Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 5615,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 1492330,
"Rust": 710110,
"Shell": 37497,
"Makefile": 2984,
"Dockerfile": 8567,
"Go Template": 2270
},
"pushed_at": "2026-07-26T05:58:20Z",
"created_at": "2026-06-26T05:23:59Z",
"owner_type": "User",
"updated_at": "2026-07-26T05:57:49Z",
"description": "Multi-tenant, zero-trust durable POSIX disk for untrusted agents: per-agent mTLS, content-addressed chunk store, FUSE/NFS mount client.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go",
"Rust"
]
},
"owner": {
"blog": null,
"name": "Liu",
"type": "User",
"login": "liu1700",
"company": null,
"location": null,
"followers": 50,
"avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4",
"created_at": "2013-11-29T06:10:07Z",
"is_verified": null,
"public_repos": 52,
"account_age_days": 4624
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.4.5",
"kind": "patch",
"published_at": "2026-07-26T06:01:48Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2026-07-16T15:53:09Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2026-07-05T18:18:49Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2026-07-05T08:32:50Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-05T06:28:25Z"
},
{
"tag": "v0.3.3",
"kind": "patch",
"published_at": "2026-07-03T20:16:20Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-07-02T15:18:02Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-06-28T05:25:31Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-06-28T03:07:14Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-06-27T23:40:47Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-06-27T21:16:50Z"
}
],
"recent_commits": [
{
"oid": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
"body": "* fix: make live handoff portable to musl\n\n* fix: explain libc-specific length conversions",
"is_bot": false,
"headline": "Fix live handoff on musl release targets (#89)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-26T05:57:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "414a3d4180686647f6575d2b23d2c22de39869c0",
"body": null,
"is_bot": false,
"headline": "fix: stamp releases and configure mount paths (#88)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-26T05:37:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "49741d22ae372a268f80ddb7af2f2f8daf0b9ecc",
"body": null,
"is_bot": false,
"headline": "fix: add live FUSE mount handoff (#87)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-26T04:40:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bece032857ade7b4699489587d0c17d5e28b3dbb",
"body": "* fix: harden infra lifecycle and POSIX semantics\n\n* ci: disable VCS stamping in FUSE rig",
"is_bot": false,
"headline": "Harden mount lifecycle, POSIX semantics, and infra observability (#86)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-26T03:03:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9dd90b6f529952db0f0e2a7f763bc2d6461937d",
"body": "Refactor: shed datagateway-era residue, split worst-complexity paths",
"is_bot": false,
"headline": "Merge pull request #76 from liu1700/task/deep-refactor",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-16T15:46:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "88e373c9653970f86789fc412c8640280502445b",
"body": "- ORLOP_DATAGW_* env family renamed to ORLOP_* (old names remain accepted\n fallbacks via envKeyWithLegacy); helm chart + docs on the new names.\n- manifests.go: renameOpt (cognitive 86) split into five phase helpers;\n deleteSymlink/deleteSpecialNode clone collapsed. Rename/CAS/NOREPLACE\n behavior \n[…]\neck code.\n- Shared startTestServer helper collapses the 3-way control test-setup clone.\n\ngo build/vet/test, cargo build/test, clippy: all clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: shed datagateway-era residue, split worst-complexity paths",
"author_name": "liu1700",
"author_login": "liu1700",
"committed_at": "2026-07-16T06:35:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d44dd151cf2205251829b9a773b87ad2553609df",
"body": "Rename overwrites a compatible destination, so a caller that needs a collision-\nsafe atomic move (e.g. a restore into an occupied path) had to fall back to a\nstat-then-rename TOCTOU. Add a real create-only mode.\n\n- Wire: ManifestRenameRequest gains an optional no_replace flag (Go\n `,omitempty`; Rus\n[…]\ndataclient RenameNoReplace returns ErrExists over an existing dest;\nRust asserts no_replace=false is omitted and true round-trips.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dataplane): create-only rename (RENAME_NOREPLACE) (#75)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T17:31:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d97c3e1241d546724e61b2c00babd26ec0c87453",
"body": "…(#74)\n\nhandleManifestPut attaches a recovery hint (with the server's current version)\non an ESTALE conflict, so the client's StaleError.CurrentVersion is populated.\nhandleManifestDelete/handleManifestRename went through manifestErrToWire, which\nmapped ErrVersionConflict to a bare ESTALE with no hin\n[…]\n\nhint (used by manifest_put); older clients ignore it. Tests assert Delete and\nRename-source conflicts return the current version.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(dataplane): carry current version on Rename/Delete CAS conflicts …",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T17:18:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "65365caf04ec7c7c643eed8de4227fb9a576595f",
"body": "WriteFile uploads all content chunks (chunk_put) and only then commits the\nmanifest (manifest_put). chunk_put wrote the blob to disk but inserted no row\ninto the `chunks` refcount table — that row was created solely by\napplyChunkRefDelta inside manifest Put/Delete/Rename. So whenever manifest_put\nfa\n[…]\nC candidate with its real size; once referenced, re-noting leaves refcount and\nadded_at untouched and it is no longer a candidate.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(gc): reclaim chunks orphaned by an uncommitted WriteFile (#73)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T17:13:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f4f85566a6f0e3631dc94e1a554322745744bafd",
"body": "Two doc-accuracy fixes and one test-coverage gap from an adversarial review of\nthe whole-file object-ops surface. No behavior change.\n\n- ManifestRenameRequest.ExpectedVersionTo was documented \"0 = must-not-exist;\n otherwise CAS replace\", and ErrAlreadyExists was documented as returned by\n Rename o\n[…]\n tenant-only→\"\", and garbage/nil→\"\" fail-closed paths,\n so SAN-parsing drift is caught in unit CI instead of as a scoping outage.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(dataplane): correct Rename CAS docs; cover agentIDFromCertDER (#72)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T15:52:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8039c96429881d7fea565e02179262092b17d3be",
"body": "…e (#71)\n\nDial presented only the leaf certificate. orlop-server's client-CA pool is\nthe org ROOT ALONE (cert_tenant_binding.go), so a leaf signed by a tenant\nintermediate can't be verified from the leaf alone: in TLS 1.3 the client's\nhandshake \"succeeds\" but the server closes the connection right a\n[…]\ned a single self-signed CA, so this class of bug only shows\nagainst a real intermediate chain — which the live test now exercises.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(dataclient): present the tenant intermediate on Dial; add live e2…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T08:29:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2dd460641d13e25477f6764c9164959f17f73b35",
"body": "…ount (#70)\n\nAdds github.com/liu1700/orlop/dataclient: a Go client that speaks\norlop-server's binary mTLS frame protocol directly to list/read/write/\ndelete/rename an agent's files with no FUSE mount and no mount lease.\nReads are lease-free; writes are guarded by manifest CAS (ErrStale).\n\n- Enroll()\n[…]\ntays\nstdlib-only). No server changes. Tested with an in-process frame server\nand a real mTLS Dial round-trip; go test -race clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dataclient): Go data-plane client for whole-file ops without a m…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-05T06:23:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3862d13e84e830958e50245261d30195e76ffd4d",
"body": "…ecreate an orphan dir (#69)\n\nA data-plane connection resolves its *tenantState once at accept and reuses that\npointer for every frame (serveFrames -> identifyV2Peer -> goRequest). When\norlop-control purges a tenant (unregisterTenant: delete from map, db.Close,\nos.RemoveAll(tenantDir)), a chunk_put \n[…]\nstChunkPutOnClosedTenantReturnsESTALE — wire-level errno\n\n\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "server: gate tenant store writes on unregister so a dying pod can't r…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-03T20:06:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6192d82db97652f2c3f5e7b7da2c7093ceb3f289",
"body": "…(#68)\n\nLinter-guided (deadcode, staticcheck, golangci-lint, clippy) plus a manual\nsweep of all three trees. Net -1,700 lines with no behavior change except\nthe listed fixes. All tests pass; clippy is warning-clean.\n\nControl plane (net -875):\n- Delete 17 dead sqlc queries (the whole anonymous-sessio\n[…]\nre and\n .dockerignore; list advanced-usage.md in the README docs table.\n- Add CLAUDE.md (component map, build/test, invariants, docs pipeline).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: repo-wide dead-code purge, dedup, and doc/config alignment …",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-02T16:02:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6561135bac1bacc6536524914e4e44d64e0bf9b5",
"body": "…se (#67)\n\n* docs: fact-check and optimize all reference docs against the implementation\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images:\n[…]\nored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "server: stale mount connection can no longer kill its successor's lea…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-07-02T15:00:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ef4295caee0731951bbddc8c0726a5ea3fbb877f",
"body": "…tation (#66)\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images: document the real `orlop mount --from-env` env contract;\n drop the non-ex\n[…]\nS (it's NFS there).\n\nAlso normalize doc link style and point repo-file links at absolute GitHub URLs\nso they resolve on orlop.dev.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: fact-check and optimize all reference docs against the implemen…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T20:17:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d8ec8b1e1c0a6025b54bdc34c1200175bda89812",
"body": "…panion (#65)\n\nCut the standalone quickstart to the first-integration essentials (install →\nup → see the disk → stop → verify persistence) for a shell-fluent ops/backend\nreader. Everything past that minimal path — the agent paste block, install\noverrides, build-from-source, what `dev up` does, prefl\n[…]\nta lives, and\n`doctor` troubleshooting — moves to a new advanced-usage.md companion, linked\nfrom the quickstart's \"Going further\".\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: slim the quickstart to its minimal path; add advanced-usage com…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T18:24:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "925e83db30f04bed146c5fc3db2e9feae88ad18d",
"body": "Rewrite the agent-memory reference from a feature overview into a\npractical how-to: a local round-trip, then five abstracted steps for\ngiving an agent its own durable, isolated disk (allocate -> enroll ->\nmount -> read/write -> reattach), each with real commands and a verify.\n\nAdd a \"Where orlop sto\n[…]\nm) for positioning\nand SEO. The lead sentence is tuned so the auto-generated meta\ndescription leads with the keywords and JuiceFS.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: reframe agent-memory as a how-to (per-agent disk, SEO peers) (#64)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T15:43:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4fb39ab4c03dd309b36cb4965897d1c1c9ea5867",
"body": "Patch release consolidating the standalone dev-stack fixes (closes #51–#56):\nnon-interactive lifecycle (`dev up --detach` + `dev down`, #51), graceful\nshutdown exits 0 (#52), `status` liveness-probes UP/DEGRADED/DEAD (#53),\n`doctor --dev` + dev-up-aware warnings (#54), stable non-epoch directory mti\n[…]\n-compat — API major stays 1, no new migrations.\n\nBump version strings + the helm appVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: set version to 0.3.1 (#63)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T05:21:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e989d5d7319d498ae8e182f0f5451c9a89199e29",
"body": "… commands (#56) (#62)\n\nThe standalone quickstart was effectively 4 mental steps (verify ports/mount →\ninstall → doctor → dev up). Fold the host checks into `dev up` itself so the\nhappy path is just install + run.\n\n- `dev up` preflight now runs the same checks as `orlop doctor --dev` (mount\n suppor\n[…]\n busy port → fail-fast preflight with fix,\nexit 1; clean host → comes up; full install→up→write→down→up→file-survived\nwalkthrough.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dev): fold host preflight into `dev up`; shorten quickstart to 2…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T04:36:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8151a169f385bda6bc9b90a16b38346464bc763b",
"body": "Directories carry no manifest (only files do), so the macOS NFSv3 server passed\nmtime_ns = 0 for every directory — surfacing as `Dec 31 1969` in `ls -l` and\nconfusing tools that sort/filter by mtime.\n\nSynthesise a sane, stable timestamp for directories: capture the mount time\nonce (`started_ns`) and\n[…]\nserts dir getattr/readdir/root mtimes are non-zero and\nstable; e2e `ls -laR` on a live mount shows real timestamps with no `1969`.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(nfs): give directories a stable non-epoch mtime over NFS (#55) (#61)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T04:31:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8f1c7d590eb1b73238e304e3fbea2e74e6aedaf1",
"body": "On a clean host, `orlop doctor` warned about a missing config + credentials —\nirrelevant to `orlop dev up`, which supplies them out of band — so a first-time\nuser read the standalone quickstart as \"your setup is incomplete.\"\n\nAddress both options from the issue:\n- `orlop doctor --dev`: checks exactl\n[…]\n, exit 0; with a\nstack holding the ports → port checks FAIL, exit 1 with actionable fixes;\nplain `doctor` warnings mention dev up.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(doctor): make doctor aware of the `dev up` flow (#54) (#60)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T04:22:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4a4d7992ad98d72f0b4773f16a19c376a5ca50d6",
"body": "…#53) (#59)\n\n`orlop status` printed a hardcoded `dev stack: UP` header straight from the\ncached `dev.json`, so a stack that died uncleanly (kill -9, OOM, crash) still\nread as a healthy UP — even though the per-component lines already probed\nliveness.\n\nDerive the overall state by probing the supervis\n[…]\n to component health.\n\nTested e2e (macOS): healthy → UP; `kill -9` supervisor → DEAD (not UP) with\nhint; `dev down` → not running.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(status): report DEAD/DEGRADED from live probes, not a cached UP (…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T04:16:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "baea0110aef5efeed7aa1de1bfc22e096643d187",
"body": "A signal-initiated shutdown of `orlop dev up` is the documented, intended way\nto stop the stack, so it must be a success — a process supervisor or CI step\nshouldn't see a non-zero exit and mistake a normal stop for a crash.\n\nMake the exit status explicit and deterministic instead of always returning\n[…]\ntrol-plane child → tears the rest down and exits 1 naming the\ncrashed component. Unit tests cover the three shutdown_result cases.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(dev): make `dev up` exit status reflect why it stopped (#52) (#58)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T04:11:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e7db06aeee4e2249908ae72048a50110dfe2fbc2",
"body": "…ecycle (#51) (#57)\n\n`orlop dev up` only ran in the foreground, stoppable solely by Ctrl-C, so CI,\nbackgrounded jobs, IDEs, and agents had to PID-hunt the supervisor to stop it\n(and the naive pgrep selects the wrapper shell, whose SIGINT is dropped).\n\n- `dev up --detach`/`-d`: re-exec the supervisor\n[…]\n up --detach → status → I/O → down; crash (kill -9) →\ndown reconcile frees ports; foreground up stopped via down; idempotent down.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dev): add `dev down` + `dev up --detach` for non-interactive lif…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T03:57:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f970c5e397a4f298a6813ec6a74a57c8b594f965",
"body": "Feature release consolidating the consumer-feedback work: multi-arch GHCR\nimages (#47), a reference Helm chart (#48), control-plane API versioning +\nOpenAPI (#49), and upgrade-safety guards — CI in-place-upgrade test + boot\nschema self-check + migration policy (#46). All additive and back-compat\n(API major stays 1; no new migrations). Bump version strings + the helm\nappVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: set version to 0.3.0 (#50)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T03:02:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "04c96758e771a9b0023d51e940c97d58392d8d61",
"body": "… detection (#42) (#49)\n\nThe Go SDK and orlop-control agreed on REST paths and bodies only implicitly: it\nhappened to be byte-identical across v0.1.0 and v0.2.0, but there was no\ndocumented contract and no way to detect version skew — a mismatched pair would\nsurface as an opaque 4xx, and other-langu\n[…]\nd\n SDK/server (v0.1.0–v0.2.x) speaks major 1. Other-language clients implement\n from the spec and check the header the same way.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "api: version the control-plane API — OpenAPI spec + SDK<->server skew…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T01:22:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "992b59577ef12d776e6a8f448f531ffd1698b0a8",
"body": "… (#48)\n\nConsumers had to reverse-engineer the whole deployment from the binaries — the\nmigrate step, the CA/secrets topology, the mTLS self-provisioning, and a set of\ncross-component env constraints that are easy to get subtly wrong. This adds a\nreference chart (deploy/helm/orlop) that stands up a \n[…]\nallowed) and served mTLS on ops+data, both\nreached Ready, and `orlop-control server register` (the NOTES.txt next step)\nsucceeded.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "deploy: reference Helm chart for control + server on Kubernetes (#41)…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T01:11:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7e374f8d733c698a3b45208ea4782f436f18d1b2",
"body": "Consumers running orlop on Kubernetes had to rebuild from source every release —\nthe Go binaries are cheap, but the Rust mount client (libfuse3 + a multi-minute\ncargo build) is the painful one. Publish prebuilt multi-arch images instead.\n\nThe release workflow gains an `images` job (tag-only, sibling\n[…]\n and a multi-arch\n(amd64+arm64) buildx of the TARGETARCH-staged Dockerfile succeeds. The GHCR\npublish itself runs on the next tag.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "images: publish multi-arch GHCR images per release (#40) (#47)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T00:59:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "26974e8ba722703ceab8becb686c6cf0157a39c0",
"body": "…(#39) (#46)\n\nIn-place upgrades had no guarantee: squashing already-released migrations\n(#23) reset goose numbering, so a deployed v0.1.0 database skipped the\nsquashed baseline and silently lacked access_tokens.consumed_at and the\ncert_revocations table. goose reported success; the gap only surfaced\n[…]\nnd a v0.1.0 database without the bridge fails boot with the exact\nincident (missing cert_revocations + access_tokens.consumed_at).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "upgrade safety: CI guard + boot schema self-check + migration policy …",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T00:46:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f761e97f1410ef26a18903e9c7bbe12a86f9ceaa",
"body": "These two are required status checks on main. With their `pull_request`\npath filters, a PR touching no Go/Rust files (docs, config) never triggered\nthem, leaving the required `go`/`build` checks stuck \"Expected\" and the PR\nunmergeable. Drop the pull_request path filters so both always run and\nreport on every PR; this is the prerequisite for enforce_admins=true gating.\nPush-to-main path filters are left as-is.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: run go and build checks on every PR (not path-filtered) (#44)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T00:21:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f65cc0aaba21cb9eb2dff53ce353a2383d0c1e0e",
"body": "…l-bring-up (#43)\n\nThe quickstart still walked the six manual steps and ended with the fragile\n`kill %1 %2 %3` teardown, predating `orlop dev up`. Rewrite it around the\none-command path: install -> `orlop dev up` (+ `orlop status`) -> write a file,\nCtrl-C, bring it back up, watch it survive. Move th\n[…]\nthe\nrestart cycle preserves the file. Update README quickstart + docs table and the\ndatabase-backends cross-reference accordingly.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: make the quickstart `orlop dev up`-first; move by-hand to manua…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-28T00:15:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "31f723fa57b7129aacf2e20df7ef5dc094a61049",
"body": "Patch release: bridge migration (#38) so v0.2.0+ upgrades a database\nprovisioned by the pre-squash v0.1.x line. Update the install-version examples\nin the quickstart and the release workflow comment to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: set version to 0.2.1",
"author_name": "liu1700",
"author_login": "liu1700",
"committed_at": "2026-06-27T23:37:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a6f99c9a658579bfc89d7130f5a7bef103290c62",
"body": "…base (#38)\n\nThe squashed baseline (0001_init, #23) reset goose numbering to version 1, but a\ndatabase migrated by v0.1.0 is already at goose version 9 (from its original\n0001-0009 files). goose only applies versions greater than the current max, so on\nthose databases it skips the squashed baseline \n[…]\n010 and adds both objects; idempotent on re-run; a fresh DB applies\n0001+0010 to the same final schema. sqlc codegen is unchanged.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(db): bridge migration so v0.2.0 upgrades a pre-squash v0.1.x data…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T23:36:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a2131424eadf9acdd0a9914fb5f796c872538e84",
"body": "… dev up + status (#37)\n\n* cli: stop orlop-control booting a server on unknown args; add --version\n\n`orlop-control <anything>` fell through a bare os.Args[1] switch to run(),\nso a typo or `--version` silently started a control plane on :8080 with no\ndatabase configured. Classify the arguments instea\n[…]\npatch) read, removing\n the duplicated verb list.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "CLI UX: kill the orlop-control footgun, fix macOS unmount zombie, add…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T23:18:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d795efd448ba33bc8feb54d4182442473cb896c4",
"body": "Commit the standalone quickstart to a single SQLite happy path. Drop the\nPostgres/Docker branch (now a one-line pointer to database-backends.md),\nremove the optional `migrate up` step (SQLite applies its embedded schema\non open), and cut the duplicated gotchas and thrice-stated durability\nthesis. St\n[…]\nle blocks, the durability proof as the\npayoff. Net 126 lines removed.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: make the quickstart SQLite-only and tighter (#36)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T21:28:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b33819fc874e51177a4b13516791cd1f4fd34ccb",
"body": "1.0.0-rc.17 overstated maturity for a project still at v0.1.0. Move to\n0.2.0 and update the install-version examples in the quickstart and the\nrelease workflow comment to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: set version to 0.2.0 (#35)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T21:12:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f0227bbc27a01e0a3273f3b63578ba51bb2cc819",
"body": "GitHub's Intel macos-13 runners sat unassigned for hours and blocked the\nrelease. Build x86_64-apple-darwin on macos-14 instead (Go via GOARCH,\nRust via the x86_64-apple-darwin target), same runner as darwin/arm64.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: cross-compile darwin/amd64 on the Apple-Silicon runner (#34)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T21:04:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "eba5384c300065fa8071153e2f3a09fee6eb141d",
"body": "…l-first quickstart (#33)\n\n* release: cross-platform binary builds and install.sh\n\nAdd .github/workflows/release.yml: on a v* tag, build orlop, orlop-control,\nand orlop-server for linux/darwin x amd64/arm64 and publish tarballs +\nsha256 to the GitHub Release. Go binaries are pure-Go (modernc sqlite \n[…]\n the agent\nfast-path prompt are updated to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: prebuilt binaries (release workflow + install.sh) and instal…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T18:28:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f376213bc59742cf0930cb5b144dae516c099bc8",
"body": "…s (#32)\n\nRemoving the dead device-flow code (#31) left the two now-empty tables in the\nschema. Drop them from the Postgres squashed baseline and the SQLite schema, and\nregenerate sqlc so the dead DeviceAuthorization / RefreshToken models go away.\n\nNothing references these tables. go build/vet/test \n[…]\n(which applies schema.sql on open) and the sqlc-validated db package.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: drop the unused device_authorizations and refresh_tokens table…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T17:43:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "89ae5c0bd91a253470d347ca6cc3ff3c2545821d",
"body": "The orlop binary has no `orlop login` command and nothing drives the\ncontrol-plane device-code flow, so remove it end to end and make the docs match.\n\nControl plane (Go):\n- Remove the device routes (/auth/device/code|token, /auth/token/refresh,\n /device, /device/lookup, /device/approve) and their h\n[…]\nsurface.\n\nVerified: go build/vet/test and cargo build/test all green.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: remove the dead device-flow login subsystem (#31)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T17:34:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b5bbb9d7ef6e2ec00fd0565cec2bf0864d11fe56",
"body": "… (#30)\n\nRewrite the README and every docs/ page against the actual implementation,\nfixing factual drift and turning the internal design RFCs into reader-facing\nreferences.\n\n- Fact-checked every command, flag, env var, route, field, and behavior against\n the code. Corrected the major errors: design\n[…]\nark, light/dark wordmarks); the README now leads\n with the wordmark.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: fact-check and reframe all viewer-facing docs; add brand assets…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T16:31:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "25d7b705097358e97f5d053ebf783b2a93217c80",
"body": "Our SQLite/Postgres choice was buried inside the standalone quickstart as\n\"Option A/B\" with no single home, no comparison, and the caveats (single-node,\nCA-secrets backend constraint) scattered across the quickstart and code.\n\nRestructure it the way established multi-backend projects do — a dedicate\n[…]\n and the runbook's\nDATABASE_URL example point at it too.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add a canonical \"Database backends\" reference page (#29)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T14:58:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b88757661de7a50cd0ca50197a3242dea79b0ef3",
"body": "…(#28)\n\nWires the embedded SQLite backend in so the control plane actually runs on it.\nA storage.Store union interface (every role interface) lets runtimeDeps.store\nhold either backend; a DATABASE_URL \"sqlite:\" scheme selects SQLite (schema\napplied on open), anything else is Postgres. openStore() is\n[…]\nes not\neven Postgres is required for a single-node try).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage/sqlite: backend selection + quick-start on SQLite (stage 6d) …",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T14:49:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "472a9a412f38bbdb74e95dda5dd5412494d3ea77",
"body": "Completes the SQLite adapter: the allocations subdomain (disk lifecycle, mount\nleases, purge CAS, placement + capacity reservations), the provisioning writes\n(idempotent tenant/user ensure + per-agent allocation upsert + reassign), and\ntransactions. *sqlite.Store now implements every storage role in\n[…]\nime). Still additive — wiring +\nquick-start docs are 6d.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage/sqlite: AllocationStore + Tx + provisioning (stage 6c) (#27)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T14:40:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8bceaeec2ac8f5131e2631e8e03cc7455d1bb244",
"body": "Implements the sessions subdomain (SessionOps) on the SQLite backend: device\nauthorizations, access tokens (incl. the single-use agent-enroll consume),\nrefresh tokens, and the user reads. The conditional updates preserve the\nPostgres semantics exactly — Approve/Deny match only a still-pending row\n(R\n[…]\n tests cover the flow\nagainst a real temp-file database.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage/sqlite: SessionStore — device flow + tokens (stage 6b) (#26)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T14:28:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b6e8d2ae9068f419e8ca7f380213c947d8e62564",
"body": "…) (#25)\n\nFirst slice of an embedded, zero-external-dependency SQLite backend (issue #4's\n\"SQLite implementation\"), so the control plane can run for local quick-start\nwithout Postgres. Pure-Go driver (modernc.org/sqlite), hand-written database/sql\nadapter mirroring package postgres.\n\nThis slice land\n[…]\nemp-file\ndatabase (no external dependency — runs in CI).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage/sqlite: embedded backend foundation + simple stores (stage 6a…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T14:24:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fa1b6cfb614724957ce62ffc084859aeded627df",
"body": "…s (stage 5c) (#24)\n\nMove internal/db (the goose migration runner, sqlc query sources, generated\nsqlcdb, and squashed schema) under internal/storage/postgres/db, so everything\nPostgres-specific lives beneath the postgres adapter. The domain layer\n(internal/storage) and a future internal/storage/sqli\n[…]\nthe relocated goose embed applies\nthe baseline cleanly).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: relocate the Postgres backend under internal/storage/postgre…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:43:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "759fcf5f9acf7eeb88948c811d18080e76003ed1",
"body": "The 12 incremental migrations (0001-0012) accreted real cruft — most visibly\nthe email-OTP self-service login added in 0009 and dropped in 0010 when #9\nremoved self-service signup. Pre-release, with no production schema history to\npreserve, collapse them into one 0001_init.sql baseline that reflects\n[…]\ne\nrecreated; there is no released deployment to migrate.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "db: squash migrations into a single clean baseline (stage 5b) (#23)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:36:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dfdb50a8fb8a30cb90f8db6397b65d3d5e17d7f2",
"body": "With every consumer migrated onto the storage domain layer, the\nsqlc-generated db.Store alias (and db.ErrNotFound) has no users left — delete\ninternal/db/store.go. The runtimeDeps.queries field and its sqlcdb.New wiring go\nwith it; the DB-configured guards now key on deps.store. The internal/db pack\n[…]\nunner + sqlc query layer the Postgres adapter\nbuilds on.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: remove the db.Store god interface (stage 5a) (#22)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:25:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "548818ce2373a866578fed26ec22ee6d932f2b4c",
"body": "Move the operator CLI commands (user seed/suspend, server register, token\nissue) and the serverapiMountLeaseFencer off direct sqlcdb.New(pool) usage onto\nthe storage domain layer, so sqlcdb is no longer touched outside the adapter\npackage.\n\nAdds storage.AdminStore — the privileged out-of-band operat\n[…]\n the runtimeDeps.queries field and its wiring (stage 5).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate operator CLI + fencer off sqlcdb (stage 4e) (#21)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:18:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "077f758bc60de79254da348f2ee28763ba562e45",
"body": "The journal HTTP handler carried a db.Store field that nothing read — drop it\n(and the constructor param). The serverapiJournalAdapter's inline placement\nquerier moves onto the storage domain layer: its queries field is now a\ntenantPlacementQuerier, and opsAddrFor delegates to the shared\nresolveTena\n[…]\nstill yields an empty\njournal page rather than an error.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate journal off db.Store (stage 4d) (#20)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:06:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ea1768eba0ba38d16d0ee603128837327609e63e",
"body": "Move the entity provisioning handler — the control-plane→control-plane\n/v1/entities + /v1/agents/{id}/enroll-token surface — off the sqlc db.Store\ngod interface and onto the storage domain layer.\n\nAdds storage.ProvisioningStore (EnsureTenant, EnsureUserWithID,\nUpsertAgentAllocation, GetAllocationByA\n[…]\n; callers are the control-plane passing canonical UUIDs.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate /v1/entities provisioning off db.Store (stage 4c) (#19)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T08:01:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c361ba6fa3e8d0773dcc9aeaa4d6c25b9eaa5f3b",
"body": "Move the five read-path handlers — agent enroll, mount-lease, dashboard,\ncontrol tenant-usage, and purge-sweep — off the sqlc-generated db.Store god\ninterface and onto the backend-agnostic storage layer.\n\nEach handler now depends on a narrow domain interface listing exactly the\nmethods it calls (age\n[…]\nreshes the stale WithTx note in the storage package doc.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate read handlers off db.Store (stage 4b) (#18)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T07:43:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ac739bf5309b5b95664f64f2d73f640b500d910b",
"body": "First slice of the handler migration. The api-token routes and the bearer\nmiddleware no longer use db.Store.\n\n- storage.APITokenStore: domain types (APIToken, NewAPIToken, APITokenAuth) and\n the role interface; postgres adapter.\n- api_token_handlers + the requireBearer middleware (RequireBearer /\n \n[…]\nship 404,\nidempotent revoke) and the bearer-middleware suite (revoked/expired/suspended)\npass, plus the whole control-plane suite.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate API tokens off db.Store (stage 4a) (#17)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T07:19:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "08cd011dfe7d0a62ec729a7fa809fecce25b8fde",
"body": "Stage 3. allocations.Service no longer holds *sqlcdb.Queries / *pgxpool.Pool;\nit depends on storage.AllocationStore.\n\n- storage.AllocationStore / AllocationOps: domain types (Allocation, AgentEnrollment,\n ServerVM, Server, ChosenServer) and the ~22-method role interface for disks,\n leases, placeme\n[…]\nns suite (lease takeover, quota, capacity race,\nplacement, resize compensation, purge CAS) and the whole control-plane suite pass.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate the allocations subdomain to the domain layer (#16)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T07:07:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "15cc9c6cfea2c6034316bc3cbe09f2c5640be527",
"body": "… (#15)\n\nStage 2 of the data-layer redesign. The devauth service no longer holds\n*sqlcdb.Queries / *pgxpool.Pool; it depends on storage.SessionStore.\n\n- storage.SessionStore / SessionOps / SessionTx: domain types and a role\n interface for the device-flow / token subdomain, with explicit\n Begin/Com\n[…]\nily revocation, suspended user/tenant\nrejection) passes, plus the whole control-plane suite. uuid promoted to a\ndirect dependency.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: migrate the sessions subdomain (devauth) to the domain layer…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T06:46:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4f4c35e425483f6bc91e98a6d17ee12398ae2bcc",
"body": "…#14)\n\nBegin redesigning the data layer from the sqlc-shaped db.Store (84\nmethods, returns pgtype) into small domain role interfaces with no\ndriver types crossing the boundary.\n\n- internal/storage: domain types + role interfaces + ErrNotFound. The\n package doc states the conventions (intent-named m\n[…]\ned db.Store +\n override 2\" to a clean 3-method implementation.\n\nOther subdomains still use db.Store; they migrate slice by slice.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "storage: introduce backend-agnostic domain layer (foundation slice) (…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T06:25:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "179044db8c95e22ed3752ff82f64c031a8f70893",
"body": "…#13)\n\nSweep the docs against the code after the #4–#8 / email-OTP-removal work.\n\nRemoved-feature cleanup (#9 deleted self-service email-OTP; docs lagged):\n- SECURITY.md: drop the RESEND_API_KEY / ORLOP_DEV_LOG_OTP mailer bullet,\n the \"Email OTPs lock out\" hardening clause, and \"OTP\" from the\n rat\n[…]\numn is `data_addr`); also\n corrected the testing note's client_ca_file (org root, not intermediate).\n\nDocs only; no code changes.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: match current architecture; drop removed-feature descriptions (…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T06:25:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9a464453b8a03f7efa460f3c1c22c24b60b5f18a",
"body": "Post-merge quality pass over the #5-#8 / #4 changes.\n\nsimplify (efficiency): the cert-revocation deny-list pruned expired\nentries on every Add, so merging a full reconcile snapshot was O(n²).\nPrune once per push batch instead (Add is O(1) again).\n\nsecurity-review (medium): parseBoolEnv (was envBoolD\n[…]\niable.\n\nTested: go vet ./... clean; full suite green against a live Postgres\n(-p 1); the previously-flaky test now passes 100/100.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Cleanup + security follow-ups from /simplify and /security-review (#12)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T05:14:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "57a9e602669a0358ea4f7b77082fbaae2fc4cf7f",
"body": "The HTTP/business handlers held the concrete pgx-backed *sqlcdb.Queries and\nimported the pgx driver directly to interpret \"no rows\", coupling the\nconsumer layer to Postgres.\n\nIntroduce a storage seam in internal/db:\n - db.Store: the sqlc-generated query interface under a domain name, so\n handler\n[…]\n fake\ndb.Store to demonstrate the decoupling payoff.\n\nTested: go vet ./... clean; full suite green against a live Postgres (-p 1).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Hide Postgres behind a storage interface in the control plane (#4) (#11)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T04:41:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "97e8fb7dfbf67f60a8fbc302de30b152beb790a7",
"body": "Addresses the four open security issues surfaced while reviewing the\nidentity design (docs/design-identity.md §6).\n\n#6 — Single-use agent enroll tokens. A per-pod agent_enroll token is now\nspent on a successful /agent/enroll (atomic UPDATE ... consumed_at), and\nauthenticateRaw rejects an already-con\n[…]\n.\n\nTested: go vet ./... clean; full suite green with a live Postgres\n(-p 1) including new unit + integration tests for each issue.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Harden agent identity and data plane (#5, #6, #7, #8) (#10)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T04:30:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ca6c8ad3cdd6086537dae0bfbeea36e7c473ed75",
"body": "…fier (#9)\n\n* docs(identity): add identity & data-isolation design\n\nCapture the researched design basis for issue #4: separate the load-bearing\nauthorization subject (tenant/allocation/enrollment + mTLS SPIFFE) from the\nhuman account lifecycle; correct the \"passing an id is auth\" framing with the\ntw\n[…]\nroll seam,\nand re-sourcing /agent/enroll authorization from the verifier (issue #8).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "Remove self-service email-OTP login; add pluggable host-identity veri…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-27T03:10:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6894e17f86335b21e7d388d29dfeb909e02cca14",
"body": "Lead with a tight tagline, badges, and a quick-links nav row, then\nprogressively disclose detail: scannable Highlights, an early Quickstart,\nand deep prose (Why Go and Rust) folded into a <details> block. Convert\nthe doc list into an at-a-glance table and add Contributing/Security\nsections, mirroring the structure of well-organized project READMEs.\n\n\nClaude-Session: https://claude.ai/code/session_01WKCS21TsKzt66mEo2rra77\n\nCo-authored-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: reorganize README homepage for scannability (#3)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-26T14:52:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1aeff37acaf0e34aadd47900b84fb288ed89103e",
"body": "…is-wymls5\n\ndocs: explain the Go/Rust split and add one-command onboarding",
"is_bot": false,
"headline": "Merge pull request #2 from liu1700/claude/language-unification-analys…",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-26T14:40:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4cfe376fbeb13e38bc70b588d3fb618ad3865273",
"body": "Provide one-command onboarding for the two-language layout:\n\n- Makefile `setup`/`setup-go`/`setup-rust` targets verify each toolchain,\n install the Linux libfuse3 dev headers, and pre-fetch deps. The split\n targets honor the \"you usually need only one side\" guidance — apt-get\n update failures fro\n[…]\n Point CONTRIBUTING.md setup at the dev container and the make targets.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
"is_bot": false,
"headline": "build: add `make setup` targets and a dev container",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-06-26T14:37:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e9dc55778295c58fb9299512920d8a7104ab66e6",
"body": "Add docs/agent-memory.md describing what orlop's durable, isolated,\ncontent-addressed disk gives an agent-memory stack (persistence,\nfidelity-first raw storage, cheap incremental updates, overwritable\nversioned state, per-agent isolation, audit, portability) and the\nboundary where the cognitive memo\n[…]\nREADME with a new 'Why this matters for\nagent memory' section and a docs link.\n\n\nClaude-Session: https://claude.ai/code/session_01PFHaYAFUghmzjqfwt2rWQ2\n\nCo-authored-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: explain orlop as the storage substrate for agent memory (#1)",
"author_name": "Liu",
"author_login": "liu1700",
"committed_at": "2026-06-26T14:32:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "105347e1ae68ef91464852a5e6469bf6549b7684",
"body": "Add a CONTRIBUTING.md that lowers the onboarding bar for the two-language\nlayout: a per-module table showing contributors they almost always need\nonly one toolchain, exact Go/Rust build+test commands (including the\nLinux libfuse3 dependency and the macOS NFS path), and the cross-language\ncontract (w\n[…]\n (no cgo/FFI), with each\nside using the language strongest for its job.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
"is_bot": false,
"headline": "docs: add CONTRIBUTING guide and explain the Go/Rust split in README",
"author_name": "Claude",
"author_login": "claude",
"committed_at": "2026-06-26T14:32:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f1fa2c8213ea18eac31ad1f103ea2a4c24ba8ac6",
"body": "A small, standard-library-only Go SDK for the orlop-control REST API: allocate\nand manage an agent's disk, set account budgets, reassign owners, mint the\nshort-lived per-agent enroll token, and read usage. Lifted from the proven\ncontrol-plane client; this is the canonical contract a host imports to \n[…]\nkflow (build + vet + test) — the Go control/data plane and\nthis SDK previously had no CI; only the Rust client and shellcheck did.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(client): add orlop/client Go SDK + Go CI",
"author_name": "liu1700",
"author_login": "liu1700",
"committed_at": "2026-06-26T05:52:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ac3a57b20fe4217e2de0af759179f3d5a8a8cd40",
"body": "Three test initializers in the fh_tests module predated the uid/gid/atime_ns/\nrdev fields on Node and omitted them. A plain `cargo build`/`check` skips\n`#[cfg(test)]` modules so this stayed latent; CI compiling the lib tests on\nLinux surfaced E0063 (missing fields). Fill the four with their documented\nzero defaults, matching the canonical initializer.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(fs): complete Node initializers in fh_tests (uid/gid/atime_ns/rdev)",
"author_name": "liu1700",
"author_login": "liu1700",
"committed_at": "2026-06-26T05:43:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "61f874fd001f1ab12abf3d524c9057d988742f35",
"body": "Initial import. A multi-tenant file plane that gives each untrusted agent its\nown durable, auto-expanding POSIX disk over FUSE/NFS, without ever handing the\nagent a storage credential: per-agent short-lived mTLS identity (SPIFFE SAN),\ncontent-addressed chunk store with per-disk SQLite manifests, cap\n[…]\ncontrol plane that is the CA and allocator.\n\nComponents: orlop (Rust mount client), orlop-control + orlop-server (Go).\nApache-2.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "orlop: zero-trust durable POSIX disk for untrusted agents",
"author_name": "liu1700",
"author_login": "liu1700",
"committed_at": "2026-06-26T05:23:48Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 11,
"commits_last_year": 71,
"latest_release_at": "2026-07-26T06:01:48Z",
"latest_release_tag": "v0.4.5",
"releases_from_tags": false,
"days_since_last_push": 2,
"active_weeks_last_year": 4,
"days_since_latest_release": 2,
"mean_days_between_releases": 3.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 71,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/liu1700/orlop",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/liu1700/orlop",
"is_deprecated": false,
"latest_version": "v0.4.5",
"repository_url": "https://github.com/liu1700/orlop",
"versions_count": 14,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-26T05:57:44Z",
"latest_version_yanked": null,
"days_since_latest_publish": 2
}
]
},
"popularity": {
"forks": 0,
"stars": 1,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"third_party/fuser/Makefile"
],
"api_schema_files": [],
"has_devcontainer": true,
"typecheck_configs": [],
"toolchain_manifests": [
"Cargo.toml",
"bench/Cargo.toml",
"go.mod",
"third_party/fuser/Cargo.toml"
],
"largest_source_bytes": 102445,
"source_files_sampled": 291,
"oversized_source_files": 3,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 2821
},
"dependencies": {
"manifests": [
"Cargo.toml",
"bench/Cargo.toml",
"go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"crates",
"go"
],
"dependencies": [
{
"name": "anyhow",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "blake3",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "chrono",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "clap",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "4"
},
{
"name": "globset",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "libc",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.2"
},
{
"name": "lru",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.12"
},
{
"name": "parking_lot",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.12"
},
{
"name": "reqwest",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.12"
},
{
"name": "rmp-serde",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "quinn",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.11"
},
{
"name": "rustls",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.23"
},
{
"name": "rustls-pemfile",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2"
},
{
"name": "tokio",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "tokio-rustls",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.26"
},
{
"name": "serde",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "serde_json",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "serde_yaml",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.9"
},
{
"name": "rusqlite",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.31"
},
{
"name": "x509-parser",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.16"
},
{
"name": "tempfile",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "3"
},
{
"name": "serde_bytes",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.11.19"
},
{
"name": "fastcdc",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "3"
},
{
"name": "nfsserve",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.11"
},
{
"name": "async-trait",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.1"
},
{
"name": "daemonize",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.5"
},
{
"name": "os_pipe",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.2"
},
{
"name": "anyhow",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "chrono",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "clap",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "4"
},
{
"name": "rand",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.8"
},
{
"name": "serde",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "serde_json",
"manifest": "bench/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "github.com/bmatcuk/doublestar/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.10.0"
},
{
"name": "github.com/go-chi/chi/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.2.5"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/gorilla/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.3"
},
{
"name": "github.com/jackc/pgx/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.9.2"
},
{
"name": "github.com/pressly/goose/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.27.1"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.2"
},
{
"name": "github.com/quic-go/quic-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.60.0"
},
{
"name": "github.com/vmihailenco/msgpack/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.4.1"
},
{
"name": "golang.org/x/time",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "lukechampine.com/blake3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.1"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.49.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 64,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 24,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "liu1700",
"commits": 69,
"avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4"
},
{
"type": "User",
"login": "claude",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.972
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"go.yml",
"orlop-cli.yml",
"posix.yml",
"release.yml",
"shellcheck.yml",
"upgrade.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock",
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/29 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "25 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
"ran_at": "2026-07-28T08:19:06Z",
"aggregate_score": 3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-26T06:03:44Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-26T05:57:45Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/liu1700/orlop",
"host": "github.com",
"name": "orlop",
"owner": "liu1700"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"security": 30,
"vitality": 70,
"community": 33,
"governance": 59,
"engineering": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 70,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 56,
"inputs": {
"commits_last_year": 71,
"human_commit_share": 1,
"days_since_last_push": 2,
"active_weeks_last_year": 4
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "4/52 weeks with commits",
"points": 2.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 4
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "71 commits in the last year",
"points": 16.7,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 71
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 11,
"latest_release_tag": "v0.4.5",
"releases_from_tags": false,
"days_since_latest_release": 2,
"mean_days_between_releases": 3.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "11 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 11
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 33,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 1,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "1 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 1
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 59,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 12,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.972
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 97% of commits",
"points": 0.6,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 97
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"merged_prs": 64,
"open_issues": 0,
"closed_issues": 24,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 1
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "64/65 decided PRs merged",
"points": 37.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 64,
"decided": 65
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 59,
"inputs": {
"followers": 50,
"owner_type": "User",
"is_verified": null,
"owner_login": "liu1700",
"public_repos": 52,
"account_age_days": 4624
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "50 followers of liu1700",
"points": 12.3,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 50,
"login": "liu1700"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "52 public repos, account ~12 yr old",
"points": 24.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 52
}
},
{
"code": "account_age_years",
"params": {
"years": 12
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/liu1700/orlop"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 2
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 2 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 2
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "14 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 14
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 71,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 30,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 30,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "25 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 75,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 2821
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "71 of 71 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 71,
"sampled": 71
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Cargo.lock",
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"third_party/fuser/Makefile"
],
"has_devcontainer": true,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.915,
"toolchain_manifests": [
"Cargo.toml",
"bench/Cargo.toml",
"go.mod",
"third_party/fuser/Cargo.toml"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, third_party/fuser/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, third_party/fuser/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "devcontainer, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "devcontainer, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "65 of the last 71 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 65,
"sampled": 71
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 102445,
"source_files_sampled": 291,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/291 source files over 60KB",
"points": 54.4,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 291,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch crates package 'orlop' from its registry",
"Could not fetch crates package 'orlop-bench' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-28T08:19:22.659347Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/liu1700/orlop.svg",
"full_name": "liu1700/orlop",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}