Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [
"ai-assistant",
"chatbot",
"discord-bot",
"docker",
"memory",
"opencode",
"self-hosted"
],
"is_fork": false,
"size_kb": 28309,
"has_wiki": true,
"homepage": null,
"languages": {
"CSS": 46682,
"HTML": 1919,
"Shell": 146505,
"Python": 17473,
"Svelte": 838108,
"Dockerfile": 37123,
"JavaScript": 52713,
"PowerShell": 18689,
"TypeScript": 5280773
},
"pushed_at": "2026-08-01T06:29:12Z",
"created_at": "2026-02-17T05:56:04Z",
"owner_type": "User",
"updated_at": "2026-08-01T05:22:29Z",
"description": "Personal AI assistant(s) powered by OpenCode",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": "NOASSERTION",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript",
"Svelte"
]
},
"owner": {
"blog": null,
"name": "IT Lackey",
"type": "User",
"login": "itlackey",
"company": "Washington University in St. Louis",
"location": "St. Louis",
"followers": 39,
"avatar_url": "https://avatars.githubusercontent.com/u/6414031?v=4",
"created_at": "2014-01-15T22:04:37Z",
"is_verified": null,
"public_repos": 82,
"account_age_days": 4580
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "0.13.0-beta.15",
"kind": "prerelease",
"published_at": "2026-07-29T04:24:48Z"
},
{
"tag": "0.12.52",
"kind": "patch",
"published_at": "2026-06-30T16:35:27Z"
},
{
"tag": "platform-0.12.52",
"kind": "other",
"published_at": "2026-06-30T16:35:20Z"
},
{
"tag": "0.12.51",
"kind": "patch",
"published_at": "2026-06-30T06:41:55Z"
},
{
"tag": "platform-0.12.51",
"kind": "other",
"published_at": "2026-06-30T06:41:49Z"
},
{
"tag": "0.12.50",
"kind": "patch",
"published_at": "2026-06-29T22:28:44Z"
},
{
"tag": "platform-0.12.50",
"kind": "other",
"published_at": "2026-06-29T22:28:34Z"
},
{
"tag": "guardian-0.12.49",
"kind": "other",
"published_at": "2026-06-29T21:37:38Z"
},
{
"tag": "0.12.48",
"kind": "patch",
"published_at": "2026-06-29T20:03:20Z"
},
{
"tag": "platform-0.12.48",
"kind": "other",
"published_at": "2026-06-29T20:03:13Z"
},
{
"tag": "0.12.47",
"kind": "patch",
"published_at": "2026-06-29T17:46:09Z"
},
{
"tag": "platform-0.12.47",
"kind": "other",
"published_at": "2026-06-29T17:46:00Z"
},
{
"tag": "0.12.46",
"kind": "patch",
"published_at": "2026-06-29T16:42:06Z"
},
{
"tag": "platform-0.12.46",
"kind": "other",
"published_at": "2026-06-29T16:41:58Z"
},
{
"tag": "0.12.45",
"kind": "patch",
"published_at": "2026-06-29T15:36:43Z"
},
{
"tag": "platform-0.12.45",
"kind": "other",
"published_at": "2026-06-29T04:42:26Z"
},
{
"tag": "0.12.44",
"kind": "patch",
"published_at": "2026-06-26T17:47:51Z"
},
{
"tag": "electron-0.12.44",
"kind": "other",
"published_at": "2026-06-26T17:47:35Z"
},
{
"tag": "guardian-0.12.44",
"kind": "other",
"published_at": "2026-06-26T17:47:15Z"
},
{
"tag": "assistant-0.12.44",
"kind": "other",
"published_at": "2026-06-26T17:47:01Z"
},
{
"tag": "portals-0.12.44",
"kind": "other",
"published_at": "2026-06-26T17:46:45Z"
},
{
"tag": "platform-0.12.44",
"kind": "other",
"published_at": "2026-06-26T17:46:31Z"
},
{
"tag": "platform-0.12.44-beta.4",
"kind": "other",
"published_at": "2026-06-26T17:02:23Z"
},
{
"tag": "platform-0.12.44-beta.3",
"kind": "other",
"published_at": "2026-06-26T16:23:02Z"
},
{
"tag": "0.12.44-beta.2",
"kind": "prerelease",
"published_at": "2026-06-26T07:03:07Z"
},
{
"tag": "electron-0.12.44-beta.2",
"kind": "other",
"published_at": "2026-06-26T07:02:57Z"
},
{
"tag": "guardian-0.12.44-beta.2",
"kind": "other",
"published_at": "2026-06-26T07:02:45Z"
},
{
"tag": "assistant-0.12.44-beta.2",
"kind": "other",
"published_at": "2026-06-26T07:02:35Z"
},
{
"tag": "portals-0.12.44-beta.2",
"kind": "other",
"published_at": "2026-06-26T07:02:25Z"
},
{
"tag": "platform-0.12.44-beta.2",
"kind": "other",
"published_at": "2026-06-26T07:02:14Z"
},
{
"tag": "0.12.44-beta.1",
"kind": "prerelease",
"published_at": "2026-06-26T05:10:52Z"
},
{
"tag": "electron-0.12.44-beta.1",
"kind": "other",
"published_at": "2026-06-26T05:10:42Z"
},
{
"tag": "guardian-0.12.44-beta.1",
"kind": "other",
"published_at": "2026-06-26T05:10:31Z"
},
{
"tag": "assistant-0.12.44-beta.1",
"kind": "other",
"published_at": "2026-06-26T05:10:19Z"
},
{
"tag": "portals-0.12.44-beta.1",
"kind": "other",
"published_at": "2026-06-26T05:10:08Z"
},
{
"tag": "platform-0.12.44-beta.1",
"kind": "other",
"published_at": "2026-06-26T05:09:57Z"
},
{
"tag": "0.12.42",
"kind": "patch",
"published_at": "2026-06-25T03:28:16Z"
},
{
"tag": "electron-0.12.42",
"kind": "other",
"published_at": "2026-06-25T03:28:01Z"
},
{
"tag": "guardian-0.12.42",
"kind": "other",
"published_at": "2026-06-25T03:27:47Z"
},
{
"tag": "assistant-0.12.42",
"kind": "other",
"published_at": "2026-06-25T03:27:32Z"
},
{
"tag": "portals-0.12.42",
"kind": "other",
"published_at": "2026-06-25T03:27:18Z"
},
{
"tag": "platform-0.12.42",
"kind": "other",
"published_at": "2026-06-25T03:27:04Z"
},
{
"tag": "platform-0.12.43",
"kind": "other",
"published_at": "2026-06-25T03:25:48Z"
},
{
"tag": "electron-0.12.41",
"kind": "other",
"published_at": "2026-06-25T01:53:11Z"
},
{
"tag": "portals-0.12.41",
"kind": "other",
"published_at": "2026-06-25T01:51:17Z"
},
{
"tag": "platform-0.12.41",
"kind": "other",
"published_at": "2026-06-25T01:41:17Z"
},
{
"tag": "portals-0.12.34",
"kind": "other",
"published_at": "2026-06-24T20:45:39Z"
},
{
"tag": "platform-0.12.40",
"kind": "other",
"published_at": "2026-06-24T20:01:34Z"
},
{
"tag": "platform-0.12.39",
"kind": "other",
"published_at": "2026-06-24T19:19:41Z"
},
{
"tag": "platform-0.12.38",
"kind": "other",
"published_at": "2026-06-24T17:55:29Z"
},
{
"tag": "platform-0.12.37",
"kind": "other",
"published_at": "2026-06-24T17:10:57Z"
},
{
"tag": "platform-0.12.36",
"kind": "other",
"published_at": "2026-06-24T01:51:55Z"
},
{
"tag": "platform-0.12.35",
"kind": "other",
"published_at": "2026-06-23T20:02:09Z"
},
{
"tag": "platform-0.12.34",
"kind": "other",
"published_at": "2026-06-23T14:39:08Z"
},
{
"tag": "platform-0.12.33",
"kind": "other",
"published_at": "2026-06-23T13:49:36Z"
},
{
"tag": "platform-0.12.30",
"kind": "other",
"published_at": "2026-06-22T22:16:48Z"
},
{
"tag": "platform-0.12.29",
"kind": "other",
"published_at": "2026-06-22T17:21:29Z"
},
{
"tag": "platform-0.12.28",
"kind": "other",
"published_at": "2026-06-22T14:50:58Z"
},
{
"tag": "platform-0.12.27",
"kind": "other",
"published_at": "2026-06-22T02:03:34Z"
},
{
"tag": "platform-0.12.26",
"kind": "other",
"published_at": "2026-06-21T23:37:19Z"
},
{
"tag": "platform-0.12.25",
"kind": "other",
"published_at": "2026-06-21T23:02:19Z"
},
{
"tag": "platform-0.12.24",
"kind": "other",
"published_at": "2026-06-21T22:46:41Z"
},
{
"tag": "platform-0.12.23",
"kind": "other",
"published_at": "2026-06-21T22:28:47Z"
},
{
"tag": "electron-0.12.22",
"kind": "other",
"published_at": "2026-06-21T20:57:14Z"
},
{
"tag": "platform-0.12.22",
"kind": "other",
"published_at": "2026-06-21T20:24:24Z"
},
{
"tag": "guardian-0.12.21",
"kind": "other",
"published_at": "2026-06-21T19:45:00Z"
},
{
"tag": "guardian-0.12.20",
"kind": "other",
"published_at": "2026-06-21T06:19:30Z"
},
{
"tag": "images-0.12.19",
"kind": "other",
"published_at": "2026-06-21T06:09:17Z"
},
{
"tag": "guardian-0.12.19",
"kind": "other",
"published_at": "2026-06-21T05:37:40Z"
},
{
"tag": "images-0.12.18",
"kind": "other",
"published_at": "2026-06-21T04:53:56Z"
},
{
"tag": "platform-0.12.18",
"kind": "other",
"published_at": "2026-06-21T04:39:01Z"
},
{
"tag": "guardian-0.12.17",
"kind": "other",
"published_at": "2026-06-21T00:04:30Z"
},
{
"tag": "platform-0.12.16",
"kind": "other",
"published_at": "2026-06-20T21:43:58Z"
},
{
"tag": "guardian-0.12.15",
"kind": "other",
"published_at": "2026-06-20T21:23:10Z"
},
{
"tag": "guardian-0.12.14",
"kind": "other",
"published_at": "2026-06-20T21:17:48Z"
},
{
"tag": "guardian-0.12.12",
"kind": "other",
"published_at": "2026-06-20T21:12:03Z"
},
{
"tag": "guardian-0.12.11",
"kind": "other",
"published_at": "2026-06-20T20:58:50Z"
},
{
"tag": "platform-0.12.14-rc.9",
"kind": "other",
"published_at": "2026-06-20T00:35:52Z"
},
{
"tag": "platform-0.12.14-rc.8",
"kind": "other",
"published_at": "2026-06-19T22:04:14Z"
},
{
"tag": "platform-0.12.14-rc.7",
"kind": "other",
"published_at": "2026-06-19T21:16:05Z"
},
{
"tag": "platform-0.12.14-rc.6",
"kind": "other",
"published_at": "2026-06-19T20:51:23Z"
},
{
"tag": "platform-0.12.14-rc.5",
"kind": "other",
"published_at": "2026-06-19T19:57:07Z"
},
{
"tag": "platform-0.12.14-rc.4",
"kind": "other",
"published_at": "2026-06-19T19:04:59Z"
},
{
"tag": "platform-0.12.14-rc.3",
"kind": "other",
"published_at": "2026-06-19T14:35:46Z"
},
{
"tag": "platform-0.12.14-rc.2",
"kind": "other",
"published_at": "2026-06-18T23:53:12Z"
},
{
"tag": "platform-0.12.14-rc.1",
"kind": "other",
"published_at": "2026-06-18T21:35:27Z"
},
{
"tag": "platform-0.12.13",
"kind": "other",
"published_at": "2026-06-18T06:58:08Z"
},
{
"tag": "guardian-0.12.8",
"kind": "other",
"published_at": "2026-06-18T06:56:13Z"
},
{
"tag": "platform-0.12.12",
"kind": "other",
"published_at": "2026-06-18T03:29:45Z"
},
{
"tag": "guardian-0.12.7",
"kind": "other",
"published_at": "2026-06-18T01:29:57Z"
},
{
"tag": "platform-0.12.11",
"kind": "other",
"published_at": "2026-06-18T01:22:49Z"
},
{
"tag": "platform-0.12.9",
"kind": "other",
"published_at": "2026-06-17T22:14:56Z"
},
{
"tag": "platform-0.12.7",
"kind": "other",
"published_at": "2026-06-17T20:12:05Z"
},
{
"tag": "platform-0.12.6",
"kind": "other",
"published_at": "2026-06-17T18:30:18Z"
},
{
"tag": "platform-0.12.5",
"kind": "other",
"published_at": "2026-06-17T17:28:50Z"
},
{
"tag": "assistant-0.12.5",
"kind": "other",
"published_at": "2026-06-17T16:59:12Z"
},
{
"tag": "portals-0.12.6",
"kind": "other",
"published_at": "2026-06-17T16:58:36Z"
},
{
"tag": "guardian-0.12.5",
"kind": "other",
"published_at": "2026-06-17T16:57:54Z"
},
{
"tag": "portals-0.12.5",
"kind": "other",
"published_at": "2026-06-17T16:25:51Z"
},
{
"tag": "v0.12.4",
"kind": "patch",
"published_at": "2026-06-17T15:02:10Z"
}
],
"recent_commits": [
{
"oid": "11d81a31c7aff610ca04b39feb7590fd303b51a9",
"body": "Onboarding & setup: end-to-end review + fixes for the critical findings",
"is_bot": false,
"headline": "Merge pull request #594 from itlackey/claude/onboarding-ux-review-r043qu",
"author_name": "fwdslsh-dev",
"author_login": "fwdslsh-dev",
"committed_at": "2026-08-01T05:22:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6968966c8145b70b4cee10d5cf508ec6a0e16eca",
"body": null,
"is_bot": false,
"headline": "fix(ci): isolate overlay guard test from Docker",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-08-01T05:15:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b384565c8fcfb694255a76890cddd7bbdb523396",
"body": null,
"is_bot": false,
"headline": "fix: harden onboarding and release validation",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-08-01T04:32:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28a28cdfd9abccf99f4938758b7980706bbb90a4",
"body": "The wizard rewrites a host-loopback provider URL to host.docker.internal so\nthe assistant container can reach it, and that value is persisted into\nconfig/akm/config.json. But that file has two readers with opposite needs: the\ncontainer reads it over a bind mount and needs host.docker.internal, while\n[…]\n\nAlso drops an import left unused by the earlier writeFileInPlace switch.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(lib): give host-side akm runs a reachable provider endpoint",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T23:34:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "61f149b27b7c39e87eeece2934c4699e11481ed6",
"body": "auth.json is a single-file bind-mount source, so this PR's switch to an\natomic tmp+rename write silently detached running containers from it: they\nkeep the old inode and stop seeing host writes, while OpenCode inside the\nassistant keeps writing OAuth refreshes into the orphan. writeSecretFile now\nus\n[…]\n the interim deploy poll only\ncounts containers this up actually created.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(lib): resolve the review's lib findings",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T23:17:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2076565360b580e1e7f1d9f8a2436b192d4d5ad2",
"body": "lib and UI review-fix agents are still working. lib is at 1191 pass / 11 fail\nlocally — the 11 being the unchanged pre-existing root-sandbox uid/gid set.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight review fixes (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T23:05:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8e5da49f757dd8f8e2c484bb05f3f1a26c7fd214",
"body": "Fixes the three release-blocking defects the Opus review found, all verified\nagainst the installed electron-builder/electron-updater source:\n\n- NSIS artifactName is now GitHub-safe, so the on-disk name, the updater feed\n reference, the uploaded asset and checksums-sha256.txt all agree. Previously\n \n[…]\n a stream on cold rotation.\n\nlib and UI review fixes are still in flight.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint review fixes (release/CLI/Electron verified)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T23:04:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e8616acea00c5bd1d72e335db0a7ab7b1059eaac",
"body": "Removed in the previous commit on the strength of a local aggregate run that\nshowed them breaking ~84 packages/lib tests. That reading was wrong: this\nsandbox runs as root, so operator-id resolution fails and cascades — the base\ncommit shows 121 aggregate failures here while being green in CI. CI ra\n[…]\ning\nthe wording, now that the import affordance it names actually exists.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "test(cli): restore the bootstrapInstall tests",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:54:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "745364f49caa19c46801837c091f71feb5aa2689",
"body": "Follow-up to the previous commit, which went too far: removing the version\nkeys from the fallback template would break `compose up` outright, since the\ncompose files reference every one of them as ${OP_*_VERSION:?}.\n\nThe template keeps emitting them, now paired with their\nOP_MANAGED_<SERVICE>_VERSIO\n[…]\ne versions it wasn't\nasked to, and each still carries its managed marker.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(lib): seed version defaults with their managed markers",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:40:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "18305dc889ed9b8fbe59d441fff2f4ab0b5d893e",
"body": "…back template\n\nConsolidating the two stack.env generators made the fallback template\npre-populate all four service version keys. Those keys are only half the\ncontract: ensureVersionDefaults writes each one together with its\nOP_MANAGED_<SERVICE>_VERSION marker, and advanceManagedImageVersions uses t\n[…]\n/host/versions\n\"writes only requested tags\" test was the canary for this.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(lib): let ensureVersionDefaults own version seeding, not the fall…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:33:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6e07bc9c31c7567ad60a093aaacb4ec46a3585ee",
"body": "lib/stack agent progress: healthcheck reconciliation between the Dockerfiles\nand compose, with a new parity test to stop the two drifting again.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:26:31Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0f0be377d030b2ec9a38b3c6b7bacb6b9079a96e",
"body": "Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:23:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5da52fb49c8019bf7c6d0dc1328b7be012d831f0",
"body": "CLI and Electron sweeps are complete and locally green (207 and 166 tests,\nboth typecheck clean). lib/stack, wizard, and chat/UI are still mid-edit — the\napi/host/versions failure is fallout from the in-progress stack.env generator\nconsolidation, not a settled regression.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:22:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d1b25d8ad80293fb5131092a7ebc9a189395c68e",
"body": "Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:17:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "bb8eb21273887a58422bc94d7386f2809684be2a",
"body": "Closes the settings.test.ts gap the previous checkpoint captured: the\nhideToTrayNoticeShown setting had landed in settings.ts but its test had not\nyet been updated. Electron is locally green again (164 tests, typecheck clean).\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:17:01Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "74c231dbb15f852b8104798472a6cba4fa2bdcb2",
"body": "Fourth checkpoint. Includes the Electron updater.installOnQuit implementation\nthat the previous checkpoint captured a test for but not yet the code — that\nsnapshot's CI failure is resolved by this commit. Other agents remain mid-edit,\nso CI red here still carries no signal; verification happens against a settled\ntree.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:15:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ce0e4ab131c11396bd4803d4390c2416ad561531",
"body": "Third checkpoint of parallel sweep output. Agents are still mid-edit, so this\ntree is not expected to be internally consistent; CI red here is anticipated.\nThe Opus review over the finished batch gates what gets treated as done.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:13:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "917a38cd57253904f51fe4bea3e2b88aa9f5356c",
"body": "Deleting the dead admin-tools workspace left three dangling references the\ndeleting change could not reach: CI still ran a build step for the removed\ndirectory (failing the Electron job outright), and the release package-group\nmanifest still listed its package.json, which silently breaks version sta\n[…]\nso a future package removal fails loudly here instead of at\nrelease time.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "chore: drop the admin-tools references its removal left behind",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:13:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8145c2a8d4c29dd2c81b8adf812ea2651319294d",
"body": "Second checkpoint of parallel sweep output — release gate, CLI, Electron\nadmin-tools removal, and partial wizard/lib/chat work. Committed only so an\nephemeral container cannot lose it; several agents are still mid-edit, so the\ntree is not expected to be internally consistent at this commit. The Opus\nreview pass over the finished batch gates what gets treated as done.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T21:11:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f69b30b83965300191fc26adbc5764a5a2cda972",
"body": "Partial output from the parallel sweep agents, committed only so an ephemeral\ncontainer cannot lose it. Not yet reviewed or verified — the Opus review pass\nover this batch gates what gets treated as done.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight sweep work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T20:54:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "24ff1df34a4c936390641fc4cc70fbffad83e4bf",
"body": "The reconnect-reload added for the cold-start empty-chat state fired whenever\nsessions were not yet loaded, including while the INITIAL load was still in\nflight. loadSessions() bumps sessionsGeneration on entry, so the second call\nmade the first abandon its own result and return without ever setting\n[…]\nthe same\nrequirement is documented under system requirements and updates.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(chat): don't supersede the in-flight session load on connect",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T20:24:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "883389e0c9de01c5863c88b01b90ae47fc44c856",
"body": "The admin (:3880) and container (:3800) UIs shared one host-scoped op_session\ncookie but signed tokens with different per-process keys, so each surface\ninvalidated the other's session: finishing the wizard and clicking through to\nthe assistant UI forced a re-login, and with both tabs open the slidin\n[…]\nrd\"; and there is now a sign-out control, which no UI\npreviously offered.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(ui): repair the first-chat auth and error paths",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T19:12:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dfcc18121808e4f991277de65d4d2f4a67093457",
"body": "Snapshot of the auth and first-chat workstream while its agent is still\nwriting. Committed only so the work survives container reclamation:\nsyntax-checked, but not yet reviewed and tests have not been run against it.\nCorrectness is established in the follow-up commit that finishes it.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight auth/first-chat work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T19:06:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6af05e7b9b08ed46403dc580c17805994fe40481",
"body": "A first run without Docker seeded the home and minted guardian tokens before\nrequireDocker ever ran, so the re-run after installing Docker hit \"OpenPalm\nappears to already be installed\" and offered to back up an install that never\nexisted. The preflight now runs before any disk mutation (skipped onl\n[…]\n is\ndescribed in docs/reviews/onboarding-setup-review.md findings C1-C10.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(cli): run the Docker preflight before seeding OP_HOME",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T19:04:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "459d15e986717a3c8a57b812a4952d80b592e549",
"body": "Snapshot of the Electron, auth/chat, and wizard-provider workstreams while\ntheir agents are still writing. Committed only so the work survives container\nreclamation: syntax-checked, but not yet reviewed and tests have not been run\nagainst it. Correctness is established in the follow-up commits that finish\neach workstream.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight fix work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:59:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "84a3264db0398a6713bfc219a4491e37b5c760b2",
"body": "Snapshot of the CLI, Electron, wizard-provider, auth/chat, and installer\nworkstreams while their agents are still writing. Committed only so the work\nsurvives container reclamation: syntax-checked, but not yet reviewed and\ntests have not been run against it. Correctness is established in the\nfollow-up commits that finish each workstream.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight fix work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:56:01Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "25fbafd91fbdb534db73647fb3c3a656a379cb9d",
"body": "The wizard declared deploy phases the control plane never emitted and a row\nstatus nothing produced, so two of the worst first-run experiences were\ncontract mismatches rather than missing features.\n\nrunDeploy now enters 'pulling-images' before activateStack and polls compose ps\nread-only alongside i\n[…]\nsh no longer\nsilently regenerates the password the user was told to save.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(setup): make deploy progress and terminal states real",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:55:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dd4adea70f2bd5dabcf3c4bcd5cfcd9f3aa6b3a2",
"body": "Snapshot of work still being written by the deploy-pipeline, auth, and\nwizard-provider workstreams, committed only so it survives container\nreclamation. Syntax-checked but NOT yet reviewed and tests have not been run\nagainst it; correctness is verified in the follow-up commits that finish each\nworkstream.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "wip: checkpoint in-flight fix work (unreviewed)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:39:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b03d79445ff764df5c9ce3c4782cb5808ffe54af",
"body": "Download table now lists the real versioned asset filenames, including the\ntrap that the Intel mac zip carries no arch marker while the Apple Silicon\nbuild does, plus the previously-missing Linux arm64 AppImage and the libfuse2\ndependency. Notes that the desktop app currently ships only in the 0.13.\n[…]\nleanup uninstall leaves behind, AKM/principal definitions and a glossary.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "docs: correct onboarding docs from end-to-end review",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:37:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c875981a9c305105856462b9b2e7bc9752b2ddb9",
"body": "This endpoint verified the same password and minted the same op_session\ncookie as /api/auth/login, but never called checkLoginThrottle — so the\nlogin brute-force protection could be bypassed entirely by posting to the\nalias instead. Nothing referenced the route, so it is removed rather than\ngiven a duplicate copy of the throttle.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "fix(ui): remove unthrottled /api/auth/session alias",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:29:44Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a0ea8c8f548e9a81fe1489a3595d49a5f5044b06",
"body": "Full review of the new-user journey from download to first chat message:\ndocs accuracy, shell installers, CLI bootstrap, Electron first launch,\nsetup wizard, stack deploy, and the login/first-chat handoff. 4 critical,\n20 high, and ~80 medium/low findings with file:line evidence, cross-cutting\nthemes, and a prioritized action list.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LjLTdCAJyvwj5GEzK5rdbd",
"is_bot": false,
"headline": "docs: add end-to-end onboarding & setup review",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T18:06:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e22063e14223dafe15458fe70f912f2131ed0afe",
"body": "Ship every artifact complete; replace the runtime UI updater with full-app electron-updater releases",
"is_bot": false,
"headline": "Merge pull request #593 from itlackey/claude/openpalm-572-review-jsmpwo",
"author_name": "IT Lackey",
"author_login": "itlackey",
"committed_at": "2026-07-31T00:57:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b64b36e0a3840924a688871a95cf6755bad1eb5",
"body": "… manual update surface\n\nFive findings, all confirmed against the code rather than taken on trust.\n\nP1 — stable installs would never find an update. electron-updater turns\n`channel` straight into a feed FILENAME (getChannelFilename returns\n`${channel}.yml`) and its default channel is `latest`. Assig\n[…]\nests, svelte-check and Biome\nclean, whole-repo failures unchanged at 121.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SspKZ5yiSGNhStEzvkSouc",
"is_bot": false,
"headline": "fix(electron): address Codex review — feed channels, skeleton reseed,…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-31T00:47:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f79751e2eebad1c106fad77ec11a5f26b0506cfa",
"body": "The desktop app announced updates but could not install them: users had\nto find the release, download an installer and reinstall by hand, while\nthe UI it ran could move independently. Replace that with one update\noperation that installs a COMPLETE tested release — shell and bundled UI\ntogether, the \n[…]\nepo failures are\nunchanged at 121, all pre-existing on main.\n\nCloses #572\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SspKZ5yiSGNhStEzvkSouc",
"is_bot": false,
"headline": "feat(electron): full-application updates via electron-updater (#572)",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T22:43:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1ba41750b89318ab5a3ed48fabac4480cc8d18be",
"body": "The CLI embedded its UI build and skeleton from two tar.gz files that\nwere COMMITTED as tiny placeholders and overwritten in place by the\nbuild. Generated artifacts living at committed paths caused both\nproblems the review found:\n\n- a release binary compiled without the pack step embedded the\n plac\n[…]\npackages/cli is now green (182 pass, 0 fail); those three failed on main.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SspKZ5yiSGNhStEzvkSouc",
"is_bot": false,
"headline": "fix: generate embedded archives instead of committing placeholders",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T22:25:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "98f773f0a5987d7d26cacfdbfd3b329f56de25ec",
"body": "The CLI was the only artifact that did not carry the UI it serves.\nContainers bake it at image build; Electron ships it in extraResources;\nthe CLI downloaded a GitHub host-assets tarball into OP_HOME/data/ui at\nruntime. That one gap is what kept ~2,600 lines of download, version\narbitration, backup,\n[…]\nor now; replacing it with\nelectron-updater is #572's own work.\n\nRefs #572\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SspKZ5yiSGNhStEzvkSouc",
"is_bot": false,
"headline": "refactor: ship every artifact complete, delete the runtime UI updater",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T21:26:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "93b2f1cb50c3b9436d382b63f4d5686ab88233b2",
"body": "…ract\n\nReplace the thin-harness/harness-contract section in core-principles.md\nwith \"Artifact completeness and updates\". The old section was built on\nthe premise that re-downloading the desktop app should be avoided, which\nis what forced data/ui arbitration, two version lines (PLATFORM_VERSION\nvs HA\n[…]\nemove the Host UI row that was the last\nexception to that doc's own rule.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SspKZ5yiSGNhStEzvkSouc",
"is_bot": false,
"headline": "docs: make artifact completeness the rule, drop the thin-harness cont…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T20:17:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8537f8b431e8a668927107850b2cc52cb8315723",
"body": "…ogjpzw\n\nLAN access review Phase 1-2: consolidate network config, fix access toggles",
"is_bot": false,
"headline": "Merge pull request #592 from itlackey/claude/assistant-ui-lan-access-…",
"author_name": "IT Lackey",
"author_login": "itlackey",
"committed_at": "2026-07-30T05:45:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dd532a4a11e5e2a814a10f1937a788318eebe31",
"body": "Six of the seven findings reproduce. Each is a place this branch either broke\nsomething it had been holding correct, or promised a behaviour in a comment that\nthe code could not deliver.\n\nP1 — a bare `openpalm ui` honoured an ambient HOST as if a supervisor had set\nit. runUiBuild skipped the whole n\n[…]\nto the next locked\napply. Replying on the thread rather than changing it.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix: address the Codex review — six real gaps in this branch's own work",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T05:39:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "199b0fe4e07a778329548ff82639caf3885d8bb2",
"body": "Cleanup pass over the LAN-access rework. Every item is a place the branch's own\n\"one owner per question\" goal was stated and then missed - usually with a\ncomment acknowledging the duplication instead of removing it.\n\nReuse:\n- Extract net-interfaces.ts. lan-urls.ts's collectNonInternalIpv4 and\n mdns\n[…]\nformly, so converting one would\nmake that file less consistent, not more.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor: finish the consolidations this branch started",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T04:56:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "581865d6832770d29bf9a4cfdf5d538eec490665",
"body": "app.test.ts still expected `openpalm app` to open the browser at\nhttp://localhost:PORT and asserted the URL did NOT contain 127.0.0.1. This\nbranch unified that deliberately: resolveUiLoopbackHost pins one spelling for\nthe bind, the printed URL, ORIGIN and the browser open, because localhost and\n127.\n[…]\n login prompt on their very next command. Print UI_LOOPBACK_HOST instead.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(cli): open the setup wizard on the canonical loopback spelling",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T04:04:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1da47c646e59f8d0b5c0116d8ec3403e90a80a9b",
"body": "…migrated\"\n\nThe activation-audit rollback test pinned stack.env to a literal, so the new\naccess-intent migration (home schema v5) failed it: applyManagedFiles runs\nrunHomeMigrations BEFORE it snapshots, deliberately, so the snapshot it rolls\nback to carries the migrated file. That ordering is right \n[…]\ns a key no longer has to be transcribed\ninto this test to keep it honest.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "test(deploy): express the rollback assertion as \"pre-deploy file, as …",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T03:57:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3b3739bdb5b94f595e2d51d59d9f00ee1c571815",
"body": "CI's thin-harness boundary check flagged four @openpalm/lib imports added by\nthis branch. Three are legitimate bootstrap symbols; one is a real violation.\n\nrunHomeMigrations was called from both launchers so a UI child could never\nboot on an unmigrated home. In the Electron harness that is exactly w\n[…]\nin.test.ts and\nui-server.test.ts were updated when that contract changed.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(harness): move home migrations out of the frozen Electron harness",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T03:54:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "16210fd622ef3c129583e3285f12b7eccc8d1cbb",
"body": "…xists\n\nThe LAN-voice opt-in granted the network path but the co-process still\nrefused. Both gates — the /voice advertisement in computeVoiceRuntime and the\nproxy's own availability check — decide by reading\n`listEnabledAddonIds(getState().homeDir)`. In the container that home is\n`$HOME/.openpalm` i\n[…]\nS\nthe in-container state that broke it; verified failing without the fix.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(voice): let the container UI actually serve voice once the path e…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T03:43:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "62dbf91cf114c3febd7cf568479a57f573f38a87",
"body": "Voice worked on the desktop UI and silently 503'd on the LAN-published one.\nThe container-served UI co-process was hard-blocked: the entrypoint set\nOP_UI_NO_LOCAL_VOICE=1 because the assistant container has no loopback path\nto a sibling container, and voice joined addon_net only.\n\nOP_VOICE_LAN_ACCES\n[…]\nnfig` against a home with the setting on is\nwhat would confirm the merge.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "feat(voice): let the LAN-published UI serve voice, toggleable per addon",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T03:20:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8c5a6cb4f711ccdef195ef166336fbef4e9035aa",
"body": "The assessment was written as a plan, in the future tense; all four phases have\nnow landed across 19 commits. Records what shipped against each phase, the one\nitem deliberately left undone (voice on the LAN UI, which needs an addon\ntrust-boundary decision rather than a refactor), the follow-up the w\n[…]\nthat the LAN e2e is collected but\nunexecuted in a sandbox with no Docker.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "docs(roadmap): record the implemented state of the LAN-access review",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:35:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a6a67a5b74b61f1b8aaa0580a8f18778a6993bde",
"body": "…be in tests\n\nThe new port-literal guard shipped with five entries allowlisted as\n\"PRE-EXISTING debt\": a re-declared DEFAULT_ASSISTANT_PORT in the CLI's ports.ts\n(two lines below where the same file already imports the canonical UI port), a\nre-declared assistant/UI pair in mdns-responder.ts (same pa\n[…]\ntion being\nrefused in order to stay offline — the seam exists, so use it.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor: retire the last duplicate port constants; stub the mDNS pro…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:34:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b9abe0909e11ef6d187d7c0733ad16c7eed9c9ee",
"body": "Three guards against the failure modes the review found recurring.\n\nHarness parity. The recurring defect was two harnesses answering the same\nquestion differently from the same home: Electron ignoring a persisted\nOP_HOST_UI_PORT the CLI honoured, its child-env spread inverting live-vs-\npersisted pre\n[…]\n agent's behalf after verifying: 43/43 pass, lint\nclean, typecheck clean.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "test: guard the invariants this subsystem kept losing",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:27:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b85fc69b9c370376d87097ba6c9eec2284bc49de",
"body": "Phase 2 of the LAN-access review (\"make the promise visible\"): no doc or\nscreen in the product ever stated the concrete address a person types on\ntheir phone, and the access toggles alone cannot answer it — a toggle is\nSTORED INTENT, and intent can outrun Compose reality (a save whose recreate\nfaile\n[…]\noggle save (since the apply may\nhave just made the front door reachable).\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "feat(ui,lib): answer \"what URL do I open on my phone, and does it work?\"",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:25:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c5f6b7e3b97ecb928325292b2630a8f46e5fe2ba",
"body": "The mDNS responder was a per-process singleton reconciled at only three call\nsites (startup, the stack PUT, setup complete), so only whichever process\nhappened to serve a write ever updated its adverts — a bare `openpalm`\nsupervisor running alongside `openpalm admin`, or Electron, kept advertising\nw\n[…]\ns\nworking unchanged; only this module's own tests needed the extra await.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(lib): converge mDNS across processes and gate it on a self-probe",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:24:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3c7ec8eb72fff5f102d2d597887355147f1cd231",
"body": "… truth\n\nPhase 2 documentation sweep from the ui-lan-access-review assessment. Every\nclaim below was checked against the current code, not carried over from the\nold model.\n\nremote-access-tls.md was the worst offender: its Guardian step told operators\nto keep OP_GUARDIAN_BIND_ADDRESS=127.0.0.1 and ha\n[…]\nESS_* stored-intent keys in environment-and-mounts.md, which had\nneither.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "docs: sweep LAN-access docs for the flat toggle model, /oc, and voice…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:19:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "84a3f38409fb510422dd462e2602acb06b4918fb",
"body": "…g copy\n\n`ACCESS_TOGGLE_DESCRIPTIONS.assistantDirect` has always promised the\ngenerated OpenCode key is \"shown in the dashboard\", but nothing ever served\nit — its only reader was the server-side proxy's own credential resolver.\nCompleting the toggle (pointing a third-party OpenCode client, or anothe\n[…]\nr\n recreate + mDNS reconcile as a side effect, so this stays a text fix.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(ui): serve the generated assistant key, fix stale rotation/pairin…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:16:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2fe86190a27fdc8a96e76a4e0a732c8c335c1d72",
"body": "Three origin checks ran on a state-changing request, and the framework's\ncontradicted the audited one. SvelteKit's form-CSRF check compares Origin\nagainst `event.url.origin`, which under adapter-node is the PINNED ORIGIN env\nvalue — so it 403'd any form-like POST (multipart/form-data, urlencoded,\nte\n[…]\nand it answered the pre-flat\nquestion differently from readAccessToggles.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor(ui,lib): one origin gate; split proxy-trust from bind-widening",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-30T00:00:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6da1779ba6422366bb9e72165106a23a8bdcce2e",
"body": "The desktop app spawned a second, ephemeral OpenCode on every launch with its\nown staged HOME and the admin-tools plugin. It was built to feed the connection\nbroker, which was deleted in Phase 3b, and after the /oc resolver split its\nonly remaining consumer was gone: nothing reads its URL, its runti\n[…]\n it managed to break chat\nunder Electron while appearing to be a feature.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor(electron): delete the unread admin OpenCode child",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:54:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3379fe771d036c58c67a742f5d634ac3149ddbc7",
"body": "Three implementations of the retired 3800/3810 port swap disagreed at the\nedges, and one of them ran in the UI's request path on every supervised boot.\nport-contract.ts re-derived the disk migration from magic literals — a live\nOP_ASSISTANT_PORT of '3800' was taken as proof of an inherited retired d\n[…]\nher to discard\nit — detection any formatting change would silently break.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor: one assistant resolver; delete the per-boot port shim",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:50:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d87c9e6d21b40af007c1a350ec58bfa7e4860250",
"body": "…th, one LAN gate\n\nThree ways the LAN front door could be broken or silently dead.\n\nThe in-container listen port read OP_UI_PORT with a 3000 default, but 3000 is\nthe target of the compose port mapping and cannot vary. OP_UI_PORT is the\nHOST-facing knob, so an operator who set it in custom.compose.ym\n[…]\nching the\ncontainer UI still meets the login wall with no session cookie.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(containers,ui): harden the container UI — fixed port, honest heal…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:44:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "64ae6cb55cd197572b5834b500cac2755ce76afa",
"body": "Intent was stored only as its own consequences — four bind addresses — and\nread back by inferring 'is this loopback?'. Inference and Compose's own\nprecedence could disagree, in both directions, and the next save made the\nwrong reading real. The churn history returns to this repeatedly:\n\n- a shared-g\n[…]\ne never moves a bind.\n\nFull suite: 1764 pass / 147 fail, no new failures.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor(lib,ui): store network-access intent instead of inferring it",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:39:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "701ddc6e947d8049cf938b072429ea2fb3647a80",
"body": "'Which port does the host UI listen on' had seven answers: an explicit\n--port, PORT, OP_HOST_UI_PORT from live env, the same key from persisted\nstack.env, three independent 3880 constants, and inline ?? 3880 fallbacks in\nUI routes. Two of those divergences were real bugs:\n\n- Electron read live env A\n[…]\nose comment\nclaimed hooks.server.ts imported it — nothing did but a test.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "refactor(lib,cli,electron,ui): one owner for the host UI's port and bind",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:31:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "333fa1a490df834d2fe1d89ac45cd80573fb86b0",
"body": "…ng a recorded pid\n\nElectron had neither of the two guards the CLI added as D1, and the failure\nwas user-visible. With a plain `openpalm` already serving a NON-admin UI on\n3880, launching the desktop app spawned a child that died instantly of\nEADDRINUSE — the exit handler only logged it — while wait\n[…]\nbe supersedes it: nothing is killed on the strength of a\nrecorded number.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(electron,lib): probe for an existing UI instance instead of killi…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:18:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ce7059c8eae9c39dad850ca0eaf24e8f470f4d9d",
"body": "… assistant\n\nTwo related holes in the same threat model.\n\nop_session_signing_key was never added to DELEGATED_SECRET_NAMES, so it\nstayed under knowledge/secrets — bind-mounted into the assistant at /stash\nand reachable by the agent's own bash tool. The key exists precisely so that\nan attacker holdin\n[…]\nne was injected. Same\ntreatment OP_UI_NO_LOCAL_VOICE already gives voice.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(lib,ui): keep the session signing key and LAN password out of the…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:09:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "74277dbb1e6f5cedf554443c7ee0e862decb223b",
"body": "The bind addresses, OPENCODE_AUTH and GUARDIAN_DIRECT_INGRESS reach Docker\nonly through Compose interpolation, which is re-read when a container is\nRECREATED. Both affordances the product pointed operators at — `openpalm\nrestart` and the Containers-tab restart button — run `docker compose\nrestart`, \n[…]\n\nFull suite: 1726 pass / 147 fail, against 1703 / 147 before this branch.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "feat(lib,ui): make saving access toggles actually apply them",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T23:04:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "536d28762af33ed76e4f95e6bf9343887db83425",
"body": "createOpenCodeClient accepted only a baseUrl and sent no Authorization\nheader. OpenCode authenticates EVERY client, loopback included, as soon as\nthe assistantDirect toggle turns its auth on — so enabling that toggle 401'd\nevery route built on this client: provider list and API-key writes, model\nrea\n[…]\n3 / 147 before this branch. The\n147 are pre-existing in this environment.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(lib,ui,cli): one credentialed OpenCode client, one encoder",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T22:54:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fa15fca75ec9026c78f6e4abcd5e33283114b5ab",
"body": "…dmin child\n\ngetHostOpencodeTarget() resolved 'the host's own OpenCode' with a precedence\n— the Electron-spawned admin child first, the env-derived assistant second —\nwhich conflated two servers with different purposes behind one name.\n\nUnder Electron with a real install the consequences were severe\n[…]\ne resolver), which is how three high-severity defects\nlived here at once.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(ui): point every OpenCode call at the assistant, not Electron's a…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T22:36:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "24513424c6d45b7f4fa5c9c6c0b18d77dcb7d5e6",
"body": "The proxy armed a 30s header-arrival timeout on the theory that headers\nalways arrive quickly and only bodies stream. That is false for the request\nthat matters most: OpenCode returns the headers of\nPOST /session/:id/message when the TURN COMPLETES. Every tool-using or\nlong-reasoning turn on the loc\n[…]\ne arms no abort of its own, while still pinning client-abort\nforwarding.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(ui): stop /oc aborting chat turns longer than 30 seconds",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T19:12:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "91947068747c1124d2a288e0fce0063b62763775",
"body": "`openpalm install` (and bare `openpalm` on a fresh machine) spawned the UI\nwithout `adminHostUi`, so the child advertised no host:setup capability.\nWith the skeleton already materialized the home classifies as\nsetup_incomplete, so the UI redirected every navigation to /setup — which\nthe same process\n[…]\nxercised\ntheir composition, which is how this shipped. The new tests do.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "fix(cli,ui): serve the setup wizard from an admin-capable process",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T19:12:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ffba7c80d489e7342a81ac5f8e20b129298b221e",
"body": "…eness\n\nThorough review of the code managing access to the assistant UI and\nOpenCode: seven subsystem reviews, six adversarially verified\nhigh-severity defects, structural diagnosis (duplicated sources of\ntruth, intent inferred from consequences, write/apply decoupling,\nmigration shims in the reques\n[…]\nhased simplification\nplan converging three independent design exercises.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VXdQeLdLxXkaSSq26N7t9s",
"is_bot": false,
"headline": "docs(roadmap): assessment of assistant UI serving + LAN access brittl…",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-07-29T18:51:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "58d648514b3e5d3bcd45e5db65fcffa2020b3d3e",
"body": "… 26.15\n\nelectron-builder ≥26.15 validates executableName; the default derived\nfrom the package name (@openpalm/electron → \"@openpalmelectron\")\ncontains '@' and fails the new check, breaking the Linux AppImage leg.\nName the executable openpalm explicitly. Verified with a local AppImage\nbuild; nothing references the old derived name.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "fix(electron): set explicit linux executableName for electron-builder…",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T17:21:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "69ca03560a6ad95ab325a092389321390edf7887",
"body": "opencode-ai 1.17.13 → 1.18.9 in both image tool manifests (lockstep),\n@opencode-ai/sdk + /plugin 1.17.7 → 1.18.9, and every workspace\ndependency to latest: Electron 43, electron-builder 26.15, @slack/bolt\n5, discord.js 14.27, MCP SDK 1.30, SvelteKit 2.70, vite 8.1.5, svelte\n5.56, vitest 4.1.10, Play\n[…]\nDir\nline, one citation shifted +1), and the doc header now reads 1.18.9.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(deps): bump all dependencies to latest",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T17:04:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8c45c97d557feb9258eefe38ce6f982a4c652b0f",
"body": "…in rule\n\nPer maintainer approval: remove the two dangling §S1 citations (the\ncited public-seams-review.md was deleted; the rationale was already\ninline), collapse the Tooling feature list to its one actual principle,\ncut the changelog narration from the Logs section and the thin-harness\nrule, and m\n[…]\nasserts the assistant and guardian tools\nmanifests pin the same version.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "docs(core-principles): approved trim — drop dangling cites, enforce p…",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:43:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1aaddce270c1cdf91cfb7c6b9ede30a258ae1d0d",
"body": "Remove the Key Files rows duplicating the rules-documents table, the\nType Checking section and test examples that restated the commands\nabove them, the rotting \"~100 test files\" count (actual: 379), and the\nfilesystem table that copied core-principles.md's authoritative one\n(now a pointer plus the o\n[…]\n, and correct OPTIONAL_SERVICES to MANAGED_SERVICES in the\ntypes.ts row.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "docs: trim AGENTS.md duplication and fix stale constant",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:28:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9a10a917f4388cdfadfdabd0bb81da538a7b6216",
"body": "Fold in the rules that lived only in the local CLAUDE.md — the\nuser-data deletion protection, the flat access model guard, and the\nno-boot-time-install invariant — and fix two inaccuracies: the root\ntest row now lists the real aggregate scope (plus the root-.env\nworktree caveat), and the delivery ch\n[…]\nest\nand lint gates. The gitignored CLAUDE.md is now just a pointer here.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "docs: make AGENTS.md the single instruction source",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:11:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "be93fe51925ebce50d580129e6bc1c25359dfc1f",
"body": "- Merge release-architecture/-management/-rc-runbook and the unit=all\n checklist tombstone into one docs/operations/release.md (fixing the\n stale \"six CLI binaries\" count — the workflow ships five), delete the\n install-update-constitution redirect stub, and repoint all inbound\n links.\n- AGENTS.m\n[…]\nename; fix final-four-plan's reference to the removed\n workflow script.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "docs: consolidate release docs and repair every stale reference",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:06:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "79b977e19149b4810dcc366ec233f16596ddbd66",
"body": "They lagged at beta.13 while the rest of the workspace was stamped to\nbeta.15; stamped via bump-unit.mjs so the whole workspace reads one\nversion again.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(release): align guardian and portal manifests to 0.13.0-beta.15",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:05:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "50157d9cc8de5ab63ec61b5b2b9528493c87eeed",
"body": "OPENCODE_TIMEOUT_MS's only consumer (guardian forward.ts) was deleted in\n33d1388f and the OpenCode binary does not read it, so remove it from the\nshipped portals compose. Five comments cited docs/public-seams-review.md\n(deleted in cccf6464), three by section number; each already carried or\nnow carri\n[…]\nso unmangle\na mid-sentence TODO in the Slack question-rejection comment.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore: drop dead env var and stale doc pointers from shipped assets",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T16:05:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0b007f6c6308c09e43621e05a916e005bfdc5a52",
"body": "compute-version spent a whole runner and a full-history checkout on two\nvalidations (semver parse, live-publication ref restriction) that the\ncandidate job can do itself — candidate already checks out the same ref\nwith fetch-depth: 0. Move the validation step there as the first step\nafter checkout, \n[…]\nstrap\ngains a direct candidate edge it previously only had transitively.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(release): fold compute-version into the candidate job",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T14:20:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5db0018ef99755d8c381b3a03f53a0216fbcc845",
"body": "The compiled UI was built five times per release — in the assistant\nDocker leg, all three Electron matrix legs, and assemble-assets —\nproducing identical output each time. Build it once in a new ui-build\njob and download it into packages/ui/build wherever it is consumed,\nreusing the artifact hand-of\n[…]\nat all;\nthe Electron legs keep it for the electron bundle/builder steps.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "perf(release): build the UI once and share it via artifact",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T14:16:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "07a3844e682187726925ee14e1a4cba426b9e663",
"body": "…dits\n\npublish-extensions.yml required guardian/portal manifests to be\nhand-edited before dispatch and then only validated that the edits\nmatched. Stamp them from the dispatched version with bump-unit.mjs\ninstead (mirroring release.yml's candidate stamp), so packed tarballs\ncarry the right version a\n[…]\now exercises the stamp step in preview mode so it cannot dirty\nthe tree.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(release): stamp extension versions instead of validating hand-e…",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T14:14:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8ba7a6c08beef96ddc3b56652a7d47b61c08624b",
"body": "assert-docker-tag-monotonic.mjs queried an unauthenticated Docker Hub v2\nAPI to prove a new tag was semver-greater than published ones. The\nproduct release stopped using it, and publish-voice.yml already had a\nstronger authenticated guard: docker manifest inspect, refusing to push\nover an existing t\n[…]\nn the\nmanually dispatched model bundles; immutability is still enforced.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(release): replace tag-monotonic script with manifest exists-guards",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T14:14:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0b6ab5eb6e2660df40592a5edbe5cee075738820",
"body": "The 0.13 model has one explicit-version product release, so the\nregistry-anchored auto-bump machinery never executes: collapse\nbump-unit.mjs to a stamp-only script over release-package-groups.json\n(env VERSION replaces VERSION_OVERRIDE/BUMP), delete the orphaned and\ndrifted containers/assistant/VERS\n[…]\n\npackage.json scripts (analysis:fta was broken — nonexistent .fta.json).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(release): remove dead multi-unit release machinery",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:36:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1158785f284c2ac0a55edf03c956e0b53f79827b",
"body": "sessionOwnedByOther had zero callers; the live protection is proxy.ts's\nownsSession gate, and ownership is only recorded for fresh\nassistant-issued session ids, so there is no re-point path for it to\nguard. Also drop resolveUiChildLaunch's ignored _appMode parameter and\nthe appMode plumbing feeding \n[…]\n justified by a doc comment pointing at a test file\nthat does not exist.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore: delete unwired sessionOwnedByOther and dead appMode plumbing",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:31:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2b9b3b77423c5e450488bd75e8215ea4b7fe00fe",
"body": "- api/secrets.ts: drop the unused user-env client wrappers (the route\n uses @openpalm/lib's server-side functions directly)\n- client/constants.ts + types: drop abandoned PROVIDER_GROUPS /\n MAX_VISIBLE_MODELS and the orphaned ProviderGroup interface\n- lib/types.ts + types/providers.ts: drop unrefer\n[…]\n kept as a documented\n redefinition target in ui-styling-unification.md\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(ui): remove dead client wrappers, types, and legacy wizard CSS",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:23:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "353a49432bda0dfdac95efd93c36be4c098541b5",
"body": "Eleven paths.ts constants (guardianConfigDir, akmCacheDir,\nguardianAuditPath, assistantServiceDir, guardianServiceDir,\nguardianAkmDir, akmDataDir, taskLogDir, taskLogsRootDir,\ncoreComposePath, servicesComposePath), the hostAssetsError wrapper and\nits now-orphaned errMessage import, and the AccessSco\n[…]\n continuing paths.ts's own convention\nof pruning zero-consumer builders.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(lib): remove zero-consumer path helpers and dead exports",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:21:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7408dbdc7bec54d6389a5560113789573c3e0da4",
"body": "stream-render.test.ts imports buildPermissionBlocks/buildAnswerBlocks/\nbuildToolBlocks via their individual exports; nothing references the\n_internal bundle (unlike the guardian and portal-discord equivalents,\nwhich their tests do import and which stay).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(portal-slack): drop unused _internal test-helper export",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:20:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d1bdd31ba612244d1bd110bc2379fcf2bccdd786",
"body": "Nothing reads STT.device (health and callers use .ready/.error only), so\nthe property and its write-only _device/_compute_type backing fields go;\nTTS.synthesize reads _default_voice directly, leaving the default_voice\nproperty with zero readers.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(voice): remove unread STT.device and TTS.default_voice properties",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:18:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3b7523eaff884226788b2b93f55373535d714c3e",
"body": "warn() and its YELLOW color were defined but never called; every other\nhelper and script in scripts/ traced to a live caller.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "chore(scripts): remove unused warn() helper from setup.sh",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:14:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1d6c0535a97b1c180b6efd9d03085beb0c8e5d8f",
"body": "…image\n\nThe Google Workspace CLI was the last Google CLI baked into the assistant\nimage, and its only consumer is the gws-setup skill. Drop the Dockerfile\ninstall and add gws to the install-optional-tool manifest (npm\n@googleworkspace/cli, pinned to the previously baked 0.22.3) so it\ninstalls into /\n[…]\n gcloud pattern, and the skill docs no longer claim the image\nships gws.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RcgesDna8JKUQdtFSStMpX",
"is_bot": false,
"headline": "feat(assistant): install gws on demand instead of baking it into the …",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T07:11:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "af5c45bd49f5ad14ae7c1bd45c9023ab215d1164",
"body": null,
"is_bot": true,
"headline": "chore(release): prepare 0.13.0-beta.15",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-29T04:17:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fb17314279985f9e42ebe10b644829df96dc620",
"body": null,
"is_bot": false,
"headline": "fix(release): support npm 12 pack metadata",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T04:16:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "22199749d74bfb28765435877aac1ef476423198",
"body": null,
"is_bot": true,
"headline": "chore(release): prepare 0.13.0-beta.14",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-29T03:54:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec8043071f05e57cbe2ef3a1a66512d4fb687906",
"body": null,
"is_bot": false,
"headline": "fix(release): use x64 CLI on Windows ARM64",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T02:03:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b0127aa9bea55eff6429d0736f843904aa5f307",
"body": "Refactor/deployment model",
"is_bot": false,
"headline": "Merge pull request #591 from itlackey/refactor/deployment-model",
"author_name": "IT Lackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T01:44:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06a47643ebc6a3268454f8ffd525c284685aa2c9",
"body": null,
"is_bot": false,
"headline": "fix(ownership): harden secrets after host adoption",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T01:13:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "151565755c376526cb16adcb9320ce6495a95f15",
"body": null,
"is_bot": false,
"headline": "fix(smoke): provide exact dev image pins",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T01:07:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "221cdb9b371c3cebabf6d40ffe910dc86095ef79",
"body": null,
"is_bot": false,
"headline": "fix(ci): provide compose validation image pins",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T01:04:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc7000598394d0b7c59585a933eda46cd8d3d10f",
"body": null,
"is_bot": false,
"headline": "fix(release): resolve deployment review findings",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-29T01:01:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "846ec8efc33e1d2af59c8e6093c6fd7e4ff4f610",
"body": "Move the Discord and Slack adapter workspaces from the exceptional top-level portals tree to packages/portal-discord and packages/portal-slack.\n\nUpdate workspace metadata, lockfile entries, release groups, extension publication, candidate-local portal image packing, development commands, imports, documentation, and path contract tests to use the consolidated package layout.",
"is_bot": false,
"headline": "refactor(repo): group portal adapters under packages",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-28T23:42:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "554b79bc548dbe1690e246cb6393c600291d4bd7",
"body": "Replace the npm-coupled platform release with one coordinated product pipeline built from candidate-local source. Produce deterministic GitHub host assets containing the UI and skeleton, keep the public openpalm package as a zero-dependency binary launcher, and move Guardian and portal publication i\n[…]\ne and image verification paths, update documentation and release contracts, and add focused coverage for host assets, activation, immutable image restoration, extension ordering, and release assembly.",
"is_bot": false,
"headline": "refactor(release): simplify the 0.13 deployment model",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-28T23:35:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92570e82171368be22cd5a1cb5afa96beab107e0",
"body": "Expose the CUDA and cuDNN shared libraries bundled by the PyTorch wheel to ONNX Runtime in the cu121 entrypoint. Without those paths, ONNX advertised CUDAExecutionProvider but failed to load it when Kokoro created a session and silently fell back to CPU.\n\nValidate the provider list on the actual Kok\n[…]\nt the corrected runtime contract.\n\nVerified with real Kokoro WAV generation and faster-whisper transcription on NVIDIA GPUs, plus the full 1,993-test suite, UI checks, lint, and a rebuilt cu121 image.",
"is_bot": false,
"headline": "fix(voice): require real CUDA execution for Kokoro",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-28T17:35:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed2e8517bde3511fe472cc02b84c485efb576639",
"body": "Capture Guardian container logs once before checking baked-package receipts. Piping docker logs into grep -q under pipefail could report a false failure when grep exited after a match and docker received SIGPIPE, even though offline boot and both install skips succeeded.",
"is_bot": false,
"headline": "fix(smoke): avoid pipefail race in guardian log checks",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-28T16:04:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1282d034b237f43f1c9e326eab5af4e94cb10c77",
"body": "Keep the Assistant authentication guidance inside the task command block. The escaped comments had ended the YAML literal early, causing the shipped catalog automation validator to reject session-maintenance.yml.",
"is_bot": false,
"headline": "fix(tasks): restore valid session maintenance YAML",
"author_name": "itlackey",
"author_login": "itlackey",
"committed_at": "2026-07-28T15:58:34Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 100,
"commits_last_year": 3423,
"latest_release_at": "2026-07-29T04:24:48Z",
"latest_release_tag": "0.13.0-beta.15",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 22,
"days_since_latest_release": 3,
"mean_days_between_releases": 3.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "openpalm",
"exists": true,
"license": "MPL-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/openpalm",
"is_deprecated": false,
"latest_version": "0.12.52",
"repository_url": "https://github.com/itlackey/openpalm",
"versions_count": 151,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 3133,
"first_published_at": "2026-02-22T15:42:52.328000Z",
"latest_published_at": "2026-06-30T16:33:44.930000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 31
},
{
"name": "@openpalm/guardian",
"exists": true,
"license": "MPL-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@openpalm/guardian",
"is_deprecated": false,
"latest_version": "0.12.52",
"repository_url": "https://github.com/itlackey/openpalm",
"versions_count": 57,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2768,
"first_published_at": "2026-06-20T16:14:33.029000Z",
"latest_published_at": "2026-06-30T16:33:25.789000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 31
},
{
"name": "@openpalm/portal-sdk",
"exists": true,
"license": "MPL-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@openpalm/portal-sdk",
"is_deprecated": false,
"latest_version": "0.13.0-beta.1",
"repository_url": "https://github.com/itlackey/openpalm",
"versions_count": 13,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1952,
"first_published_at": "2026-07-11T22:03:10.015000Z",
"latest_published_at": "2026-07-11T22:03:10.249000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 20
},
{
"name": "@openpalm/slack-portal",
"exists": true,
"license": "MPL-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@openpalm/slack-portal",
"is_deprecated": false,
"latest_version": "0.12.44",
"repository_url": "https://github.com/itlackey/openpalm",
"versions_count": 20,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2271,
"first_published_at": "2026-06-22T21:04:19.067000Z",
"latest_published_at": "2026-06-26T17:32:36.857000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 35
},
{
"name": "@openpalm/discord-portal",
"exists": true,
"license": "MPL-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@openpalm/discord-portal",
"is_deprecated": false,
"latest_version": "0.12.44",
"repository_url": "https://github.com/itlackey/openpalm",
"versions_count": 20,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2280,
"first_published_at": "2026-06-22T21:04:09.440000Z",
"latest_published_at": "2026-06-26T17:32:39.131000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 35
}
]
},
"popularity": {
"forks": 0,
"stars": 35,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 5
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"packages/cli/tsconfig.json",
"packages/electron/tsconfig.json",
"packages/lib/tsconfig.json",
"packages/portal-sdk/tsconfig.json",
"packages/ui/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 68777,
"source_files_sampled": 822,
"oversized_source_files": 3,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 20342
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 11,
"malicious_count": 0,
"assessed_package": "npm:openpalm@0.12.52",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "electron-updater",
"manifest": "packages/electron/package.json",
"ecosystem": "npm",
"version_constraint": "^6.8.9"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "packages/guardian/package.json",
"ecosystem": "npm",
"version_constraint": "^1.30.0"
},
{
"name": "dotenv",
"manifest": "packages/lib/package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "multicast-dns",
"manifest": "packages/lib/package.json",
"ecosystem": "npm",
"version_constraint": "^7.2.5"
},
{
"name": "tar",
"manifest": "packages/lib/package.json",
"ecosystem": "npm",
"version_constraint": "^7.5.22"
},
{
"name": "yaml",
"manifest": "packages/lib/package.json",
"ecosystem": "npm",
"version_constraint": "^2.9.0"
},
{
"name": "@openpalm/portal-sdk",
"manifest": "packages/portal-discord/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "discord.js",
"manifest": "packages/portal-discord/package.json",
"ecosystem": "npm",
"version_constraint": "^14.27.0"
},
{
"name": "@opencode-ai/sdk",
"manifest": "packages/portal-sdk/package.json",
"ecosystem": "npm",
"version_constraint": "1.18.9"
},
{
"name": "@openpalm/portal-sdk",
"manifest": "packages/portal-slack/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@slack/bolt",
"manifest": "packages/portal-slack/package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 340,
"open_issues": 5,
"closed_ratio": 0.978,
"closed_issues": 225,
"closed_unmerged_prs": 23
},
"bus_factor": 1,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "itlackey",
"commits": 2050,
"avatar_url": "https://avatars.githubusercontent.com/u/6414031?v=4"
},
{
"type": "User",
"login": "claude",
"commits": 758,
"avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
},
{
"type": "User",
"login": "fwdslsh-dev",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/300268245?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.727
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"lint.yml",
"publish-assistant-models.yml",
"publish-extensions.yml",
"publish-voice-models.yml",
"publish-voice.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/1 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "46 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "11d81a31c7aff610ca04b39feb7590fd303b51a9",
"ran_at": "2026-08-01T09:25:23Z",
"aggregate_score": 4.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-08-01T05:22:34Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-08-01T05:22:16Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 22,
"created_at": "2026-02-18T18:06:39Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 426,
"created_at": "2026-06-03T00:44:30Z",
"last_comment_at": "2026-07-21T00:17:33Z",
"last_comment_author": "fwdslsh-dev"
},
{
"number": 430,
"created_at": "2026-06-05T03:48:13Z",
"last_comment_at": "2026-06-05T08:23:37Z",
"last_comment_author": "itlackey"
},
{
"number": 506,
"created_at": "2026-06-15T23:01:07Z",
"last_comment_at": "2026-07-21T04:14:50Z",
"last_comment_author": "fwdslsh-dev"
},
{
"number": 590,
"created_at": "2026-07-28T17:31:23Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/itlackey/openpalm",
"host": "github.com",
"name": "openpalm",
"owner": "itlackey"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 69 is calibrated to 81 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 69,
"calibrated": 81,
"calibration": "2026-08-02"
}
}
],
"value": 81,
"inputs": {
"security": 56,
"vitality": 83,
"community": 55,
"governance": 62,
"calibration": "2026-08-02",
"engineering": 84,
"ai_readiness": 75,
"weighted_overall_raw": 69
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 83,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"commits_last_year": 3423,
"human_commit_share": 0.98,
"days_since_last_push": 0,
"active_weeks_last_year": 22
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "22/52 weeks with commits",
"points": 15.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 22
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "3423 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 3423
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 100,
"latest_release_tag": "0.13.0-beta.15",
"releases_from_tags": false,
"days_since_latest_release": 3,
"mean_days_between_releases": 3.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.3 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 55,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"forks": 0,
"stars": 35,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "35 stars",
"points": 24.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 35
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 68,
"inputs": {
"packages": [
"openpalm",
"@openpalm/guardian",
"@openpalm/portal-sdk",
"@openpalm/slack-portal",
"@openpalm/discord-portal"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 12404
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "12,404 downloads/month across npm",
"points": 54.6,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 12404,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 62,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.727
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 73% of commits",
"points": 6.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 73
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"merged_prs": 340,
"open_issues": 5,
"closed_issues": 225,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 0.978,
"closed_unmerged_prs": 23,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "98% of issues closed",
"points": 41.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 98
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "340/363 decided PRs merged",
"points": 28.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 340,
"decided": 363
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/1 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 58,
"inputs": {
"followers": 39,
"owner_type": "User",
"is_verified": null,
"owner_login": "itlackey",
"public_repos": 82,
"account_age_days": 4580
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "39 followers of itlackey",
"points": 11.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 39,
"login": "itlackey"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "82 public repos, account ~12 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 82
}
},
{
"code": "account_age_years",
"params": {
"years": 12
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"openpalm",
"@openpalm/guardian",
"@openpalm/portal-sdk",
"@openpalm/slack-portal",
"@openpalm/discord-portal"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 20
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "5 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 5,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 20 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 20
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "151 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 151
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 84,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "7 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 7
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"topics": [
"ai-assistant",
"chatbot",
"discord-bot",
"docker",
"memory",
"opencode",
"self-hosted"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 56,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": null,
"notes": [],
"value": 45,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 4.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/1 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "46 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:openpalm@0.12.52 runtime dependency closure — what installing the published package pulls in — 11 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:openpalm@0.12.52",
"assessed": 11
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 11,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 11,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 75,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 20342
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "98 of 98 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 98,
"sampled": 98
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"packages/cli/tsconfig.json",
"packages/electron/tsconfig.json",
"packages/lib/tsconfig.json",
"packages/portal-sdk/tsconfig.json",
"packages/ui/tsconfig.json"
],
"agent_commit_share": 0.81,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "packages/cli/tsconfig.json, packages/electron/tsconfig.json, packages/lib/tsconfig.json, packages/portal-sdk/tsconfig.json, packages/ui/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/cli/tsconfig.json, packages/electron/tsconfig.json, packages/lib/tsconfig.json, packages/portal-sdk/tsconfig.json, packages/ui/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "81 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 81,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 68777,
"source_files_sampled": 822,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/822 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 822,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"library",
"application"
],
"labels": [
"chat-bot",
"mcp-server",
"library"
],
"scores": {
"library": 6,
"chat-bot": 12,
"mcp-server": 7,
"network-service": 2
},
"primary": "chat-bot",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "dependencies",
"label": "chat-bot",
"source": "dep:@slack/bolt",
"weight": 4
},
{
"tier": "dependencies",
"label": "chat-bot",
"source": "dep:discord.js",
"weight": 4
},
{
"tier": "dependencies",
"label": "mcp-server",
"source": "dep:@modelcontextprotocol/sdk",
"weight": 4
},
{
"tier": "structure",
"label": "mcp-server",
"source": "mcp_signal",
"weight": 3
},
{
"tier": "tags",
"label": "chat-bot",
"source": "tag:chatbot",
"weight": 2
},
{
"tier": "tags",
"label": "chat-bot",
"source": "tag:discord-bot",
"weight": 2
},
{
"tier": "tags",
"label": "network-service",
"source": "tag:self-hosted",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-08-01T09:25:38.842010Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/itlackey/openpalm.svg",
"full_name": "itlackey/openpalm",
"license_state": "custom",
"license_spdx": null
}