Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-24 05:55 UTC

intisy-ai / plugin-updater

Plugin lifecycle manager for OpenCode and Claude Code

TypeScript · JavaScriptЛіцензію не виявлено★ 0 зірок⑂ 0 форківз черв. 2026 р.Переглянути на GitHub ↗

intisy-ai/plugin-updater має індекс здоров’я 47 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Vitality (71/100), найнижчий — Community & Adoption (25/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

47
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

47
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

intisy-aiОрганізація
1 підписник26 публічних репозиторіївз черв. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npmplugin-updater1.5.114 965635 днів томуopencodeclaudepluginupdaterlifecycle

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

71Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
5.5/36Ритм комітів — 8/52 тижнів із комітами
18/18Обсяг комітів — 112 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year112
human_commit_share1
days_since_last_push0
active_weeks_last_year8
Як обчислюється оцінка
16.2/27Випускає релізи — 73 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~1,8 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count73
latest_release_tagv1.5.11
releases_from_tagsтак
days_since_latest_release5
mean_days_between_releases1,8
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

25Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
0/22.5Ліцензія — файлу ліцензії не виявлено
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseні
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
49.3/80Щомісячні завантаження — 4 965 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagesplugin-updater
dependents
ecosystemsnpm
total_downloads
monthly_downloads4 965
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

37У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, Прийняття PR. Залишкові ваги перенормовано.

Власність та опіка

43У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
2.2/25Охоплення власника — 1 підписників у intisy-ai
10.6/25Послужний список — 26 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers1
owner_typeOrganization
is_verified
owner_loginintisy-ai
public_repos26
account_age_days27

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 63 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesplugin-updater
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

56Помірний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 1 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

50Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

42У зоні ризику · 16% загального індексу

Стан безпеки

42У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 4 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Ліцензія — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,2
Виключено з оцінювання (немає даних або не застосовно): ci_tests, signed_releases. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

47У зоні ризику · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 83 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,83
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — tsconfig.json
0/10Відтворюване середовище
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
55/55Керовані розміри файлів — 0/21 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes18 318
source_files_sampled21
oversized_source_files0

Ключові факти

0зірок GitHub
1контриб'юторів
112комітів за останні 12 місяців
0днів від останнього пушу
73релізів
1бас-фактор
0відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:plugin-updater@1.5.11; advisories assessed against the repository dependency graph instead

Докладніше

OpenSSF Scorecard 4.2 / 10
4.2сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-24 05:55 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 4 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 148,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 12282,
        "TypeScript": 87711
      },
      "pushed_at": "2026-07-23T06:25:31Z",
      "created_at": "2026-06-18T14:42:15Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T06:26:36Z",
      "description": "Plugin lifecycle manager for OpenCode and Claude Code",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "intisy-ai",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/297198117?v=4",
      "created_at": "2026-06-26T15:06:14Z",
      "is_verified": null,
      "public_repos": 26,
      "account_age_days": 27
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.5.11",
          "kind": "patch",
          "published_at": "2026-07-18T20:00:07Z"
        },
        {
          "tag": "v1.5.10",
          "kind": "patch",
          "published_at": "2026-07-12T10:06:36Z"
        },
        {
          "tag": "v1.5.9",
          "kind": "patch",
          "published_at": "2026-07-08T09:38:05Z"
        },
        {
          "tag": "v1.5.8",
          "kind": "patch",
          "published_at": "2026-07-08T00:35:06Z"
        },
        {
          "tag": "v1.5.7",
          "kind": "patch",
          "published_at": "2026-07-08T00:25:26Z"
        },
        {
          "tag": "v1.5.6",
          "kind": "patch",
          "published_at": "2026-07-07T22:35:03Z"
        },
        {
          "tag": "v1.5.5",
          "kind": "patch",
          "published_at": "2026-07-03T10:03:03Z"
        },
        {
          "tag": "v1.5.4",
          "kind": "patch",
          "published_at": "2026-07-02T17:36:30Z"
        },
        {
          "tag": "v1.5.3",
          "kind": "patch",
          "published_at": "2026-07-02T17:13:28Z"
        },
        {
          "tag": "v1.5.2",
          "kind": "patch",
          "published_at": "2026-07-02T09:29:21Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-07-01T13:57:30Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-07-01T10:55:20Z"
        },
        {
          "tag": "v1.4.3",
          "kind": "patch",
          "published_at": "2026-06-30T13:01:48Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-06-30T12:46:06Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-06-30T12:26:56Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-06-30T11:44:04Z"
        },
        {
          "tag": "v1.3.5",
          "kind": "patch",
          "published_at": "2026-06-27T17:20:56Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-06-27T16:37:31Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-06-27T16:11:12Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-06-27T07:07:26Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-06-27T06:56:13Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-06-27T05:55:54Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-06-26T17:00:10Z"
        },
        {
          "tag": "v1.1.3",
          "kind": "patch",
          "published_at": "2026-06-26T08:54:12Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2026-06-26T07:48:09Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2026-06-24T19:33:25Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-06-24T19:33:25Z"
        },
        {
          "tag": "v1.0.46",
          "kind": "patch",
          "published_at": "2026-06-24T19:33:25Z"
        },
        {
          "tag": "v1.0.45",
          "kind": "patch",
          "published_at": "2026-06-18T13:34:57Z"
        },
        {
          "tag": "v1.0.44",
          "kind": "patch",
          "published_at": "2026-06-15T17:18:24Z"
        },
        {
          "tag": "v1.0.43",
          "kind": "patch",
          "published_at": "2026-06-13T19:24:51Z"
        },
        {
          "tag": "v1.0.42",
          "kind": "patch",
          "published_at": "2026-06-13T18:29:27Z"
        },
        {
          "tag": "v1.0.41",
          "kind": "patch",
          "published_at": "2026-06-13T11:19:06Z"
        },
        {
          "tag": "v1.0.40",
          "kind": "patch",
          "published_at": "2026-06-13T10:28:06Z"
        },
        {
          "tag": "v1.0.39",
          "kind": "patch",
          "published_at": "2026-06-11T13:16:22Z"
        },
        {
          "tag": "v1.0.38",
          "kind": "patch",
          "published_at": "2026-06-11T12:14:14Z"
        },
        {
          "tag": "v1.0.37",
          "kind": "patch",
          "published_at": "2026-06-11T11:39:11Z"
        },
        {
          "tag": "v1.0.36",
          "kind": "patch",
          "published_at": "2026-06-11T08:58:29Z"
        },
        {
          "tag": "v1.0.35",
          "kind": "patch",
          "published_at": "2026-06-11T08:40:23Z"
        },
        {
          "tag": "v1.0.34",
          "kind": "patch",
          "published_at": "2026-06-11T08:21:05Z"
        },
        {
          "tag": "v1.0.33",
          "kind": "patch",
          "published_at": "2026-06-11T08:17:56Z"
        },
        {
          "tag": "v1.0.32",
          "kind": "patch",
          "published_at": "2026-06-11T08:06:41Z"
        },
        {
          "tag": "v1.0.31",
          "kind": "patch",
          "published_at": "2026-06-10T22:09:09Z"
        },
        {
          "tag": "v1.0.30",
          "kind": "patch",
          "published_at": "2026-06-10T18:05:07Z"
        },
        {
          "tag": "v1.0.29",
          "kind": "patch",
          "published_at": "2026-06-10T17:28:24Z"
        },
        {
          "tag": "v1.0.28",
          "kind": "patch",
          "published_at": "2026-06-10T13:24:35Z"
        },
        {
          "tag": "v1.0.27",
          "kind": "patch",
          "published_at": "2026-06-10T08:32:36Z"
        },
        {
          "tag": "v1.0.26",
          "kind": "patch",
          "published_at": "2026-06-10T07:14:03Z"
        },
        {
          "tag": "v1.0.25",
          "kind": "patch",
          "published_at": "2026-06-10T05:34:06Z"
        },
        {
          "tag": "v1.0.24",
          "kind": "patch",
          "published_at": "2026-06-09T23:29:18Z"
        },
        {
          "tag": "v1.0.23",
          "kind": "patch",
          "published_at": "2026-06-09T20:54:35Z"
        },
        {
          "tag": "v1.0.22",
          "kind": "patch",
          "published_at": "2026-06-09T20:21:21Z"
        },
        {
          "tag": "v1.0.21",
          "kind": "patch",
          "published_at": "2026-06-09T16:56:07Z"
        },
        {
          "tag": "v1.0.20",
          "kind": "patch",
          "published_at": "2026-06-09T17:14:46Z"
        },
        {
          "tag": "v1.0.19",
          "kind": "patch",
          "published_at": "2026-06-04T07:35:03Z"
        },
        {
          "tag": "v1.0.18",
          "kind": "patch",
          "published_at": "2026-06-04T06:56:00Z"
        },
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2026-06-04T06:40:00Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2026-06-04T06:27:31Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2026-06-04T06:05:22Z"
        },
        {
          "tag": "v1.0.14",
          "kind": "patch",
          "published_at": "2026-06-04T05:58:01Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2026-06-04T05:43:51Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2026-06-04T05:33:56Z"
        },
        {
          "tag": "v1.0.11",
          "kind": "patch",
          "published_at": "2026-06-03T19:58:50Z"
        },
        {
          "tag": "v1.0.10",
          "kind": "patch",
          "published_at": "2026-06-03T19:48:35Z"
        },
        {
          "tag": "v1.0.9",
          "kind": "patch",
          "published_at": "2026-06-03T19:09:16Z"
        },
        {
          "tag": "v1.0.8",
          "kind": "patch",
          "published_at": "2026-06-03T16:36:22Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2026-06-03T16:36:22Z"
        },
        {
          "tag": "v1.0.6",
          "kind": "patch",
          "published_at": "2026-06-03T16:06:32Z"
        },
        {
          "tag": "v1.0.5",
          "kind": "patch",
          "published_at": "2026-06-03T15:49:37Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2026-06-03T15:41:28Z"
        },
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2026-06-03T14:38:51Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-06-03T13:43:16Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-06-03T13:22:56Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7161f66bfc5e4734679b24130c09f3f55df5fcc4",
          "body": null,
          "is_bot": false,
          "headline": "feat: uninstallPlugin removes the entry and prunes its artifacts",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-23T06:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55075bb76152fb3068528300b99f8e8aaa4b27c3",
          "body": null,
          "is_bot": false,
          "headline": "fix: copy nested proxy submodule dists to deployed clones",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-22T22:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f9ab337b9119d417b0184f195188a055fb7cd75",
          "body": "…ordering; check remote in manual update_on_launch mode\n\nThree review fixes on the update-status-cache/commitHash-pin work:\n\n- Add sync export downgrade(plugin, commitHash) matching core-loader's\n  updater.downgrade(repo, hash) contract (string return, no async). It\n  checks out the commit via updat\n[…]\nlso bumped the cache.test.ts git-integration test's timeout (pre-existing\nflakiness under the default 5s vitest timeout on this machine, reproduced\non the prior commit too — unrelated to these fixes).",
          "is_bot": false,
          "headline": "fix: wire downgrade() so a downgrade persists; fix self-update cache …",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-18T20:00:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28e026e3ea9be09d99726386a0d0725c89daf0ce",
          "body": "…e remotes; thread persisted commitHash\n\n- new cache.ts writes <configDir>/cache/plugin-updates.json each earlyLaunch run\n  (git localHead/remoteHead + npm installed/latest versions, updateAvailable,\n  updatedAt), for the loader TUI to read (Task B, separate repo). Best-effort,\n  never throws.\n- aut\n[…]\ntPluginCommitHash) so a downgrade pin survives the next earlyLaunch.\n- add src/__tests__/cache.test.ts: real git clones (behind vs up-to-date) prove\n  updateAvailable is computed correctly end-to-end.",
          "is_bot": false,
          "headline": "feat: write update-status cache in earlyLaunch; check autoUpdate:fals…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-18T19:40:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37051f31fe5ea07a523af1fe2fc653124a6d0a8b",
          "body": "… (no TUI in the updater)",
          "is_bot": false,
          "headline": "feat: init multi-app selection is a plain one-line prompt, not a menu…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-12T10:06:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5742b7ac1996afa05e22908b7d6c2ea594b1d5f",
          "body": "…ts (a leftover ~/.opencode hijacked init/runtime path resolution)",
          "is_bot": false,
          "headline": "fix: opencode home resolution prefers ~/.config/opencode when it exis…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-11T09:13:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89ae083409361c3bb7d09901f7187d8fc7ac28f0",
          "body": "…S_PACKAGE_JSON); release v1.5.9",
          "is_bot": false,
          "headline": "fix(deploy): mark plugin execution dir as ESM (silence MODULE_TYPELES…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-08T09:38:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abbd24cb5515fa3f007a8aee051e03191e586b3c",
          "body": "… dist/ prefix); stop double-nesting to dist/dist and deploying a stale artifact; release v1.5.8",
          "is_bot": false,
          "headline": "fix(deploy): resolve deploySource against sourceDir (pkg.main carries…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-08T00:35:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40e6dbf2fe4759633214390c9dd2b3fb5e08b1c4",
          "body": "…ed sha != clone HEAD); release v1.5.7",
          "is_bot": false,
          "headline": "fix(deploy): self-heal stale deployed artifacts (redeploy when deploy…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-08T00:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8f53c88f55d5118a7ea5ac784ce251c92d60228",
          "body": "…IG_DIR)",
          "is_bot": false,
          "headline": "chore: release v1.5.6 (Windows cleanup() pathToFileURL fix + HUB_CONF…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-07T22:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf49f140129b7cbae4e8d2b096746e9f0d60119b",
          "body": "… a valid specifier)\n\ndeployToExecutionDir's callPluginCleanup did `import(<abs path>)`, which on Windows\nthrows \"Only URLs with a scheme in: file, data, node … Received protocol 'c:'\". Use\npathToFileURL like the activate path already does. (Non-fatal — it's caught — but it\nlogged an error on every Windows deploy.)",
          "is_bot": false,
          "headline": "fix: cleanup() import uses pathToFileURL (Windows raw C:\\ path is not…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-07T22:05:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d327d4f6f84b62128aa49ea2693c7b6fff271d3",
          "body": "… hit the right home\n\nThe loader spawns updatePluginPublic in a child that inherits HUB_CONFIG_DIR but\nno argv/app hint; getAppConfigDir ignored HUB_CONFIG_DIR and guessed the app home\nfrom argv (which lacks \"claude\"), so single-plugin updates landed in the wrong\nconfig dir and the loader repos/<name> clone never advanced. Now HUB_CONFIG_DIR\n(the unified loader signal, below the earlyLaunch dir) wins.",
          "is_bot": false,
          "headline": "fix: honor HUB_CONFIG_DIR in getAppConfigDir so loader-driven updates…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-07T14:34:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "411548a707c891ba8f094d8ed499008bcba3392f",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump core/* submodules for unified config-dir resolution",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-07T10:06:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c36dd54926687c4deac0709b5139562659cf3d42",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove dead code, trim comments",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-05T15:38:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bffda03ddbadbe9bfc0f838dfd386cc8c6fa1a8",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v1.5.5 (earlyLaunch startup ~25s -> ~5s)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-03T10:03:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ef6df9fe526d8716fb08577b99051949154ddfa",
          "body": "Three changes, all on the no-change fast path that runs every launch:\n- Drop the per-launch 'git submodule status --recursive' drift check. It spawns a\n  git subprocess per nested submodule and cost 10-17s PER plugin under load — the\n  dominant startup delay. The full-update path still syncs submodu\n[…]\neHashes) instead of N serial network round-trips.\n- Skip the redundant copy + plugin re-import (cleanup) + re-activate on unchanged\n  plugins under opencode (opencode imports deployed plugins itself).",
          "is_bot": false,
          "headline": "perf: cut earlyLaunch startup from ~25s to ~5s",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-03T10:02:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69b63b39ea26b96a04116ab1e35a565e3a9ff611",
          "body": "readOpencodeJson/writeOpencodeJson only handled opencode.json, so npm plugins\ndeclared in opencode.jsonc were invisible (empty npm list) and install/uninstall\nedited the wrong file. Resolve the actual config file (prefer .json, else .jsonc).\nBumps to v1.5.4.",
          "is_bot": false,
          "headline": "fix: detect opencode.jsonc for npm plugins (read + write)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-02T17:36:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db828b99a83f77e7223d59e92c1b1e2438d16f2f",
          "body": "Each loader is app-specific; if the foreign loader was mistakenly registered\n(e.g. a mixed-container init without --app), getPlugins now filters it out by\nconfig dir, so opencode never manages/shows claude-code-loader and vice versa.\nBumps to v1.5.3.",
          "is_bot": false,
          "headline": "fix: getPlugins skips the other app's loader",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-02T17:13:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "793daace6cfd8a404f583920cdea979674317bd0",
          "body": "Ships the run-exit + fresh-activate fixes (0522f9d) to npm so the SessionStart\nhook's npx invocation no longer hangs or activates stale code.",
          "is_bot": false,
          "headline": "chore(release): plugin-updater v1.5.2",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-02T09:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0522f9d4bc0eebb25adfeebfbeb1b4682a27ebe9",
          "body": "Two defects that broke the CC SessionStart flow:\n\n- run never exited: dynamically-imported plugin/loader modules can leave the\n  event loop non-empty, hanging the task-runner and stalling CC's SessionStart\n  hook. Explicitly process.exit(0) once main() resolves (detached daemons are\n  already unref'\n[…]\nactivate import returned the cached old module (e.g. regenerating the\n  cc wrapper from pre-fix code). Cache-bust the activate import via a pathToFileURL\n  query so it loads the freshly-copied module.",
          "is_bot": false,
          "headline": "fix: exit cleanly after run and activate against fresh plugin code",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-02T09:01:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44b96d8199b5333a338a8a48e74e9a0527d2a178",
          "body": "README now generated by the central core generator; advance core submodule to 659ce90.",
          "is_bot": false,
          "headline": "chore(release): v1.5.1",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-01T13:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ba7f281e5b293a132f74a3be8370900b91d43c0",
          "body": "- Advance core submodule to 3f87378 (readme generator)\n- Add defineReadme spec (description, architecture, structure, commands, dependencies, extraSections for adding-plugins/sync/api)\n- Add maybeRunReadmeCli guard before maybeRunCli in src/index.ts\n- Add postbuild script: node dist/index.js readme\n- Add readme: true to contract test\n- Add git diff --exit-code README.md drift-check to publish workflow",
          "is_bot": false,
          "headline": "docs: generate README from central generator (defineReadme)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-01T13:39:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91bb7ed269a3fa83c105b459573906e4dd2e9b3a",
          "body": "Coordinated ecosystem release: advance bundled core/core-auth/core-loader\nsubmodule pointers to latest and republish with this session's config, TUI,\nand fix changes.",
          "is_bot": false,
          "headline": "chore(release): v1.5.0",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-01T10:55:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73dc8d11019fb54f264e5b81d8096e4101322ed3",
          "body": "Fixes oc/cc breaking until restart after a TUI-driven loader self-update:\nthe update runs inside the bun tui.js process (not opencode), so activate()\n- which reinstalls the oc/cc wrapper - was never called under opencode. Now\nloaders activate after any deploy (idempotent; earlyLaunch stays guarded).",
          "is_bot": false,
          "headline": "plugin-updater: run loader activate() after deploy under opencode too",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-07-01T10:13:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fc37b3d618c88c481a209d3cbbc33d124d385f9",
          "body": "When false, earlyLaunch skips selfUpdate, npm-plugin updates, and git\npull/rebuild for already-cloned plugins — manual-only mode. Plugins not\nyet cloned still receive a full clone+build so freshly-added plugins work\nimmediately. Composes with self_update: both must be true for selfUpdate\nto run.",
          "is_bot": false,
          "headline": "feat(config): add update_on_launch knob (default true)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T21:59:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf7d3c90fcb0425ee011994d29d64d777a6dd53a",
          "body": "defineConfig now registers all 7 settings with production-matching\ndefaults. Each is wired to its call site: git/npm/build execSync\ntimeouts, AbortController timeout in isDaemonHealthy, self_update guard\naround selfUpdate(), and default_update_interval_hours as the fallback\nfor plugin.updateInterval ?? <cfg>.",
          "is_bot": false,
          "headline": "Add config knobs: timeouts, self_update, default_update_interval_hours",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T21:44:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9802e967f7aee305dd1adda6610aa48c4cf3456",
          "body": "…ault)",
          "is_bot": false,
          "headline": "fix(init): default to 'both' when cwd gives no app signal (was no def…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T13:01:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d4bf331e720e6dd2eaf5eb0dbb47ca332258418",
          "body": "…t pick from neutral dirs",
          "is_bot": false,
          "headline": "fix(init): no default app unless cwd is a config dir; require explici…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T12:46:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55b57ad23d62aa80ea2d97def6e04afcb12b9aaa",
          "body": "…app ambiguous, handle tuple plugin entries",
          "is_bot": false,
          "headline": "feat(init): edit existing opencode.jsonc (no dup .json), prompt when …",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T12:26:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5ee44a0cde0b4fb6d453dafa53226600841e3e5",
          "body": "…tAppName import",
          "is_bot": false,
          "headline": "fix(config): isolate commands test from real ~/.claude + drop dead ge…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T11:44:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "716a80e3ce26ae22ca465ad42221db85a260d3f1",
          "body": "…ugin settings",
          "is_bot": false,
          "headline": "feat(config): add unified /config command dispatching global + per-pl…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-30T11:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d03e98c63b81625a4d712abcabff9eff4571d08",
          "body": "…ted on launch",
          "is_bot": false,
          "headline": "docs: config is loader-editable (Plugins -> Configure), not auto-crea…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T17:24:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6586bbec7481c8184693b9049bbf3be6f92a67d4",
          "body": "…son on launch)",
          "is_bot": false,
          "headline": "chore: release 1.3.5 (register-only defineConfig; no plugin-updater.j…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T17:20:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e00f197396c0ad1baf832256d9cfd4325d879b6",
          "body": "…launch\n\nBumps bundled core to register-only defineConfig + the 'config schema' CLI verb.\nConfig defaults are now registered (for discovery/editing) without creating a file;\na config appears only when a value is actually changed.",
          "is_bot": false,
          "headline": "feat(config): declare settings via defineConfig — nothing written on …",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T17:20:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c30e59c62ef28afebe44e82d46938031d9ac4496",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump core (ensureConfig skips trivial configs); release v1.3.4",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T16:37:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0db90eb8169461a5ee22b5a8e461df95e6b762b",
          "body": "…ep READMEs in sync)",
          "is_bot": false,
          "headline": "docs: note auto-materialized config + global config/settings.json (ke…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05dc38f90092852aa4413e6b62758bcd255a9a2e",
          "body": "…'s ensureConfig; bump core (settings.json + ensureConfig). release v1.3.3",
          "is_bot": false,
          "headline": "feat(config): materialize plugin-updater.json on earlyLaunch via core…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T16:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d643460d639d436a5d6c52574c8fe1ee37c4af92",
          "body": "BUILD_OUTPUT_DIRS only copied dist + core/dist back from the symlink-free temp\nbuild, so after the core->core-loader rename the loaders' core-loader/dist/tui.js\n(the TUI, run as its own process) was never restored to the repo clone — oc/cc\nfound no TUI and fell through to plain opencode/claude. release v1.3.2",
          "is_bot": false,
          "headline": "fix(build): copy core-loader/dist back from the temp build (loader TUI)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T07:07:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dc859b918a01eaa4ba4546f5fa27dcf37eb6afc",
          "body": "The submodule's own core/.gitignore (dist/) made npm-packlist drop core/dist from\nthe published tarball, so dist/log.js + dist/commands.js could not resolve\n../core/dist/index.js and plugin-updater crashed on load (earlyLaunch skipped →\nno plugins set up). esbuild core -> root-level lib/core.js (force-shipped via files,\nno nested gitignore), import from ../lib/core.js. release v1.3.1",
          "is_bot": false,
          "headline": "fix(packaging): bundle core to lib/ so it actually ships",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T06:56:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51633924123fbe9634ad817539c308aec6485272",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v1.3.0",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-27T05:55:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "820fc97ec253b2e1fe8e590334e26ce74a9f8f27",
          "body": "…, global console toggle)\n\n- bump core submodule to the logger commit; replace inline writeLog with core's makeWriteLog\n- console output now mirrors to stderr (hook-safe) when global config/core.json logConsole / CORE_LOG_CONSOLE is on",
          "is_bot": false,
          "headline": "feat(log): route logging through core (prefix [plugin-updater], color…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T21:33:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1223ba520f2c55783db7ce84b660beacaa11d45e",
          "body": null,
          "is_bot": false,
          "headline": "ci: run tests before publish (gate releases on green tests)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T20:26:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ee0ac1500369aae6186eef73f9b37db0df36341",
          "body": "- bump core submodule; vitest devDep + build-then-vitest test script\n- src/__tests__/contract.test.ts: config round-trip + deployUpdaterCommands\n- tsconfig excludes *.test.ts from emit; vitest.config scoped to src/",
          "is_bot": false,
          "headline": "test: add core contract test + vitest",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T20:25:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "583e0c5287b81fd5789fc3d12f40b22fa86444d2",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v1.2.0",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T17:00:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "712bbaf5d3e2d660e36400c6b22c0fc39fa03956",
          "body": "…ne/container builds)",
          "is_bot": false,
          "headline": "build: add esbuild devDependency (npx esbuild step needs it for offli…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T16:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a0d00f39b20cece828be66b7c23698fd6c59215",
          "body": "- add core submodule (esbuild core/dist) for config CLI + the command framework\n- node dist/index.js config <list|get|set> runs the config CLI then exits (guard before self-activate)\n- deploy /plugin-updater-config to both apps each earlyLaunch (loaders own /plugins)\n- expand README with Structure/Installation/Commands/Configuration/Dependencies/Logging",
          "is_bot": false,
          "headline": "feat: integrate core, add /plugin-updater-config command",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T16:33:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4310417cefa4c86c3eaa5b7b2409199c377936c7",
          "body": null,
          "is_bot": false,
          "headline": "chore: migrate repository URLs to intisy-ai org",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T15:24:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b67a46a979da22041bd8ee7a38e1e20956f9cfb0",
          "body": "… — fixes intermittent double earlyLaunch when plugin-updater loads as 2 module instances",
          "is_bot": false,
          "headline": "index: make self-activation idempotent per process (ACTIVATION guard)…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T08:54:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad930ba45dad6895a863337c7243b3eda5ef9366",
          "body": "…--sync updates existing entry",
          "is_bot": false,
          "headline": "deploy: skip gracefully when built file is missing (no ENOENT); cli: …",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-26T07:48:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "054bc086ad2b7d4129456ddcb582a897ee9972c9",
          "body": null,
          "is_bot": false,
          "headline": "ci: guard against runaway patch versions (force minor bump at patch>=20)",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-25T17:16:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db056b628c1885406fe4d17f67574ec8faf5c65e",
          "body": null,
          "is_bot": false,
          "headline": "chore: align package.json to published 1.1.1",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-25T16:48:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53842d54c231a46171617c0989af7eb9280340bf",
          "body": "- earlyLaunch loads sync-bridge's dist/lib.js and runs syncPlugins() first, then\n  re-reads plugins so a synced-in plugin is cloned/built the same pass\n- Plugin.sync field + --sync CLI flag\n- set PLUGIN_UPDATER_ACTIVATION=1 on self-activate so loaders skip a duplicate earlyLaunch",
          "is_bot": false,
          "headline": "Add cross-app plugin sync (sync:true) + ensure single earlyLaunch",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-24T19:33:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae483ace412089bc01a6de69e885c424398f526b",
          "body": null,
          "is_bot": false,
          "headline": "v1.0.45: fast-path skips submodule sync/update unless drift detected",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-18T13:34:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1a0dbb4b605e5914a714c352fa52baf9cf900c6",
          "body": "… status' shows drift (+/-)\n\nPreviously every plugin with submodules ran a full 'git submodule sync' +\n'update --init --recursive' on every launch just to detect drift — the bulk of\nthe startup delay. Now do a cheap local status check first and only resync when a\nsubmodule is actually off its pinned commit or uninitialized.",
          "is_bot": false,
          "headline": "fast-path: skip expensive submodule sync/update unless 'git submodule…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-18T13:18:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79a0df0ae9a4ea8449d5a902b399c600740996d9",
          "body": "…alize metadata",
          "is_bot": false,
          "headline": "chore: untrack .idea + package-lock and ignore them; strip BOM / norm…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-17T20:24:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3e35b645b6adf13b69c10a38e081cf2c5d86808",
          "body": "…h (no more rm + interval wait)",
          "is_bot": false,
          "headline": "Fast-path: cheap ls-remote so pushed commits are picked up next launc…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-15T17:18:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d32605ecdc81f9ebfb6a99e93f175b5cd5449620",
          "body": "…ere out of sync",
          "is_bot": false,
          "headline": "Self-heal stale embedded submodules on fast-path; rebuild when they w…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-13T19:24:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3436f704fcab6ad9f05c07433647ce28848c8612",
          "body": "… command",
          "is_bot": false,
          "headline": "Prune orphaned repos/plugin entries not in plugins.json; add 'remove'…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-13T18:29:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67c471f2fc3c603ad7ed446f4ca7ff6008c5d1ec",
          "body": null,
          "is_bot": false,
          "headline": "Revert core-auth/dist copy-back; loaders no longer embed core-auth",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-13T11:19:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80b9fe58dfd320fc2a86a6ca04b0287ef84a42f2",
          "body": null,
          "is_bot": false,
          "headline": "Copy back core-auth/dist after build so loader submodule resolves",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-13T10:28:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5e321dd7ed885980e5b0631410fe6c656f45b4e",
          "body": null,
          "is_bot": false,
          "headline": "Remove stray .ai artifact; ignore it",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T13:16:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0ab23127b53313f94c8fba2ffc488293a42c202",
          "body": "…mon/deploy)\n\nSame behavior, now one concern per file per the modularity standard. Drops\nthe dead pluginUpdaterEntry and its unused input type. tsc-verified.",
          "is_bot": false,
          "headline": "Split index.ts into focused modules (types/env/log/config/npm/git/dae…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T13:16:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ef5cdb08edb5065b9d63d30e2e5bb8eb612b2b",
          "body": "…ugins.json",
          "is_bot": false,
          "headline": "Expose getPlugins/getPluginsPath as the single source of truth for pl…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T12:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cd73c89c9d48c26795b8d64bf11664e9350efa9",
          "body": "On deploy, health-check the plugin daemon and spawn it detached only if\ndown, so the loader proxy persists across the session. Generic for both\napps; reads script/runtime/port/healthCheckUrl from the manifest.",
          "is_bot": false,
          "headline": "Daemon manager: idempotent detached spawn from claudeHub.daemon",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T11:39:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6630cd12950c37fe3d010f1b806f62ff622efba",
          "body": "…sive earlyLaunch",
          "is_bot": false,
          "headline": "Set PLUGIN_UPDATER_ACTIVATION during activate() so loaders skip recur…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T08:58:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10ddb8c1ebcb1ff5919d2bcf39d4047e2f995572",
          "body": "detectApp falls back to which/where lookups of the claude and opencode\nbinaries when both or neither config dir exists, so --app is rarely\nneeded. A failed setup removes its plugins.json entry again instead of\nleaving a stale one. The SessionStart hook pins plugin-updater@latest\nso npx re-resolves instead of freezing its first cached version.",
          "is_bot": false,
          "headline": "CLI: binary-based app detection, rollback on failed add, @latest hook",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T08:40:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "707fd03417ad514c5c145185c1018f79bd1e651a",
          "body": "…o CLI exit",
          "is_bot": false,
          "headline": "Fail loudly when a clone fails: no lastcheck write, no deploy, nonzer…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T08:21:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46f4759d7a69ca0f26a74e9114a6da9512922d40",
          "body": "Plugins can declare a claudeHub block in package.json; under claude the\nupdater merges its env into settings.json on deploy (providers work\nwithout any subscription login) and logs declared daemons it does not\nmanage yet. Plugins with runtime dependencies get a prod install in the\nclone so their scripts resolve imports.",
          "is_bot": false,
          "headline": "Honor claudeHub manifests and install runtime dependencies",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T08:17:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d9bf74b9a609675b593829a1f40b740270a5276",
          "body": "init registers the engine itself (SessionStart hook in claude\nsettings.json, plugin entry in opencode.json) and creates an empty\nplugins.json; add appends any given git url and sets it up immediately;\nrun executes earlyLaunch for the hook. The engine stays plugin-agnostic:\nconsumers pass their url o\n[…]\ntection gains a\nPLUGIN_UPDATER_APP override since the CLI lacks claude in argv, and\nunder claude the updater invokes deployed plugins activate() itself,\nbecause Claude Code never imports plugin files.",
          "is_bot": false,
          "headline": "CLI: init/add/run for one-command bootstrap on both apps",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-11T08:06:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68d578b0406465a796f9157647fb7dafbfbe7541",
          "body": "… manual updates\n\ngit pull --ff-only and a plain submodule update could not survive the\nrewritten core-loader history: the submodule checkout failed and the\nbuild silently used the stale core. Updates now fetch and reset to the\nremote branch, force-sync submodules, and reclone from scratch if that\nstill fails. updatePluginPublic passes interval 0 so an explicit update\nrequest never fast-path-skips.",
          "is_bot": false,
          "headline": "Hard-sync clones and submodules; reclone on failure; no fast-path for…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T22:09:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31ad516eeb4055292df54c4efbb198638b71255d",
          "body": "The loader TUI deletes the enabled key to enable a plugin while\nearlyLaunch required it to be truthy, so entries without the key were\nskipped without any log line — the loader silently never deployed.\nOnly an explicit enabled: false disables now, and every skip is logged.",
          "is_bot": false,
          "headline": "Treat a missing enabled flag as enabled, log every skipped plugin",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T18:05:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28a064886c987a2a82807a44d4ff9965f9176afa",
          "body": "The loader TUI imports this module for its API; the import-time\nactivate() ran the whole update sequence inside the TUI process and\nwriteLog printed every line to the console, painting over the screen.\nPLUGIN_UPDATER_LIBRARY_MODE=1 limits the module to its exports.",
          "is_bot": false,
          "headline": "Library mode: skip import-time activation and console output",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T17:28:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bef9f31c618885f5727ad3faa9d4d84c6e603844",
          "body": null,
          "is_bot": false,
          "headline": "Detect npm plugin versions in opencode package cache",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T13:24:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59e72bdb29b1d6191db2c2fa6221276ed0605a93",
          "body": null,
          "is_bot": false,
          "headline": "Resolve npm global root via npm root -g instead of hardcoded paths",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T08:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c4a5fe9491917be90b6f7d59fd389067639bc23",
          "body": "npm install creates node_modules/.bin symlinks, which fail with EPERM on\nfilesystems without symlink support such as Windows-backed Docker bind\nmounts. Copy the plugin source (minus .git and node_modules) to a temp\ndir, run npm install and npm run build there, and copy dist/ and\ncore/dist/ back to the repo clone.",
          "is_bot": false,
          "headline": "Build plugins in OS temp dir to survive symlink-less filesystems",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T07:14:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2415895813f9cd0f2bc1378a4ce55d52f6f17eb3",
          "body": null,
          "is_bot": false,
          "headline": "Sync package-lock.json version to 1.0.26",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T07:01:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9663438b839155756320510d08813c5e17c48b6",
          "body": "opencode calls every exported function of a plugin module as a plugin\nfactory, passing a context object. That crashed module load (path.join\non an object: paths[0] must be of type string) and re-ran the full\nupdater sequence a second time via the exported activate(). Each export\nnow detects non-string protocol arguments and returns an inert value so\nopencode receives a valid empty plugin instance.",
          "is_bot": false,
          "headline": "Guard exports against opencode invoking them as plugin hooks",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T07:01:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9626171912dc43214359050f58ae1ef2f0580c9",
          "body": null,
          "is_bot": false,
          "headline": "fix: capture npm stderr in build failures for better diagnostics",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-10T05:34:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94a4215d342a021042e272b7de72a361c7b52204",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 1.0.24",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T23:29:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34e03b315c480fdbc61ad555bed436facf367663",
          "body": "…n startup\n\n\r\nPreviously pluginUpdaterEntry(null) at module load did nothing on startup,\r\nso git plugins (including opencode-loader) were never cloned on first install.",
          "is_bot": false,
          "headline": "Add activate() export that bootstraps git plugins from plugins.json o…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T20:54:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce4d79d715a62bcff6d19ef9a16f08972eef0263",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 1.0.22",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T20:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "769f931d6aa40c1ee5348a5e5780322499b330ec",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 1.0.21",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T20:21:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f701ae70fb79f5e1de4da00b59ebfe10bde5298b",
          "body": "…deployment",
          "is_bot": false,
          "headline": "Add cleanup hook support: call cleanup() on deployed plugin before re…",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T20:20:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9eb1820ab266a70a4f462e95e1e3029ddf6ffe0",
          "body": "\r\n- New exports: getNpmPlugins, installNpmPlugin, uninstallNpmPlugin, updateNpmPlugin\r\n- earlyLaunch now self-updates first, then updates all npm plugins from opencode.json\r\n- npm updates are interval-gated via per-package .lastcheck files\r\n- Converted repo to TypeScript (src/index.ts -> dist/index.js)",
          "is_bot": false,
          "headline": "feat: add npm plugin API and self-update support",
          "author_name": "intisy (Finn Birich)",
          "author_login": "intisy",
          "committed_at": "2026-06-09T17:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29a222e76ee2220683826ac3e98e12f2aaa45e33",
          "body": null,
          "is_bot": false,
          "headline": "perf: skip install and build if repository has not changed",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T11:41:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf3f32e9c7c260cdfffbac9c2a2df31b0c01741",
          "body": null,
          "is_bot": false,
          "headline": "fix: capture git stderr and force GCM_INTERACTIVE=never",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T07:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb1ac70cb6cdb202609da7b177d26bb966069dbf",
          "body": null,
          "is_bot": false,
          "headline": "fix: freeze log start time to prevent multiple log files per run",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T06:56:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01301cc03ecf5e2a6c718dd85aa10414b4a3217e",
          "body": "…ts, format log time",
          "is_bot": false,
          "headline": "fix: copy single file to .js instead of full directory, remove commen…",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T06:40:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "553e312156c6927fbddb44af560aa119700c8994",
          "body": "…ut.directory",
          "is_bot": false,
          "headline": "fix: correctly resolve configDir using getAppConfigDir instead of inp…",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T06:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e341546e2bf949fac8b1ff98be7d1b62019e789",
          "body": "…loader",
          "is_bot": false,
          "headline": "fix: bare function default export, no named exports for opencode NPM …",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T06:05:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2015978c308f5a6b9b681e82ad51ff9a15edb749",
          "body": null,
          "is_bot": false,
          "headline": "fix: use opencode V1 plugin contract (export default { id, server })",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T05:58:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b739311c6eb0299e5b7e3426b5fc066ce47da3c",
          "body": null,
          "is_bot": false,
          "headline": "fix: avoid Object.assign overwriting read-only Function.name",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T05:43:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7dbc752527cd39091570f7ef1e6216899b3e7d8c",
          "body": null,
          "is_bot": false,
          "headline": "fix: convert to native ESM for Bun compatibility",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-04T05:33:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "413bb27605fc7ff59c291868306a890fc676270f",
          "body": null,
          "is_bot": false,
          "headline": "fix: revert export structure to pure function",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T19:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb1358a95d6002eb1a50c997c18a7d4a14f96f5e",
          "body": null,
          "is_bot": false,
          "headline": "fix: export activate function directly for ESM interop",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T19:48:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d80243e4e90423477bfe9550f6271d18bfa0224",
          "body": "… crash",
          "is_bot": false,
          "headline": "fix: ensure repos/plugin dirs exist, add timestamp logging, fix build…",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T19:09:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90a56ab9ffb5d2c22f7f8b412e9b480c0c9c5d7d",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove BOM from files introduced by PowerShell",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T16:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce85c63a7e21168f291b63b38b933de9564d99d6",
          "body": null,
          "is_bot": false,
          "headline": "chore: restore --provenance flag now that OIDC is linked",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T16:42:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d36a49f690d77c74755785b3dbe8ed398d3a41da",
          "body": null,
          "is_bot": false,
          "headline": "fix: remove --provenance flag to test OIDC without provenance",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T16:36:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "775096186fa66ae9e29334607a0e9bec117d7ab4",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove BOM from package.json",
          "author_name": "Intisy",
          "author_login": "intisy",
          "committed_at": "2026-06-03T16:06:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 73,
      "commits_last_year": 112,
      "latest_release_at": "2026-07-18T20:00:07Z",
      "latest_release_tag": "v1.5.11",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 8,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 1.8
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "plugin-updater",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "opencode",
            "claude",
            "plugin",
            "updater",
            "lifecycle"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/plugin-updater",
          "is_deprecated": false,
          "latest_version": "1.5.11",
          "repository_url": "https://github.com/intisy-ai/plugin-updater",
          "versions_count": 63,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4965,
          "first_published_at": "2026-06-02T20:31:37.405000Z",
          "latest_published_at": "2026-07-18T20:03:56.434000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 18318,
      "source_files_sampled": 21,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "intisy",
          "commits": 112,
          "avatar_url": "https://avatars.githubusercontent.com/u/105643708?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7161f66bfc5e4734679b24130c09f3f55df5fcc4",
        "ran_at": "2026-07-24T05:55:36Z",
        "aggregate_score": 4.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/intisy-ai/plugin-updater",
    "host": "github.com",
    "name": "plugin-updater",
    "owner": "intisy-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 47,
      "inputs": {
        "security": 42,
        "vitality": 71,
        "community": 25,
        "governance": 37,
        "engineering": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 71,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 112,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 8
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "8/52 weeks with commits",
                "points": 5.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "112 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 112
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 73,
              "latest_release_tag": "v1.5.11",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 1.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "73 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 73
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 25,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "plugin-updater"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4965
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,965 downloads/month across npm",
                "points": 49.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4965,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 37,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "intisy-ai",
              "public_repos": 26,
              "account_age_days": 27
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of intisy-ai",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "intisy-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "26 public repos, account ~0 yr old",
                "points": 10.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 26
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "plugin-updater"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "63 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 63
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 56,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 42,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 47,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.83,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "83 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 83,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 18318,
              "source_files_sampled": 21,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/21 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 21,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:plugin-updater@1.5.11; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T05:55:41.826085Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/intisy-ai/plugin-updater.svg",
  "full_name": "intisy-ai/plugin-updater",
  "license_state": "absent",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.