04-12T19:02:55Z"
},
{
"tag": "2.0.10",
"kind": "patch",
"published_at": "2026-04-10T20:49:43Z"
},
{
"tag": "2.0.9",
"kind": "patch",
"published_at": "2026-04-09T14:48:00Z"
},
{
"tag": "2.0.8",
"kind": "patch",
"published_at": "2026-04-09T06:12:06Z"
},
{
"tag": "2.0.7",
"kind": "patch",
"published_at": "2026-04-08T17:30:56Z"
},
{
"tag": "2.0.6",
"kind": "patch",
"published_at": "2026-04-08T05:19:21Z"
},
{
"tag": "2.0.5",
"kind": "patch",
"published_at": "2026-04-08T02:33:25Z"
},
{
"tag": "2.0.4",
"kind": "patch",
"published_at": "2026-04-07T05:04:56Z"
},
{
"tag": "2.0.3",
"kind": "patch",
"published_at": "2026-04-06T22:50:36Z"
},
{
"tag": "2.0.2",
"kind": "patch",
"published_at": "2026-04-06T15:34:32Z"
},
{
"tag": "2.0.1",
"kind": "patch",
"published_at": "2026-04-06T03:44:01Z"
},
{
"tag": "2.0.0",
"kind": "major",
"published_at": "2026-04-06T02:35:57Z"
},
{
"tag": "1.0.36",
"kind": "patch",
"published_at": "2026-04-05T14:57:01Z"
},
{
"tag": "1.0.35",
"kind": "patch",
"published_at": "2026-04-04T01:48:19Z"
},
{
"tag": "1.0.34",
"kind": "patch",
"published_at": "2026-04-03T19:50:47Z"
},
{
"tag": "1.0.33",
"kind": "patch",
"published_at": "2026-04-03T05:29:27Z"
},
{
"tag": "1.0.32",
"kind": "patch",
"published_at": "2026-04-03T05:22:27Z"
},
{
"tag": "1.0.31",
"kind": "patch",
"published_at": "2026-04-02T17:18:18Z"
},
{
"tag": "1.0.30",
"kind": "patch",
"published_at": "2026-04-02T16:45:00Z"
},
{
"tag": "1.0.28",
"kind": "patch",
"published_at": "2026-04-01T22:42:48Z"
}
],
"recent_commits": [
{
"oid": "b5813feb19a1149992b1d2e8a5e10ab2b975e663",
"body": "BAI-290 catch BaseExceptionGroup from anyio TaskGroup in create_mcp_s…",
"is_bot": false,
"headline": "Merge pull request #53 from icanbwell/IQ-BAI-290",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-07-03T06:12:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53fe7443998e9f4116af17a4f20aa6883a4e955f",
"body": "…ession",
"is_bot": false,
"headline": "BAI-290 catch BaseExceptionGroup from anyio TaskGroup in create_mcp_s…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-07-02T18:20:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d5917f9d624ade33138b81c31b8d807b37128f8b",
"body": "BAI-262 Fix tool-progress newlines and KeyError on /reload",
"is_bot": false,
"headline": "Merge pull request #50 from icanbwell/IQ-BAI-262",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-17T15:09:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84c4e06a9e67b4db5c2744af277df75dd62562ca",
"body": "The branch is `return-appropriate-response-for-safety-scanning` (no JIRA ticket pattern present). The diff adds a new converter, environment variables module, a `RateLimitException`, and tests — the core theme being robust error classification and appropriate response handling for upstream failures \n[…]\nitException\ncarrying a Retry-After hint, retry-before-first-token with jittered\nbackoff, and context compaction on input-too-long. Includes the common\nenvironment variables module and converter tests.",
"is_bot": false,
"headline": "I'll write the commit message based on the staged changes.",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-17T04:50:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "778e849e626fad43fbcfea2aedad8960ed28fb23",
"body": null,
"is_bot": false,
"headline": "Add uv.lock files for baileyai and language-model-common",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-16T18:52:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc4525efbf942d82664221e4c6a2cb47d84f09a0",
"body": "- ToolDisplayNameMapper.get_message_for_tool now wraps with \\n\\n on both\n sides so Markdown chat UIs render the tool-progress line as its own\n paragraph instead of collapsing the soft break to a space.\n- McpToolListStore.clear catches the KeyError raised by py-key-value-aio's\n MongoDBStore.destroy_collection when the collection was never read or\n written (lazy _collections_by_name init). Surfaces as no-op rather than\n \"Code: 102\" to the user.",
"is_bot": false,
"headline": "BAI-262 fix tool-progress newlines and KeyError on /reload",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-16T18:47:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b789e6bab398c52abf218b59c7c9beb31f95dcb9",
"body": "Expose tool_choice, support label-only MCP refs, and unwrap streaming error responses",
"is_bot": false,
"headline": "Merge pull request #49 from icanbwell/iq-add-tool-choice-to-wrapper",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-12T13:36:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eccc6f89e68c54c7e06a501441077a74ffda52e7",
"body": "- Replace Optional[Any] return on tool_choice with str | dict[str, Any] | None\n so callers can branch on the structured shape without further widening;\n cast at the ChatCompletion site since OpenAI's TypedDict variants are dicts\n at runtime but mypy treats them as distinct.\n- Collapse extract_mcp\n[…]\n into one early-continue.\n- Parametrize tool_choice tests over None / \"none\" / \"auto\" / \"required\" /\n dict, and add coverage for the new label-only MCP mode plus the missing\n server_label skip path.",
"is_bot": false,
"headline": "Tighten tool_choice typing and simplify MCP extraction",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-11T04:38:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd601b5a8a15656af0427618586c9a41ba570e0c",
"body": "Propagate the caller-provided parallel_tool_calls into streaming and\nnon-streaming Response envelopes and expose tool_choice via the wrapper\nso downstream code can respect the request's tool selection preference.",
"is_bot": false,
"headline": "Honor tool_choice from request in ResponsesApiRequestWrapper",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-10T17:09:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fd302221f80cae9b4b2d52bdb3f81f94d31e904",
"body": "Introduces Pipeline class that runs pre-execution, execution, and\npost-execution steps against a shared PipelineContext, with separate\nstreaming and non-streaming entry points. Drains SSE content streams\ninto accumulated_content supporting both simple delta and OpenAI\nchoices[].delta.content formats, and unwraps StreamingResponse error\nresults so error bodies are yielded chunk-by-chunk during streaming.",
"is_bot": false,
"headline": "Add Pipeline orchestrator with streaming and error handling",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-10T14:32:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "118237d9eea9b84107144c830b36d22de197e583",
"body": "Both ResponsesRequest and the chat-completions ChatRequest schemas already\naccept a tool_choice field, but neither wrapper exposed it to callers, so\nconsumers (e.g. baileyai's AgentServiceFactory) had no way to read the\nclient's tool-binding preference from a unified interface.\n\nAdds tool_choice as \n[…]\n so callers can match on the string literals (\"none\", \"auto\",\n\"required\") or inspect the structured form without further widening.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Expose tool_choice on the abstract ChatRequestWrapper",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-10T06:05:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8e8311d5e2f9117afa82fa6e8dd9c2f498170389",
"body": "BAI-204 Add pipeline infrastructure and security utilities",
"is_bot": false,
"headline": "Merge pull request #47 from icanbwell/IQ-BAI-204",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T21:20:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c68815e211ffc7b81af7ce02650aa4cf4c37a16",
"body": "Introduces the foundational infrastructure for language-model-common:\n- Container factory with singleton registrations for all core services\n- GitHub App token provider with automatic refresh and caching\n- GitHubDirectoryHelper for resolving github:// URIs to local paths\n- Centralized environment variables class with typed property accessors\n- pyproject.toml with full dependency and tooling configuration\n\nIQ-BAI-204",
"is_bot": false,
"headline": "Add DI container factory, GitHub token provider, and environment config",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T20:17:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fe751aa37c92c979ceafa02ecf1b6e0cbc00708",
"body": "Migrate from legacy setup configuration to pyproject.toml with uv as the\npackage manager, defining all runtime and dev dependencies with version\nconstraints and tool configurations (pytest, mypy, ruff, setuptools).\n\nIQ-BAI-204",
"is_bot": false,
"headline": "Add pyproject.toml and uv.lock for uv-based dependency management",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T18:20:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c66030b8459d3a045bb386b0dbe0eef8a55937d",
"body": "…tests\n\n- Add * separator to all public functions in normalize.py,\n off_topic_detector.py, and prompt_extraction_detector.py\n- Consolidate duplicated REFUSAL_MESSAGE constant into normalize.py\n- Add parameterized unit tests for all security detection functions\n- Add _drain_stream SSE parsing tests for pipeline",
"is_bot": false,
"headline": "BAI-204 enforce keyword-only args in security detectors and add unit …",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T16:27:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b52fda10b65d6c76b21e4bdae459df32e81e1cf8",
"body": null,
"is_bot": false,
"headline": "BAI-204 add debug logging for skipped SSE events in _drain_stream",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T16:19:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d1f0733eb1643d116c3814dc475cb37f87ac605",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' into IQ-BAI-204",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T16:12:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a944ec6b639390b45e7585427655838bf8caa6c",
"body": "Bump aiohttp from 3.13.5 to 3.14.0",
"is_bot": false,
"headline": "Merge pull request #43 from icanbwell/dependabot/uv/aiohttp-3.14.0",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T16:12:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "255af4d103cf3842cfe46c9ce4a28f4b27e7223a",
"body": null,
"is_bot": false,
"headline": "BAI-204 fix _drain_stream to handle both SSE formats",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T16:02:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "07fa2152307ce5f3554ec182a2bf216c45b3d2d7",
"body": null,
"is_bot": false,
"headline": "BAI-204 drain content_stream in non-streaming pipeline path",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T15:57:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "647ca9f996ec33c29eb8725d210f8eb7855fefcc",
"body": null,
"is_bot": false,
"headline": "BAI-204 remove concrete step implementations (steps belong in baileyai)",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T15:38:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a30b4fd40639e1ce216872dba1658761fbf21bd8",
"body": "…ectors",
"is_bot": false,
"headline": "BAI-204 add InsertDatetimeStep and SecurityScanStep with security det…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T15:36:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7adab789c9229f0e3737b87d2d39faf78c26532d",
"body": null,
"is_bot": false,
"headline": "BAI-204 add pipeline infrastructure (context, step protocol, runner)",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T15:32:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e0d81964d516ec44d65fed7d690ebbebca8f4005",
"body": "… preprocessing\n\nIntroduces the core MCP infrastructure: MCPToolProvider for tool discovery\nand invocation with auth/tracing/truncation interceptors, AuthMcpCallInterceptor\nfor JWT token resolution at call time, request-scoped context variables for\nstream managers, and a composite message preprocessor with protocol definition.\n\nIQ-BAI-204",
"is_bot": false,
"headline": "Add MCP tool provider, auth interceptor, request context, and message…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-09T05:01:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "287e54dae2f4cd1a8b0ceddce22974e9799c4310",
"body": "* Add persistent MCP tool list store backed by py-key-value-aio\n\nImplements McpToolListStore that serializes MCPTool schemas to any\npy-key-value-aio backend (MongoDB, memory, etc.) with schema versioning\nfor safe deserialization. Entries persist until explicitly cleared via\n/reload, enabling tool li\n[…]\nhelpers. Wrap tool_list_cache reads in a fallback to prevent slash command\nregistration from failing when the cache is unavailable.\n\n* Add Makefile with Docker-based dev workflow and packaging targets",
"is_bot": false,
"headline": "Add schema versioning to config, prompt, and tool-list stores (#46)",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-08T19:26:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6892b5267764eea9c138dfac00e33bbbf5ad05d2",
"body": "…d-preprocessor\n\nBAI-190 add MessagePreprocessor protocol and ToolListCache.get_all_tool_names",
"is_bot": false,
"headline": "Merge pull request #42 from icanbwell/IQ-BAI-190-extract-slash-comman…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-04T20:52:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84f5b0400300a35fac1265f635e27cf94720961e",
"body": "Enables fetching static tool definitions from an MCP server's discovery\nendpoint without establishing a full session. Tries origin-level\n.well-known URL first (RFC 8615), then falls back to path-relative URL\nfor servers behind path-based gateways.",
"is_bot": false,
"headline": "Add MCP Server Card discovery via .well-known endpoint (SEP-1649)",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-04T06:11:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0ac588a944d4335b19a02033bc7caad1fc56e69b",
"body": "Introduce persistent tool list store backed by py-key-value-aio,\nan in-memory/persistent ToolListCache with TTL and pagination support,\nand a tool invocation module with interceptor chain and MCP task\nprotocol execution (supporting both old and new spec versions).",
"is_bot": false,
"headline": "Add MCP tool list caching and task-based tool invocation",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-04T04:49:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c52d4a88f49b0e94527de5c7961b87088bb314f9",
"body": "---\nupdated-dependencies:\n- dependency-name: aiohttp\n dependency-version: 3.14.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump aiohttp from 3.13.5 to 3.14.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-03T23:56:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbdc16016a83976e62a309d6117e84a5811b9694",
"body": "The ReloadCommandHandler was extracted to baileyai but docs still\nreferenced it as local. Updated file paths, code examples, and test\nlisting to point to the correct locations.",
"is_bot": false,
"headline": "BAI-190 fix docs to clarify reload handler lives in baileyai",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T21:00:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96fa95199faa0826cabcf1acd655985ba8e58cc2",
"body": "…olution",
"is_bot": false,
"headline": "BAI-190 add get_all_tool_names to ToolListCache for slash command res…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T17:33:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c9d4a923a3d316959e7d680f49fea0fc918172e",
"body": "Introduces a message preprocessing pipeline that intercepts /command\nprefixes before messages reach the LangGraph agent. Action commands\n(/reload, /reload-skills) short-circuit the LLM by raising\nSlashCommandActionComplete; content commands inject skill context as\nSystemMessages. Wires the preprocessor into BaileyAgentService via\nthe DI container with a reload callback that clears config and tool\ncaches.",
"is_bot": false,
"headline": "Add slash command preprocessor for /reload and skill injection",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T17:01:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09945b983a13b7f95d118329b2c1e2e1af47887e",
"body": "Explains architecture, handler types, and how to add new commands\nso future developers can extend the system without reading all source.\n\nIQ",
"is_bot": false,
"headline": "Add developer documentation for slash command system",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T16:48:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77ccb6f2f717e4065386ca6d755427e74972b613",
"body": "Introduces ReloadCommandHandler that maps slash commands to reload targets\n(models or skills), along with its effect type and tests. Updates the\nslash_command package __init__.py to export the new public API.",
"is_bot": false,
"headline": "Add reload command handler for /reload and /reload-skills slash commands",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T16:44:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5434caa152b40c20cdf2a48d6ab8524b4d3d0fee",
"body": "…on to 2.0.70\n\nDocument that direct commits to main are blocked and all changes require\na pull request. Bump language-model-common minimum version for slash\ncommand processor support.",
"is_bot": false,
"headline": "Add branch protection rules to AGENTS.md and bump language-model-comm…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T16:10:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f757188b0630875b408a9f1f2b8e35cd8c21742a",
"body": "…ssor\n\nGeneral-purpose abstractions for transforming message lists before they\nreach LangGraph execution. The protocol defines the contract; the\ncomposite chains multiple preprocessors in order.",
"is_bot": false,
"headline": "BAI-190 add MessagePreprocessor protocol and CompositeMessagePreproce…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T03:32:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0864619b00a7df933a6a6feffb36647a6d15745d",
"body": "BAI-190 add MCP Server Card discovery (SEP-1649 .well-known/mcp/serve…",
"is_bot": false,
"headline": "Merge pull request #40 from icanbwell/IQ-BAI-190",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T02:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "88276ebda3c4460e32a3a2bd7e0e10901b41c4ca",
"body": "Introduces a utility that resolves user-facing display names for tools\nduring streaming progress updates, supporting configurable names via\nJSON, MCP title extraction, and template placeholders with defaults.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper with parameter substitution support",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T01:55:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "076dd2b356b60c32ca83e6c32fec1603269c4db5",
"body": "Introduces a mapper that resolves tool names to display strings for\nstreaming progress updates, supporting JSON config files, MCP title\nextraction from tool metadata, and {param|default} template substitution.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool name resolution",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T01:46:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c37c1369f03b6b0849bb38007520714aee9cb9a4",
"body": "Introduces a utility that maps internal tool names to human-readable\ndisplay names with emoji prefixes, parameter substitution, and MCP\ntitle extraction. Includes comprehensive test coverage.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool progress names",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T01:38:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c20ddfcd73477ff6ffa7725724de000b3633e298",
"body": "Introduces a utility that resolves internal tool names to friendly\ndisplay names using a static JSON config and MCP tool metadata,\nwith emoji prefixing and humanized fallback.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool progress names",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-03T00:18:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af91913b83d0d61526eb0286f851834ca1b3df3d",
"body": "…dlers\n\nIntroduces a protocol-based slash command processing framework:\n- SlashCommandParser for regex-based /command extraction\n- SlashCommandProcessor with pluggable handlers\n- DebugCommandHandler (migrates existing DEBUG: prefix handling)\n- SkillCommandHandler with SkillContentResolver protocol\n- Refactors request wrappers to use new processor for /debug",
"is_bot": false,
"headline": "BAI-190 add slash command interceptor system with debug and skill han…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T23:56:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9c68c3d3019be3015d625ebca9ac03351710a74c",
"body": "…Mapper utility\n\nIQ-BAI-190: Introduce multi-stage Dockerfile that pre-downloads embedding,\nwhisper, and tiktoken models into the image. Add ToolDisplayNameMapper to\nresolve user-facing display names for tools during streaming progress updates,\nsupporting static config, MCP metadata, and humanized fallback naming.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add Open WebUI Dockerfile with model pre-download and ToolDisplayName…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T23:25:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2b5300fa24761d37a9665ed7074d7833efc3a05e",
"body": "…Mapper utility\n\nIQ-BAI-190: Introduce multi-stage Dockerfile that pre-downloads embedding,\nwhisper, and tiktoken models into the image. Add ToolDisplayNameMapper to\nresolve user-facing display names for tools during streaming progress updates,\nsupporting static config, MCP metadata, and humanized fallback naming.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add Open WebUI Dockerfile with model pre-download and ToolDisplayName…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T23:03:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "74225587c27b2a6b3e394fafbdad4dfc1119a78f",
"body": "Introduces a utility that maps internal tool names to human-readable\ndisplay names for streaming progress updates, supporting static JSON\nconfig, MCP tool metadata, and skill-specific message formatting.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool name resolution",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T22:41:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df776976f5673ed26d3f835a729f37591e0f256d",
"body": "Introduces a utility class that maps internal tool names to human-readable\ndisplay names for streaming progress updates. Supports loading from a JSON\nconfig file, extracting MCP titles from tool metadata, and generating\ncontextual messages for skill and tool invocations.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool name resolution",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T22:35:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "654336f5e12ee3941a64ce00e0dc1d158a5b9ef0",
"body": "…verflow\n\nWhen the model rejects input as too long, the ContextCompactor applies\nprogressive reduction (truncate tool results → drop tool pairs → summarize\nold exchanges) and retries the stream once. Controlled by the\nCONTEXT_COMPACTION_ENABLED environment variable (default: true).\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add context compaction to automatically recover from context window o…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T22:19:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7644ebc1707efbd67bd1562b9d930e67172c08b8",
"body": "When the model's context window is exceeded during streaming, the\nconversation is now compacted using a multi-pass strategy (truncate tool\nresults → drop tool pairs → summarize old exchanges) and retried once\nbefore surfacing the error to the user.\n\nIQ-BAI-190\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add context compaction with automatic retry on context window overflow",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T21:57:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "19ecd329e523bcba31a2de65654744301f049fe2",
"body": "Introduces a utility class that maps internal tool names to human-readable\ndisplay names for streaming progress updates. Supports static config via\nJSON file, dynamic registration from MCP tool metadata, and special\nformatting for skill-related and call_tool invocations.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add ToolDisplayNameMapper for user-facing tool name resolution",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T21:00:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d68fe86a7b3ab750ef3a007ca52071e39210a6af",
"body": "Cover successful invocation, AuthorizationNeededException propagation,\ngeneric exception wrapping with tool context, and non-dict input handling.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add unit tests for StreamingToolNode.astream error handling",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T19:49:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52464bbf4e85083dd1a2ea7166ae092ee1bac3a3",
"body": "…ture\n\nIntroduces the core streaming pipeline that translates LangGraph agent\nevents into OpenAI-compatible SSE chunks for real-time chat responses.\nIncludes persistence factory for MongoDB/memory checkpointing, chat\nmessage content normalization utilities, and tool event handling.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add LangGraph-to-OpenAI streaming converter and supporting infrastruc…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-02T19:44:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa8c3535139fd0195c3d3c1ed93689001bc88acd",
"body": "Consolidates MCP server interaction into a single provider that handles\ntool discovery (with server card and session fallback), lazy loading,\nOAuth/auth server discovery, session pooling, caching, and UI resource\nfetching for MCP app embeds.\n\nIQ-BAI-190",
"is_bot": false,
"headline": "Add MCPToolProvider class for MCP tool discovery, auth, and execution",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-06-01T04:38:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae262e575e3d7a9079fc6c928f58dc9eb879ec88",
"body": "…C container\n\nRemove inline instantiation of ServerCardDiscovery in MCPToolProvider —\nrequire it as a constructor dependency. Register both ServerCardDiscovery\nand McpAuthServerDiscovery as singletons in the common container factory.",
"is_bot": false,
"headline": "BAI-190 register ServerCardDiscovery and McpAuthServerDiscovery in Io…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-31T05:00:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d30b9fff3e2318427c9881fd2abb13d0fb0b9d82",
"body": "…r-card.json)\n\nWhen listing tools from MCP servers, try fetching the server card endpoint\nfirst to get static tool definitions without a full MCP session handshake.\nFalls back to tools/list if the endpoint is unavailable or declares tools\nas dynamic.",
"is_bot": false,
"headline": "BAI-190 add MCP Server Card discovery (SEP-1649 .well-known/mcp/serve…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-31T04:44:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78bcae2b8a657a67daedf6d2b710fe723a164e10",
"body": "…onfig\n\nImprove error diagnostics for GitHub download and MCP plugin fetch failures",
"is_bot": false,
"headline": "Merge pull request #39 from icanbwell/improve-error-logging-for-mcp-c…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-30T03:20:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b0c60ca8ff92bf6af630ee4aef7f1a53f07cfd0",
"body": "- model_config_cache_type: MongoDB is now the only backend\n- mcp_tool_cache_type: same, no longer needs a toggle\n- github_config_repo_url: only used by deleted GithubConfigRepoManager\n- github_timeout: same\n- prompt_store_type: simplified to default \"mongo\" directly",
"is_bot": false,
"headline": "Remove dead environment variable properties",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T21:51:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dea9b7c8928bf99ebe92a49a5b5565fdb57f1a58",
"body": "No production callers — all GitHub config downloads use fsspec via\nGithubDirectoryDownloader + GitHubDirectoryHelper.",
"is_bot": false,
"headline": "Delete dead GithubConfigRepoManager zipball downloader",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T21:48:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "567926eb89e1489f5b6553587c9a3e509629c152",
"body": "…h async\n\n- GithubDirectoryDownloader.download() now async, acquires AdvisoryLock\n via MongoDB store before downloading; returns None if lock held\n- GitHubDirectoryHelper accepts store param, passes to downloader\n- ConfigReader and PromptLibraryManager updated for async resolve_github_path\n- Contai\n[…]\nfore\n GitHubDirectoryHelper so store can be injected\n- Removed stale cache freshness logic (timestamp files, cache_ttl_seconds)\n- Tests updated for async signatures and MongoDB-based cache key lookup",
"is_bot": false,
"headline": "Wire advisory lock through download stack and make resolve_github_pat…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T21:47:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81c38d714f50dc22101f781e0e35014dd9bd7da3",
"body": "…ly cache backend",
"is_bot": false,
"headline": "Remove FileStore backend and cache_type parameter — MongoDB is the on…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T21:33:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8541528dfc398a3193122e6626d3de1ae5cdc35c",
"body": null,
"is_bot": false,
"headline": "Add AdvisoryLock distributed lock for download coordination",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T21:29:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2499c37e3546ff05a48ca4b69bb461aaf26c3afb",
"body": "Introduces a downloader that fetches github:// URI directories into a local\ncache with TTL-based freshness checks, exponential backoff retries, and\natomic directory swaps to prevent serving partially-written content.\nIncludes integration tests covering URI parsing, cache hits, content\ndirectory resolution, and ConfigReader/PromptLibraryManager integration.",
"is_bot": false,
"headline": "Add GithubDirectoryDownloader with cached fsspec-based downloads",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T20:55:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b46989d510f35eff261192b0550b35ebc123293",
"body": "Include docker-compose-mongo.yml in the `make up` target and upgrade\nlanguage-model-common to 2.0.61 for FHIR sync enabled flag support.",
"is_bot": false,
"headline": "Add MongoDB compose file to dev stack and bump dependencies",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T19:17:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0730bb6799b53b022636faf6e07a9a27ee950013",
"body": "Cover the RFC 8414 / OIDC discovery flow triggered when an MCP server\nreturns 401/403 and no OAuth config is pre-configured, including\nhelper method tests for nested exception group handling.",
"is_bot": false,
"headline": "Add tests for MCPToolProvider OAuth discovery on 401/403 responses",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T18:29:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd5e8715b2ab67d16b1b1d0c6a6518ef7a115ce5",
"body": "…re infrastructure\n\nIntroduces the foundational modules for model configuration loading (with\nMongoDB/file caching, S3/GitHub/filesystem sources, client overrides, and\nMCP server resolution), authentication interceptor for MCP tool calls,\ncontainer factory for DI registration, environment variables, and\ncomprehensive test coverage for config reader and cache store.",
"is_bot": false,
"headline": "Add config reader, auth interceptor, MCP tool provider, and cache sto…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T18:08:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "018c4cb6c4a975c6b8d37a33febd3d7a42d55600",
"body": "Introduces the core infrastructure for constructing and caching\nBaileyAgentService instances including tool discovery mode, plugin-based\nMCP server resolution from .mcp.json, conversation persistence with\nMongoDB, and optional FHIR sync gated behind feature flag.",
"is_bot": false,
"headline": "Add agent service factory, MCP config, and DI container for Bailey AI",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T17:05:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5eb0b432034296574ac04fc3e8d24cdc46579c61",
"body": "Centralizes MCP server communication including tool listing with caching,\nlazy-load support, OAuth/auth discovery, session pooling, and UI resource\nfetching into a dedicated provider class.",
"is_bot": false,
"headline": "Add MCPToolProvider class for MCP tool discovery and invocation",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T16:43:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "485478b330c7069aaad739e55b026c489eb5369d",
"body": "…ckend\n\nExtract LanguageModelCommonEnvironmentVariables into a standalone module and\nintroduce a pluggable snapshot cache store factory supporting MongoDB and\nfile-backed JSON persistence, with validation on connect.",
"is_bot": false,
"headline": "Add environment variables class and snapshot cache store with file ba…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T16:16:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4459c1f187ffbf14e64c3f2b3d3402c12d4cf0b6",
"body": "Configure MongoDB-backed prompt store (db: bailey-ai, collection: prompts)\nand seed prompts from filesystem on startup. Also add GITHUB_CONFIG_CACHE_DIR\nenv var for cached GitHub configuration files.",
"is_bot": false,
"headline": "Add prompt store seeding and GitHub config cache configuration",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T15:08:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a94a536c08e5ac7d24bac5f05e7608f9e95c70a2",
"body": "Configure MongoDB-backed prompt store (db: bailey-ai, collection: prompts)\nand seed prompts from filesystem on startup. Also add GITHUB_CONFIG_CACHE_DIR\nenv var for cached GitHub configuration files.",
"is_bot": false,
"headline": "Add prompt store seeding and GitHub config cache configuration",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T14:59:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a609c5d59f79a3e06fe0b49e1a63ecee183f0309",
"body": "Configure MongoDB-backed prompt store (db: bailey-ai, collection: prompts)\nand seed prompts from filesystem on startup. Also add GITHUB_CONFIG_CACHE_DIR\nenv var for cached GitHub configuration files.",
"is_bot": false,
"headline": "Add prompt store seeding and GitHub config cache configuration",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T13:55:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa3cf99e3f2bf4e9b3dbc703ef29249fac992c93",
"body": "…t library\n\nIntroduces the foundational configuration infrastructure:\n- ConfigReader with snapshot caching, MCP server resolution, and client overrides\n- DI container factory registering all language-model-common services\n- Environment variables class with all config knobs\n- PromptLibraryManager with persistent PromptStore backend and filesystem fallback\n- GithubDirectoryDownloader with retry, atomic swap, and cache TTL",
"is_bot": false,
"headline": "Add ConfigReader, container factory, environment variables, and promp…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T05:14:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05096787f3671e219b75e4ed9ab2ec3422c92850",
"body": "…cache\n\nIntroduces a downloader that resolves github:// URIs via fsspec, with\nTTL-based caching, atomic directory swaps, retry with exponential backoff,\nand stale-cache fallback on transient failures.",
"is_bot": false,
"headline": "Add GithubDirectoryDownloader for fetching github:// URIs into local …",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T03:37:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0cd0b0318ced7c15fc0b94f62815fb261d981d94",
"body": "Introduce fsspec-based GitHub directory downloading with caching, retry,\nand atomic swap, plus an MCP tool client that fetches per-plugin server\ndefinitions via the get_mcp_servers_config tool.",
"is_bot": false,
"headline": "Add GithubDirectoryDownloader and McpJsonFetcher for config loading",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-29T02:11:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d6f2b8adbbb46e2772b3011a7e101ab80b6a407",
"body": "Add MCP task protocol, enhanced Apps bridge, and Anthropic Bedrock client",
"is_bot": false,
"headline": "Merge pull request #38 from icanbwell/support-background-tasks",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T22:01:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02b1894b57e4eec4f269695d5ff67d7aaecd2f7b",
"body": "Introduce McpRequestContext with contextvars to allow shared singleton\nservices (auth interceptor, streaming manager, tool event handlers) to\naccess per-request state (headers, auth info, stream buffers) without\nbeing reconstructed on every request. Also adds container factory for\nDI registration and the full LangGraph-to-OpenAI streaming pipeline.",
"is_bot": false,
"headline": "Add request-scoped context system and singleton-compatible service layer",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T21:13:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "091989c83904744f41bf74df5d1ac1051dce4480",
"body": "Introduces the core MCP tool provider that manages tool discovery, lazy\nloading, authentication interceptor chains, and session pooling. Includes\nautomatic OAuth discovery (RFC 8414/OIDC) when servers return 401/403\nwithout pre-configured OAuth, enabling dynamic login prompt generation.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add MCPToolProvider with RFC 8414 auth server discovery",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T20:03:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a512c42f465411fd53aa71c3a95486c4a249be2c",
"body": "Implements a wrapper that adapts OpenAI's /responses API request format\nto the internal ChatRequestWrapper interface, enabling SSE streaming,\nnon-streaming responses, debug prefix toggling, and MCP tool extraction\nfor Responses API clients.",
"is_bot": false,
"headline": "Add ResponsesApiRequestWrapper for OpenAI Responses API support",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T18:42:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4180e408ea9160f59ed0571e819c25e95afa1081",
"body": null,
"is_bot": false,
"headline": "Comment out language-model-common volume mount in docker-compose",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T17:16:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "daba14da5a8b2f2bd26192d09871b4086eeeedcb",
"body": "…tore\n\nIntroduces LanguageModelCommonContainerFactory to centralize service\nregistration (singletons and request-scoped), a typed environment\nvariables class consolidating all config access, and McpToolListStore\nfor persisting MCP tool schemas across process restarts.",
"is_bot": false,
"headline": "Add DI container factory, environment variables, and MCP tool cache s…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T08:41:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e6d34d7fe9b6373f7e0448f86563953c99168975",
"body": "…tore\n\nIntroduces LanguageModelCommonContainerFactory to centralize service\nregistration (singletons and request-scoped), a typed environment\nvariables class consolidating all config access, and McpToolListStore\nfor persisting MCP tool schemas across process restarts.",
"is_bot": false,
"headline": "Add DI container factory, environment variables, and MCP tool cache s…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T08:39:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a3472c6a7e0cc8e408c50ec4b87d2d17ac706dd",
"body": "…tore\n\nIntroduces LanguageModelCommonContainerFactory to centralize service\nregistration (singletons and request-scoped), a typed environment\nvariables class consolidating all config access, and McpToolListStore\nfor persisting MCP tool schemas across process restarts.",
"is_bot": false,
"headline": "Add DI container factory, environment variables, and MCP tool cache s…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T08:36:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a30e4d809e667ecce8d0acd61d4d4fc17e5f09d8",
"body": "Wire MongoToolListStore into MCPToolProvider for persistent tool list\ncaching. The /reload endpoint now also clears the tool list cache\nalongside config cache. Fix CONVERSATION_MONGO_DB_NAME to use consistent\n\"baileyai\" database name.",
"is_bot": false,
"headline": "Add MongoDB-backed MCP tool list cache and clear on reload",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T08:25:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b57ae62929fb998b12a7aebe1b22840e5f896fc",
"body": "Introduces MCPToolProvider for discovering and invoking MCP tools with\nauth interceptors, session pooling, and OAuth server discovery fallback.\nAdds ToolListCache with TTL-based in-memory caching backed by a\npersistent MongoDB store to avoid redundant list_tools round-trips.\nIncludes LanguageModelCommonContainerFactory for centralized DI registration.",
"is_bot": false,
"headline": "Add MCP tool provider with tool list caching and DI container factory",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T08:16:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "484247f060cd5f671219656f791ed1792b647145",
"body": "Introduces the LangGraph-to-OpenAI streaming pipeline including\nStreamBufferManager, StreamDebugOutputManager, ToolEventHandler,\nLangGraphStreamingManager, and LangGraphToOpenAIConverter along with\ntheir DI registrations in LanguageModelCommonContainerFactory.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add streaming converter layer with DI container factory",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T07:43:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "bf14bcadc436046c7c0afe12380ca27d12bb4ae8",
"body": "Introduces LangGraphStreamingManager that dispatches LangGraph astream_events\n(chat model stream, tool lifecycle, chain end, custom events) into\nOpenAI-compatible SSE chunks for real-time rendering in OpenWebUI.",
"is_bot": false,
"headline": "Add LangGraph-to-OpenAI streaming manager for SSE translation",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T07:21:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "46481d992529d55fea8c218bb6209b3282beb146",
"body": "…ranslation\n\nIntroduces StreamBufferManager for batching streaming chunks by time interval\nor newline boundaries, and LangGraphStreamingManager to dispatch LangGraph\nevents into OpenAI-compatible SSE format. Includes unit tests for buffer logic.",
"is_bot": false,
"headline": "Add stream buffer and streaming manager for LangGraph-to-OpenAI SSE t…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T06:50:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42e7e7d9f52168365f80530921528e770844e901",
"body": null,
"is_bot": false,
"headline": "Bump uv from 0.11.6 to 0.11.16 in Dockerfile",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-28T06:03:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f60945a1193c1ef3b82c5e0a0599e15af0dcc4be",
"body": "… auth\n\nIntroduces foundational components for the language-model-common package:\n- MCP client callbacks, tool provider, tool invocation with task protocol\n- Config reader with GitHub/S3/file sources and snapshot caching\n- Streaming manager with SSE translation and stream buffering\n- Token exchange \n[…]\ndiscovery with BM25 ranking\n- Chat message helpers for LangChain/OpenAI format conversion\n- Token reducer utility for context window management\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add core modules for MCP tool provider, config reader, streaming, and…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T23:18:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7e440e6594536f9c5f1b44ca27d276543f8578c4",
"body": "Introduces the core infrastructure for the BaileyAI service including\nthe OpenAI-compatible chat completions/responses router, MCP tool\nprovider with session pooling and task protocol support, conversation\nhistory management, config reader with snapshot caching, token exchange\nauth flow, and organization-wide AGENTS.md coding standards.",
"is_bot": false,
"headline": "Add BaileyAI foundation: API router, MCP tooling, and org guidelines",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T22:20:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9c498613c1027048ed3883eb3e92d938c7660267",
"body": "Establishes the icanbwell baseline AI agent instructions covering\ndistributed systems patterns, FHIR-native modeling, tenant isolation,\nevent-driven architecture, SOLID principles, and operational standards.",
"is_bot": false,
"headline": "Add organization-wide AGENTS.md with architecture and design guidelines",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:55:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "104323256cb83f6548385678124dff070e455fec",
"body": "…s configurable\n\nAgentServiceFactory parameter is no longer optional in _build_agent_service,\nremoving the fallback instantiation. Debug prefix detection now reads from\nthe DEBUG_PREFIXES environment variable for runtime configurability.",
"is_bot": false,
"headline": "Make AgentServiceFactory a required dependency and make debug prefixe…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:41:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3834d4749032aecd673335d59fdfee8f6afc7f1",
"body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "EA-2365 Refactor streaming_manager to delegate to extracted modules",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:32:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "64d126625a9a1de800e0c426a15e0defbb1802c2",
"body": null,
"is_bot": false,
"headline": "Extract tool_event_handlers module from streaming_manager",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:24:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a773b2f20b82b90ecf9ba843405cbe17d504356f",
"body": null,
"is_bot": false,
"headline": "Extract stream_buffer module from streaming_manager",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:19:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b46ef97a624fdce6aa7de8f965b60c5c2d28d72c",
"body": null,
"is_bot": false,
"headline": "Extract streaming_formatters module from streaming_manager",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:15:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7303f7ad695705e50ccac9cd19ece4ff5f45276e",
"body": "7-task TDD plan for splitting streaming_manager.py into\nstreaming_formatters, stream_buffer, tool_event_handlers,\nand a slimmed-down orchestrator.",
"is_bot": false,
"headline": "Add streaming manager decomposition implementation plan",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:09:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "08c7c30e79d816c1fa107254285677c418436fdd",
"body": "Conservative 4-module split for code health: orchestrator,\ntool event handlers, stream buffer, and formatting utilities.",
"is_bot": false,
"headline": "Add streaming manager decomposition design spec",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T21:03:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c42268c2b9b49c12cf6e4e5350b7d1f2d1961f36",
"body": "…g manager\n\nIntroduces the foundational request handling layer for both OpenAI Chat\nCompletions and Responses API formats, along with config reading from\nfile/S3/GitHub sources with snapshot caching, and the LangGraph-to-SSE\nstreaming bridge. Includes comprehensive test coverage for config reader,\nGitHub repo manager, and responses API wrapper.",
"is_bot": false,
"headline": "Add ChatCompletion/Responses API wrappers, ConfigReader, and streamin…",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T20:40:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9c62ad1d93248ab2fd0afc6f38ae4fbff45cf8b7",
"body": "Introduce org-wide AI agent instructions (AGENTS.md) defining architecture\nconstraints, design principles, and coding standards. Add ChatCompletion and\nResponses API request wrapper classes with SSE streaming support, and tests\nfor the Responses API wrapper.",
"is_bot": false,
"headline": "Add AGENTS.md and OpenAI request wrapper implementations",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T19:56:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e33c9a9340cadc1211a6d48dbb37e525f4c8a57",
"body": "Bridges LangGraph's internal event stream (astream_events) with OpenAI SSE\nformat, handling token streaming, tool lifecycle events, buffering, and\ndebug output for the BaileyAI chat completions endpoint.",
"is_bot": false,
"headline": "Add LangGraph streaming manager for OpenAI-compatible SSE translation",
"author_name": "Imran Qureshi",
"author_login": "imranq2",
"committed_at": "2026-05-27T19:23:27Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 100,
"commits_last_year": 454,
"latest_release_at": "2026-07-24T18:38:40Z",
"latest_release_tag": "2.0.91",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 16,
"days_since_latest_release": 0,
"mean_days_between_releases": 4.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "language-model-common",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"Development Status :: 4 - Beta",
"Operating System :: OS Independent",
"Programming Language :: Python :: 3"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/language-model-common/",
"is_deprecated": false,
"latest_version": "2.0.91",
"repository_url": "https://github.com/icanbwell/language-model-common",
"versions_count": 125,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2026-03-17T22:20:24.300150Z",
"latest_published_at": "2026-07-24T18:39:11.656238Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 9
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"languagemodelcommon/py.typed"
],
"toolchain_manifests": [],
"largest_source_bytes": 52599,
"source_files_sampled": 273,
"oversized_source_files": 0,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 30436
},
"dependencies": {
"manifests": [
"pyproject.toml"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "mcp",
"direct": true,
"version": "1.27.2",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": null,
"advisory_ids": [
"GHSA-vj7q-gjh5-988w",
"PYSEC-2026-3483"
],
"fixed_version": "1.28.1",
"advisory_count": 2,
"oldest_advisory_days": 7
},
{
"name": "pypdf",
"direct": true,
"version": "6.13.2",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-55h5-xmcq-c37v",
"GHSA-5qjq-93h5-hrgp",
"GHSA-5xf7-4p34-54qr",
"GHSA-g867-7843-wf8q",
"GHSA-jm82-fx9c-mx94"
],
"fixed_version": "6.14.2",
"advisory_count": 5,
"oldest_advisory_days": 36
},
{
"name": "langsmith",
"direct": false,
"version": "0.8.16",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.7,
"advisory_ids": [
"GHSA-f4xh-w4cj-qxq8"
],
"fixed_version": "0.8.18",
"advisory_count": 1,
"oldest_advisory_days": 34
},
{
"name": "pyasn1",
"direct": false,
"version": "0.6.3",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-8ppf-4f7h-5ppj",
"GHSA-hm4w-wwcw-mr6r",
"PYSEC-2026-3455",
"PYSEC-2026-3456",
"PYSEC-2026-3457"
],
"fixed_version": "0.6.4",
"advisory_count": 5,
"oldest_advisory_days": 10
},
{
"name": "pydantic-settings",
"direct": false,
"version": "2.14.1",
"severity": "moderate",
"ecosystem": "pypi",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-4xgf-cpjx-pc3j"
],
"fixed_version": "2.14.2",
"advisory_count": 1,
"oldest_advisory_days": 34
},
{
"name": "setuptools",
"direct": false,
"version": "82.0.1",
"severity": "moderate",
"ecosystem": "pypi",
"cvss_score": 6.1,
"advisory_ids": [
"GHSA-h35f-9h28-mq5c",
"PYSEC-2026-3447"
],
"fixed_version": "83.0.0",
"advisory_count": 2,
"oldest_advisory_days": 16
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 4,
"moderate": 2
},
"advisory_count": 16,
"affected_count": 6,
"assessed_count": 190,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 4,
"direct_affected_count": 2
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "boto3",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.40.21"
},
{
"name": "fastapi",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.115.8"
},
{
"name": "httpx",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.27.2"
},
{
"name": "langchain",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.0.0"
},
{
"name": "langchain-aws",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.2.0"
},
{
"name": "langchain-community",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4"
},
{
"name": "openai",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.5.0"
},
{
"name": "langchain-openai",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.1.6"
},
{
"name": "langgraph",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.0.0"
},
{
"name": "pydantic",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.0,<3.0.0"
},
{
"name": "mcp",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.27.2"
},
{
"name": "langgraph-checkpoint",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.0.0"
},
{
"name": "langgraph-checkpoint-mongodb",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.3.1"
},
{
"name": "langgraph-store-mongodb",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.1.0"
},
{
"name": "tiktoken",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.12.0"
},
{
"name": "simple-container",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.0.2"
},
{
"name": "pypdf",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=6.6.0"
},
{
"name": "markdownify",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.14.1"
},
{
"name": "beautifulsoup4",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.12.3"
},
{
"name": "oidcauthlib",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.0.13"
},
{
"name": "fsspec",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2026.2.0"
},
{
"name": "authlib",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.6.5"
},
{
"name": "langchain-google-genai",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.1.3"
},
{
"name": "py-key-value-aio",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4.4"
},
{
"name": "PyJWT",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.8.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "authlib",
"direct": true,
"version": "1.7.2",
"ecosystem": "pypi"
},
{
"name": "beautifulsoup4",
"direct": true,
"version": "4.15.0",
"ecosystem": "pypi"
},
{
"name": "boto3",
"direct": true,
"version": "1.43.30",
"ecosystem": "pypi"
},
{
"name": "fastapi",
"direct": true,
"version": "0.137.1",
"ecosystem": "pypi"
},
{
"name": "fsspec",
"direct": true,
"version": "2026.6.0",
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": true,
"version": "0.28.1",
"ecosystem": "pypi"
},
{
"name": "langchain",
"direct": true,
"version": "1.3.9",
"ecosystem": "pypi"
},
{
"name": "langchain-aws",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "langchain-aws",
"direct": true,
"version": "1.5.1",
"ecosystem": "pypi"
},
{
"name": "langchain-community",
"direct": true,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "langchain-google-genai",
"direct": true,
"version": "4.2.5",
"ecosystem": "pypi"
},
{
"name": "langchain-openai",
"direct": true,
"version": "1.3.2",
"ecosystem": "pypi"
},
{
"name": "langgraph",
"direct": true,
"version": "1.2.5",
"ecosystem": "pypi"
},
{
"name": "langgraph-checkpoint",
"direct": true,
"version": "4.1.1",
"ecosystem": "pypi"
},
{
"name": "langgraph-checkpoint-mongodb",
"direct": true,
"version": "0.4.0",
"ecosystem": "pypi"
},
{
"name": "langgraph-store-mongodb",
"direct": true,
"version": "0.3.0",
"ecosystem": "pypi"
},
{
"name": "markdownify",
"direct": true,
"version": "1.2.2",
"ecosystem": "pypi"
},
{
"name": "mcp",
"direct": true,
"version": "1.27.2",
"ecosystem": "pypi"
},
{
"name": "oidcauthlib",
"direct": true,
"version": "3.0.16",
"ecosystem": "pypi"
},
{
"name": "openai",
"direct": true,
"version": "2.41.1",
"ecosystem": "pypi"
},
{
"name": "py-key-value-aio",
"direct": true,
"version": "0.4.5",
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": true,
"version": "2.13.4",
"ecosystem": "pypi"
},
{
"name": "pyjwt",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyjwt",
"direct": true,
"version": "2.13.0",
"ecosystem": "pypi"
},
{
"name": "pypdf",
"direct": true,
"version": "6.13.2",
"ecosystem": "pypi"
},
{
"name": "simple-container",
"direct": true,
"version": "1.0.2",
"ecosystem": "pypi"
},
{
"name": "tiktoken",
"direct": true,
"version": "0.13.0",
"ecosystem": "pypi"
},
{
"name": "aiohappyeyeballs",
"direct": false,
"version": "2.6.2",
"ecosystem": "pypi"
},
{
"name": "aiohttp",
"direct": false,
"version": "3.14.1",
"ecosystem": "pypi"
},
{
"name": "aiosignal",
"direct": false,
"version": "1.4.0",
"ecosystem": "pypi"
},
{
"name": "annotated-doc",
"direct": false,
"version": "0.0.4",
"ecosystem": "pypi"
},
{
"name": "annotated-types",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "anthropic",
"direct": false,
"version": "0.109.2",
"ecosystem": "pypi"
},
{
"name": "anyio",
"direct": false,
"version": "4.14.0",
"ecosystem": "pypi"
},
{
"name": "ast-serialize",
"direct": false,
"version": "0.5.0",
"ecosystem": "pypi"
},
{
"name": "attrs",
"direct": false,
"version": "26.1.0",
"ecosystem": "pypi"
},
{
"name": "autoflake",
"direct": false,
"version": "2.3.3",
"ecosystem": "pypi"
},
{
"name": "bandit",
"direct": false,
"version": "1.9.4",
"ecosystem": "pypi"
},
{
"name": "beartype",
"direct": false,
"version": "0.22.9",
"ecosystem": "pypi"
},
{
"name": "black",
"direct": false,
"version": "26.5.1",
"ecosystem": "pypi"
},
{
"name": "botocore",
"direct": false,
"version": "1.43.30",
"ecosystem": "pypi"
},
{
"name": "botocore-stubs",
"direct": false,
"version": "1.43.14",
"ecosystem": "pypi"
},
{
"name": "build",
"direct": false,
"version": "1.5.0",
"ecosystem": "pypi"
},
{
"name": "cachetools",
"direct": false,
"version": "7.1.4",
"ecosystem": "pypi"
},
{
"name": "certifi",
"direct": false,
"version": "2026.5.20",
"ecosystem": "pypi"
},
{
"name": "cffi",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "cfgv",
"direct": false,
"version": "3.5.0",
"ecosystem": "pypi"
},
{
"name": "charset-normalizer",
"direct": false,
"version": "3.4.7",
"ecosystem": "pypi"
},
{
"name": "click",
"direct": false,
"version": "8.4.1",
"ecosystem": "pypi"
},
{
"name": "colorama",
"direct": false,
"version": "0.4.6",
"ecosystem": "pypi"
},
{
"name": "coverage",
"direct": false,
"version": "7.14.1",
"ecosystem": "pypi"
},
{
"name": "cramjam",
"direct": false,
"version": "2.11.0",
"ecosystem": "pypi"
},
{
"name": "cryptography",
"direct": false,
"version": "49.0.0",
"ecosystem": "pypi"
},
{
"name": "distlib",
"direct": false,
"version": "0.4.3",
"ecosystem": "pypi"
},
{
"name": "distro",
"direct": false,
"version": "1.9.0",
"ecosystem": "pypi"
},
{
"name": "dnspython",
"direct": false,
"version": "2.8.0",
"ecosystem": "pypi"
},
{
"name": "docstring-parser",
"direct": false,
"version": "0.18.0",
"ecosystem": "pypi"
},
{
"name": "docutils",
"direct": false,
"version": "0.23",
"ecosystem": "pypi"
},
{
"name": "filelock",
"direct": false,
"version": "3.29.4",
"ecosystem": "pypi"
},
{
"name": "filetype",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "frozenlist",
"direct": false,
"version": "1.8.0",
"ecosystem": "pypi"
},
{
"name": "google-auth",
"direct": false,
"version": "2.55.0",
"ecosystem": "pypi"
},
{
"name": "google-genai",
"direct": false,
"version": "2.8.0",
"ecosystem": "pypi"
},
{
"name": "greenlet",
"direct": false,
"version": "3.5.1",
"ecosystem": "pypi"
},
{
"name": "h11",
"direct": false,
"version": "0.16.0",
"ecosystem": "pypi"
},
{
"name": "h2",
"direct": false,
"version": "4.3.0",
"ecosystem": "pypi"
},
{
"name": "hpack",
"direct": false,
"version": "4.1.0",
"ecosystem": "pypi"
},
{
"name": "httpcore",
"direct": false,
"version": "1.0.9",
"ecosystem": "pypi"
},
{
"name": "httpx-sse",
"direct": false,
"version": "0.4.3",
"ecosystem": "pypi"
},
{
"name": "hyperframe",
"direct": false,
"version": "6.1.0",
"ecosystem": "pypi"
},
{
"name": "id",
"direct": false,
"version": "1.6.1",
"ecosystem": "pypi"
},
{
"name": "identify",
"direct": false,
"version": "2.6.19",
"ecosystem": "pypi"
},
{
"name": "idna",
"direct": false,
"version": "3.18",
"ecosystem": "pypi"
},
{
"name": "iniconfig",
"direct": false,
"version": "2.3.0",
"ecosystem": "pypi"
},
{
"name": "jaraco-classes",
"direct": false,
"version": "3.4.0",
"ecosystem": "pypi"
},
{
"name": "jaraco-context",
"direct": false,
"version": "6.1.2",
"ecosystem": "pypi"
},
{
"name": "jaraco-functools",
"direct": false,
"version": "4.5.0",
"ecosystem": "pypi"
},
{
"name": "jeepney",
"direct": false,
"version": "0.9.0",
"ecosystem": "pypi"
},
{
"name": "jiter",
"direct": false,
"version": "0.15.0",
"ecosystem": "pypi"
},
{
"name": "jmespath",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "joserfc",
"direct": false,
"version": "1.7.1",
"ecosystem": "pypi"
},
{
"name": "jsonpatch",
"direct": false,
"version": "1.33",
"ecosystem": "pypi"
},
{
"name": "jsonpointer",
"direct": false,
"version": "3.1.1",
"ecosystem": "pypi"
},
{
"name": "jsonschema",
"direct": false,
"version": "4.26.0",
"ecosystem": "pypi"
},
{
"name": "jsonschema-specifications",
"direct": false,
"version": "2025.9.1",
"ecosystem": "pypi"
},
{
"name": "keyring",
"direct": false,
"version": "25.7.0",
"ecosystem": "pypi"
},
{
"name": "langchain-anthropic",
"direct": false,
"version": "1.4.6",
"ecosystem": "pypi"
},
{
"name": "langchain-classic",
"direct": false,
"version": "1.0.8",
"ecosystem": "pypi"
},
{
"name": "langchain-core",
"direct": false,
"version": "1.4.7",
"ecosystem": "pypi"
},
{
"name": "langchain-mongodb",
"direct": false,
"version": "0.11.0",
"ecosystem": "pypi"
},
{
"name": "langchain-protocol",
"direct": false,
"version": "0.0.17",
"ecosystem": "pypi"
},
{
"name": "langchain-text-splitters",
"direct": false,
"version": "1.1.2",
"ecosystem": "pypi"
},
{
"name": "langgraph-prebuilt",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "langgraph-sdk",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "langsmith",
"direct": false,
"version": "0.8.16",
"ecosystem": "pypi"
},
{
"name": "lark",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "librt",
"direct": false,
"version": "0.11.0",
"ecosystem": "pypi"
},
{
"name": "markdown-it-py",
"direct": false,
"version": "4.2.0",
"ecosystem": "pypi"
},
{
"name": "markupsafe",
"direct": false,
"version": "3.0.3",
"ecosystem": "pypi"
},
{
"name": "mdurl",
"direct": false,
"version": "0.1.2",
"ecosystem": "pypi"
},
{
"name": "more-itertools",
"direct": false,
"version": "11.1.0",
"ecosystem": "pypi"
},
{
"name": "moto",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "moto",
"direct": false,
"version": "5.2.2",
"ecosystem": "pypi"
},
{
"name": "multidict",
"direct": false,
"version": "6.7.1",
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "mypy-extensions",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "nh3",
"direct": false,
"version": "0.3.5",
"ecosystem": "pypi"
},
{
"name": "nodeenv",
"direct": false,
"version": "1.10.0",
"ecosystem": "pypi"
},
{
"name": "numpy",
"direct": false,
"version": "2.4.6",
"ecosystem": "pypi"
},
{
"name": "opentelemetry-api",
"direct": false,
"version": "1.42.1",
"ecosystem": "pypi"
},
{
"name": "orjson",
"direct": false,
"version": "3.11.9",
"ecosystem": "pypi"
},
{
"name": "ormsgpack",
"direct": false,
"version": "1.12.2",
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": false,
"version": "26.2",
"ecosystem": "pypi"
},
{
"name": "pathspec",
"direct": false,
"version": "1.1.1",
"ecosystem": "pypi"
},
{
"name": "platformdirs",
"direct": false,
"version": "4.10.0",
"ecosystem": "pypi"
},
{
"name": "pluggy",
"direct": false,
"version": "1.6.0",
"ecosystem": "pypi"
},
{
"name": "pre-commit",
"direct": false,
"version": "4.6.0",
"ecosystem": "pypi"
},
{
"name": "propcache",
"direct": false,
"version": "0.5.2",
"ecosystem": "pypi"
},
{
"name": "py-partiql-parser",
"direct": false,
"version": "0.6.3",
"ecosystem": "pypi"
},
{
"name": "pyasn1",
"direct": false,
"version": "0.6.3",
"ecosystem": "pypi"
},
{
"name": "pyasn1-modules",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "pycparser",
"direct": false,
"version": "3.0",
"ecosystem": "pypi"
},
{
"name": "pydantic-core",
"direct": false,
"version": "2.46.4",
"ecosystem": "pypi"
},
{
"name": "pydantic-settings",
"direct": false,
"version": "2.14.1",
"ecosystem": "pypi"
},
{
"name": "pyflakes",
"direct": false,
"version": "3.4.0",
"ecosystem": "pypi"
},
{
"name": "pygments",
"direct": false,
"version": "2.20.0",
"ecosystem": "pypi"
},
{
"name": "pymongo",
"direct": false,
"version": "4.16.0",
"ecosystem": "pypi"
},
{
"name": "pymongo-search-utils",
"direct": false,
"version": "0.3.0",
"ecosystem": "pypi"
},
{
"name": "pyproject-hooks",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": "9.1.0",
"ecosystem": "pypi"
},
{
"name": "pytest-asyncio",
"direct": false,
"version": "1.4.0",
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": "7.1.0",
"ecosystem": "pypi"
},
{
"name": "pytest-httpx",
"direct": false,
"version": "0.36.2",
"ecosystem": "pypi"
},
{
"name": "python-dateutil",
"direct": false,
"version": "2.9.0.post0",
"ecosystem": "pypi"
},
{
"name": "python-discovery",
"direct": false,
"version": "1.4.2",
"ecosystem": "pypi"
},
{
"name": "python-dotenv",
"direct": false,
"version": "1.2.2",
"ecosystem": "pypi"
},
{
"name": "python-multipart",
"direct": false,
"version": "0.0.32",
"ecosystem": "pypi"
},
{
"name": "python-snappy",
"direct": false,
"version": "0.7.3",
"ecosystem": "pypi"
},
{
"name": "pytokens",
"direct": false,
"version": "0.4.1",
"ecosystem": "pypi"
},
{
"name": "pywin32",
"direct": false,
"version": "312",
"ecosystem": "pypi"
},
{
"name": "pywin32-ctypes",
"direct": false,
"version": "0.2.3",
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": false,
"version": "6.0.3",
"ecosystem": "pypi"
},
{
"name": "readme-renderer",
"direct": false,
"version": "45.0",
"ecosystem": "pypi"
},
{
"name": "redis",
"direct": false,
"version": "8.0.0",
"ecosystem": "pypi"
},
{
"name": "referencing",
"direct": false,
"version": "0.37.0",
"ecosystem": "pypi"
},
{
"name": "regex",
"direct": false,
"version": "2026.5.9",
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": "2.34.2",
"ecosystem": "pypi"
},
{
"name": "requests-toolbelt",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "responses",
"direct": false,
"version": "0.26.1",
"ecosystem": "pypi"
},
{
"name": "respx",
"direct": false,
"version": "0.23.1",
"ecosystem": "pypi"
},
{
"name": "rfc3986",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "rich",
"direct": false,
"version": "15.0.0",
"ecosystem": "pypi"
},
{
"name": "rpds-py",
"direct": false,
"version": "2026.5.1",
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": "0.15.17",
"ecosystem": "pypi"
},
{
"name": "s3transfer",
"direct": false,
"version": "0.18.0",
"ecosystem": "pypi"
},
{
"name": "secretstorage",
"direct": false,
"version": "3.5.0",
"ecosystem": "pypi"
},
{
"name": "setuptools",
"direct": false,
"version": "82.0.1",
"ecosystem": "pypi"
},
{
"name": "six",
"direct": false,
"version": "1.17.0",
"ecosystem": "pypi"
},
{
"name": "sniffio",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "soupsieve",
"direct": false,
"version": "2.8.4",
"ecosystem": "pypi"
},
{
"name": "sqlalchemy",
"direct": false,
"version": "2.0.51",
"ecosystem": "pypi"
},
{
"name": "sse-starlette",
"direct": false,
"version": "3.4.4",
"ecosystem": "pypi"
},
{
"name": "starlette",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "stevedore",
"direct": false,
"version": "5.8.0",
"ecosystem": "pypi"
},
{
"name": "tenacity",
"direct": false,
"version": "9.1.4",
"ecosystem": "pypi"
},
{
"name": "tqdm",
"direct": false,
"version": "4.68.2",
"ecosystem": "pypi"
},
{
"name": "twine",
"direct": false,
"version": "6.2.0",
"ecosystem": "pypi"
},
{
"name": "types-authlib",
"direct": false,
"version": "1.6.11.20260518",
"ecosystem": "pypi"
},
{
"name": "types-awscrt",
"direct": false,
"version": "0.34.1",
"ecosystem": "pypi"
},
{
"name": "types-beautifulsoup4",
"direct": false,
"version": "4.12.0.20250516",
"ecosystem": "pypi"
},
{
"name": "types-boto3",
"direct": false,
"version": "1.43.30",
"ecosystem": "pypi"
},
{
"name": "types-boto3-bedrock",
"direct": false,
"version": "1.43.26",
"ecosystem": "pypi"
},
{
"name": "types-boto3-bedrock-runtime",
"direct": false,
"version": "1.43.30",
"ecosystem": "pypi"
},
{
"name": "types-boto3-s3",
"direct": false,
"version": "1.43.14",
"ecosystem": "pypi"
},
{
"name": "types-boto3-textract",
"direct": false,
"version": "1.43.0",
"ecosystem": "pypi"
},
{
"name": "types-botocore",
"direct": false,
"version": "1.0.2",
"ecosystem": "pypi"
},
{
"name": "types-html5lib",
"direct": false,
"version": "1.1.11.20260518",
"ecosystem": "pypi"
},
{
"name": "types-requests",
"direct": false,
"version": "2.33.0.20260518",
"ecosystem": "pypi"
},
{
"name": "types-s3transfer",
"direct": false,
"version": "0.16.0",
"ecosystem": "pypi"
},
{
"name": "types-webencodings",
"direct": false,
"version": "0.5.0.20260408",
"ecosystem": "pypi"
},
{
"name": "typing-extensions",
"direct": false,
"version": "4.15.0",
"ecosystem": "pypi"
},
{
"name": "typing-inspection",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "urllib3",
"direct": false,
"version": "2.7.0",
"ecosystem": "pypi"
},
{
"name": "uuid-utils",
"direct": false,
"version": "0.16.1",
"ecosystem": "pypi"
},
{
"name": "uvicorn",
"direct": false,
"version": "0.49.0",
"ecosystem": "pypi"
},
{
"name": "virtualenv",
"direct": false,
"version": "21.5.1",
"ecosystem": "pypi"
},
{
"name": "websockets",
"direct": false,
"version": "15.0.1",
"ecosystem": "pypi"
},
{
"name": "werkzeug",
"direct": false,
"version": "3.1.8",
"ecosystem": "pypi"
},
{
"name": "wheel",
"direct": false,
"version": "0.47.0",
"ecosystem": "pypi"
},
{
"name": "xmltodict",
"direct": false,
"version": "1.0.4",
"ecosystem": "pypi"
},
{
"name": "xxhash",
"direct": false,
"version": "3.7.0",
"ecosystem": "pypi"
},
{
"name": "yarl",
"direct": false,
"version": "1.24.2",
"ecosystem": "pypi"
},
{
"name": "zstandard",
"direct": false,
"version": "0.25.0",
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 194,
"direct_count": 28,
"indirect_count": 166
}
},
"maintainership": {
"issues": {
"open_prs": 9,
"merged_prs": 28,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 22
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "imranq2",
"commits": 448,
"avatar_url": "https://avatars.githubusercontent.com/u/896576?v=4"
},
{
"type": "User",
"login": "sean-can-bwell",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/72527375?v=4"
},
{
"type": "User",
"login": "kenanspruill",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/107875308?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.993
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"build_and_test.yml",
"python-publish.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [
"uv.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 1,
"reason": "dependency not pinned by hash detected -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "12 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "b5813feb19a1149992b1d2e8a5e10ab2b975e663",
"ran_at": "2026-07-24T18:41:12Z",
"aggregate_score": 5.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T18:23:56Z",
"oldest_open_prs": [
{
"number": 48,
"created_at": "2026-06-09T18:24:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 51,
"created_at": "2026-06-20T12:04:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 52,
"created_at": "2026-06-23T21:37:55Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 54,
"created_at": "2026-07-14T21:07:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 55,
"created_at": "2026-07-16T20:56:26Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 56,
"created_at": "2026-07-19T22:10:11Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 57,
"created_at": "2026-07-23T03:49:00Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 58,
"created_at": "2026-07-24T18:21:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 59,
"created_at": "2026-07-24T18:28:28Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-03T06:12:29Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/icanbwell/language-model-common",
"host": "github.com",
"name": "language-model-common",
"owner": "icanbwell"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"security": 55,
"vitality": 85,
"community": 24,
"governance": 57,
"engineering": 86
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 85,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"commits_last_year": 454,
"human_commit_share": 0.99,
"days_since_last_push": 0,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "454 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 454
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 100,
"latest_release_tag": "2.0.91",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 4.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~4.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 4.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 24,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 57,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.993
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 99% of commits",
"points": 0.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 99
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 68,
"inputs": {
"merged_prs": 28,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 22
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "28/50 decided PRs merged",
"points": 21.4,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 28,
"decided": 50
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"followers": 39,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "icanbwell",
"public_repos": 84,
"account_age_days": 4057
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "39 followers of icanbwell",
"points": 11.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 39,
"login": "icanbwell"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "84 public repos, account ~11 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 84
}
},
{
"code": "account_age_years",
"params": {
"years": 11
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"language-model-common"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "125 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 125
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 86,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 94,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 16,
"status": "met",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 55,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 52,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 5.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "12 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "moderate",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 190 resolved dependencies against OSV; 4 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 190
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 4
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 69,
"inputs": {
"source": "osv",
"advisories": 16,
"affected_packages": 6,
"assessed_packages": 190,
"unassessed_packages": 4,
"affected_by_severity": "high 4, moderate 2",
"direct_affected_packages": 2
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "2 affected: mcp 1.27.2 (high), pypdf 6.13.2 (high 7.5)",
"points": 11.9,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 2,
"packages": "mcp 1.27.2 (high), pypdf 6.13.2 (high 7.5)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 190,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 77,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.818,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 30436
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "81 of 99 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 81,
"sampled": 99
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 91,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"uv.lock"
],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"languagemodelcommon/py.typed"
],
"agent_commit_share": 0.08,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.01
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 11,
"status": "met",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "languagemodelcommon/py.typed",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "languagemodelcommon/py.typed"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "8 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 8,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "1 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 1,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "good",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 52599,
"source_files_sampled": 273,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python with type-check config (languagemodelcommon/py.typed)",
"points": 27,
"status": "partial",
"details": [
{
"code": "typecheck_config_language",
"params": {
"files": "languagemodelcommon/py.typed",
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/273 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 273,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"deps.dev does not index pypi:language-model-common@2.0.91; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-24T18:41:32.219497Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/icanbwell/language-model-common.svg",
"full_name": "icanbwell/language-model-common",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}