Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 20179,
"has_wiki": true,
"homepage": "https://meteora-pro.github.io/devboy-tools/",
"languages": {
"Rust": 6328763,
"Shell": 23652,
"Python": 206422,
"Dockerfile": 1042,
"JavaScript": 2655
},
"pushed_at": "2026-07-25T12:02:50Z",
"created_at": "2026-01-26T02:26:36Z",
"owner_type": "Organization",
"updated_at": "2026-07-25T12:02:53Z",
"description": "Configurable tool bundle for AI coding agents — use via MCP server, CLI, or agent skills. npm wrapper for the Rust binary.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Rust",
"significant_languages": [
"Rust"
]
},
"owner": {
"blog": "https://meteora.pro",
"name": "Meteora Pro",
"type": "Organization",
"login": "meteora-pro",
"company": null,
"location": null,
"followers": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/72404657?v=4",
"created_at": "2020-10-05T16:16:24Z",
"is_verified": null,
"public_repos": 9,
"account_age_days": 2118
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.32.0",
"kind": "minor",
"published_at": "2026-07-25T12:01:23Z"
},
{
"tag": "v0.31.1",
"kind": "patch",
"published_at": "2026-07-01T06:46:06Z"
},
{
"tag": "v0.31.0",
"kind": "minor",
"published_at": "2026-06-09T16:31:36Z"
},
{
"tag": "v0.30.1",
"kind": "patch",
"published_at": "2026-05-27T18:49:30Z"
},
{
"tag": "v0.29.2",
"kind": "patch",
"published_at": "2026-05-26T18:55:00Z"
},
{
"tag": "v0.29.0",
"kind": "minor",
"published_at": "2026-05-19T08:00:39Z"
},
{
"tag": "v0.28.1",
"kind": "patch",
"published_at": "2026-05-17T19:39:06Z"
},
{
"tag": "v0.28.0",
"kind": "minor",
"published_at": "2026-05-10T20:49:18Z"
},
{
"tag": "v0.27.0",
"kind": "minor",
"published_at": "2026-05-09T21:42:01Z"
},
{
"tag": "v0.26.0",
"kind": "minor",
"published_at": "2026-05-04T16:14:32Z"
},
{
"tag": "v0.25.0",
"kind": "minor",
"published_at": "2026-05-02T20:43:42Z"
},
{
"tag": "v0.24.0",
"kind": "minor",
"published_at": "2026-05-02T09:51:23Z"
},
{
"tag": "v0.23.0",
"kind": "minor",
"published_at": "2026-05-01T19:36:43Z"
},
{
"tag": "v0.22.0",
"kind": "minor",
"published_at": "2026-04-29T22:41:23Z"
},
{
"tag": "v0.21.2",
"kind": "patch",
"published_at": "2026-04-25T15:54:28Z"
},
{
"tag": "v0.21.1",
"kind": "patch",
"published_at": "2026-04-25T13:16:14Z"
},
{
"tag": "v0.21.0",
"kind": "minor",
"published_at": "2026-04-25T12:59:30Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2026-04-24T22:29:01Z"
},
{
"tag": "v0.19.0",
"kind": "minor",
"published_at": "2026-04-24T14:58:14Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2026-04-23T21:33:54Z"
},
{
"tag": "v0.17.1",
"kind": "patch",
"published_at": "2026-04-16T06:19:23Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2026-04-15T11:38:18Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-04-14T19:34:38Z"
},
{
"tag": "v0.15.1",
"kind": "patch",
"published_at": "2026-04-07T09:28:00Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-04-07T09:14:33Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-04-03T10:07:33Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-03-29T21:37:04Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-03-28T13:48:21Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-03-28T09:25:57Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-03-23T15:45:02Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-03-23T12:49:57Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-03-23T06:56:12Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-03-17T13:59:40Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-03-17T10:41:38Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-03-17T08:44:09Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-03-16T09:30:54Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-03-12T10:01:26Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-03-03T10:09:16Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-02-19T18:20:14Z"
}
],
"recent_commits": [
{
"oid": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
"body": "ci(release): crates.io = libraries only + metadata-derived publish + dry-run gate",
"is_bot": false,
"headline": "Merge pull request #312 from meteora-pro/feat/crates-io-lib-only-publish",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T12:02:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b291203525e99847019f4e563e694cd0e7179f17",
"body": "Option A for the chronically-broken crates.io release (#308):\n\n- Mark devboy-cli (app binary) + devboy-mcp publish=false — they hard-depend on\n the internal secrets plugins (publish=false), so they can never publish to\n crates.io. Distributed via npm + release binaries instead.\n- Replace the hardc\n[…]\ns on every PR, before the release tag.\n\nValidated: dry-run packages exactly the 17 clean libs, skips cli/mcp/plugins.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(release): crates.io = libraries only, metadata-derived + dry-run gate",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T11:52:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f8a9ec73a0f066df21668863da20eecb3401eeb2",
"body": "…able\n\nci(release): skip publish=false crates in crates.io publish",
"is_bot": false,
"headline": "Merge pull request #311 from meteora-pro/fix/crates-io-skip-unpublish…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T10:18:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63acd9ec551739bcc1e6cc5e00f0530207f7f73d",
"body": "The secrets epic (#247) added publish=false crates (devboy-secrets-agent,\nsecrets-ui, all secrets plugins), but release-crates-io.yml's publish loop\nstill lists them and publish_if_new only tolerated \"already exists\" — so\n`cargo publish` on an unpublishable crate aborted the whole release\n(v0.32.0 p\n[…]\nied on\ndevboy-secrets-agent). Guard publish_if_new to skip crates whose\ncargo-metadata `publish` is [] (publish=false).\n\nRefs #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(release): skip publish=false crates in crates.io publish",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T10:08:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "62326cadfa29b81f123b3b71a2c2f4d81fe1c3fd",
"body": "docs: clarify wayland-scanner transitive + fold dep note into 0.32.0 (#309 review)",
"is_bot": false,
"headline": "Merge pull request #310 from meteora-pro/fix/dep-note-accuracy",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T07:19:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24f36d82ec59497fe0093e882a4bf5c9ab44cfed",
"body": "Addresses Copilot review on #309: wayland-scanner is not a direct dependency —\nit resolves transitively (via eframe) to >= 0.31.11; only ratatui and keepass\nare direct bumps. Also moves the dep-upgrade entry from [Unreleased] into the\nunpublished [0.32.0] release (where it actually ships).\n\nDocs-only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: clarify wayland-scanner is transitive; fold dep note into 0.32.0",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T07:09:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3da2453af52e6e16d2fc3de14f5009622c2e747f",
"body": "fix(deps): drop all RustSec ignores via ratatui/keepass/wayland-scanner upgrades",
"is_bot": false,
"headline": "Merge pull request #309 from meteora-pro/fix/rustsec-drop-ignores",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T05:45:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "498db1a03d978df7745c6839cd43f17b372d55e5",
"body": "- ratatui 0.29 → 0.30 (removes unmaintained `paste`, RUSTSEC-2024-0436)\n- keepass 0.12 → 0.13 + wayland-scanner → 0.31.11 (both pull quick-xml >= 0.41,\n fixing RUSTSEC-2026-0194 / -0195 DoS)\n- deny.toml [advisories].ignore is now empty\n\nFresh dependency resolve confirmed: no `paste`, quick-xml 0.41.0 only.\nNo first-party API/behavior changes; build/clippy/tests/fmt/cargo-deny green.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(deps): drop all RustSec ignores via dependency upgrades",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T05:32:40Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "39171aa96f0e9307c5840add902079bdbd2328b5",
"body": "feat: OAuth 2.1 auth for proxy MCP upstreams (device flow + auto-refresh)",
"is_bot": false,
"headline": "Merge pull request #307 from meteora-pro/feat/oauth2-proxy",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T05:12:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04527ee884c0def1b68cc270e9c586e011e3155e",
"body": "The tools reference embeds the version banner; sync it after the 0.32.0 bump\n(Docs --check gate).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(docs): regenerate tools reference for v0.32.0",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T04:56:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f782dea01a99747ccc57a5dfb16d0b29493b4c79",
"body": "Bump workspace + plugin manifests 0.31.1 → 0.32.0; cut CHANGELOG [0.32.0].\nPublish (crates.io + npm) is gated on pushing the v0.32.0 tag — not done here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): v0.32.0 — OAuth 2.1 proxy auth",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T04:52:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a5f89a8da9717d4cf8aacdf17a8f90ecffbdbe78",
"body": "…llback, full initialize probe\n\n- well_known_url: bracket IPv6 authority (host_str() yields unbracketed ::1,\n building a malformed URL; require_web_url permits http loopback IPv6). +test.\n- OAuthAuth::new: drop the reqwest::Client::new() fallback that re-enabled the\n default redirect policy on the\n[…]\n436 note (paste is pulled by ratatui, not\n egui/eframe; compile-time proc-macro only).\n\nAddresses Copilot review threads on #307.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): address review feedback — IPv6 well-known, no-redirect fa…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-25T04:52:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8e116eea390656a59844c5bab2d60edd2a616931",
"body": "… (#306)\n\nThe MCP authorization spec requires the client to pass `resource=<mcp-url>`\non the authorization, token, and refresh requests so the AS binds the\nissued token's audience to the target MCP server. Thread the resource\nindicator through request_device_authorization, poll_device_token_once,\nan\n[…]\ns no introspection endpoint — so end-to-end tool calls are\nblocked on server-side token validation, tracked separately.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): send RFC 8707 resource indicator on device/token/refresh…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T15:46:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2bb0f1a47f9b6b45ef0a5b0d57cff6a5100d1d09",
"body": "…(#306)\n\nThree integration bugs found by end-to-end testing `devboy login` against\nthe real app.devboy.pro authorization server (unit/integration tests and\nstatic review missed all three — they only surface against a live server):\n\n- Config source mismatch: cmd_login loaded via Config::load() (the g\n[…]\nrough discovery → registration → device\nauthorization → poll (clean `expired_token` termination) against\napp.devboy.pro.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): make `devboy login` work against a live RFC-compliant AS …",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T14:43:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a1780b322058969185baf8c01fcf7c2c59445b7a",
"body": "…ate (#306)\n\nRemaining review findings:\n\n- cmd_login's device-poll loop had no client-side deadline (`expires_in`\n was parsed but unused); a misbehaving AS answering `authorization_pending`\n forever hung the CLI. Bound it by the device code's lifetime.\n- request_sse pushed the pending (id, tx) reg\n[…]\nd token_endpoint — so a config\n missing it showed green while the proxy was silently skipped. Doctor\n now checks both.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): bound device poll, plug SSE pending leak, align doctor st…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T10:45:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "daac829a18b53eb60b5d8c81382349c1978b623e",
"body": "The single-flight gate was in-process only, but a multi-agent setup runs\nseveral `devboy` processes (one proxy per agent) against the same\nkeychain key. When the access token expired, each independently spent\nthe same rotating refresh token; the AS rotates once, so every loser got\n`invalid_grant` an\n[…]\nopts the winner's pair rather than surfacing a re-login.\n\nAdds a test simulating another process having already rotated.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): store-reconcile refresh to survive rotation races (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T10:45:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cb5590d0e7e545c4938aa3fecf20db32cee3e0f8",
"body": "…306)\n\nTwo token-response hardening fixes from the independent review:\n\n- Panic-DoS: `now + Duration::seconds(expires_in)` panicked on an\n attacker-controlled `expires_in` (e.g. i64::MAX — a valid JSON\n integer). In OAuthAuth::refresh that aborts the running MCP proxy on a\n live tool call. Clamp \n[…]\ncess, refresh success); metadata parses keep\n their detail.\n\nAdds a from_response test for the out-of-range expires_in.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): clamp expires_in + stop echoing token bodies in errors (#…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T10:45:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "41b83a006ad4dd41391cc4a9279636005b0669a1",
"body": "…ints (#306)\n\nIndependent review (Kimi K3 + a second reviewer) found the discovery\ntrust boundary was porous. Harden it:\n\n- require_web_url now parses with `url::Url` instead of string prefixes.\n It rejects credentials in the authority (`http://localhost@evil/`),\n non-http(s) schemes, and — for ht\n[…]\nurned `issuer` matches (§3.3).\n\nAdds tests for the bypasses, IP-range rejection, and path-aware\nwell-known construction.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): close SSRF holes in discovery + validate advertised endpo…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T10:36:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c9234a6813f046a856f2ca7480ee5edcda39bef2",
"body": "…h (#306)\n\nCopilot review: the request_http oauth2 behavior (pre-flight token, then\nrefresh-and-retry-once on 401) had no test at the proxy request layer —\nonly the OAuthAuth contract was covered. Add a focused test that mocks a\npersistent 401 on tools/call and asserts exactly one refresh\n(single-flight) + one retry, ending in the actionable re-login error.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(proxy): cover oauth2 refresh-and-retry on 401 in the request pat…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T09:56:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "384faff414f3d28b7e3b14d737bdfbd44a481005",
"body": "…d (#306)\n\nCopilot review: `devboy doctor` marked an oauth2 proxy \"logged_in\" on the\nmere presence of a stored secret, but the proxy path needs it to\ndeserialize as OAuthTokens. A corrupt/partial blob now reads as\nnot-logged-in (with the actionable `devboy login` fix) instead of a\nfalse-positive session.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(doctor): report oauth2 logged_in only when the token blob is vali…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T09:56:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c3fd6d62036067d88fd9fe34c8c724dc2d293c4d",
"body": "Address Copilot review findings on the login/discovery path:\n\n- SSRF guard: validate every outbound discovery URL (resource_metadata\n from the WWW-Authenticate challenge, and the AS issuer) via\n require_web_url — https required, http only for loopback. A crafted\n upstream challenge can no longer \n[…]\ntted entirely).\n\nAdds require_web_url unit tests (https/loopback ok; remote-http, file,\nftp, gopher, hostless rejected).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): harden discovery + honor advertised scopes (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T09:56:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2b6ee42560e8ea846727d9b0462129e49c074c09",
"body": "CI's stable clippy rolled to 1.97, whose stricter lints flag pre-existing\ncode (unrelated to this PR, but it blocks the shared Clippy gate under\nRUSTFLAGS=-Dwarnings):\n\n- question_mark: collapse `match opt { Some/None=>return }` and an\n `else if let … else { return None }` chain into `?`\n (devboy-\n[…]\nll behavior-preserving. Full-workspace `clippy --all-targets\n--all-features` under -Dwarnings is clean on stable 1.97.1.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clippy): resolve rust-1.97 lints across workspace (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T06:36:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b9ea1285811731450d242d5a12fe5eff83e740f0",
"body": "cargo-deny went red on freshly-published RUSTSEC-2026-0194/0195\n(quick-xml DoS via malicious XML, patched >= 0.41.0) — a pre-existing\necosystem issue, not introduced by this PR. quick-xml enters only via\nkeepass (parses the user's own local .kdbx password DB) and\nwayland-scanner (build-time proc-mac\n[…]\needs upstream releases.\nIgnore with a documented reachability analysis, matching the existing\nRUSTSEC-2024-0436 pattern.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): ignore unreachable quick-xml XML-DoS advisories (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T06:22:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "da7c2d2e4ba082be6deed866e1770ebd176caa62",
"body": "…(#306)\n\nBring PR #307's red hygiene jobs to green with the honest ADR-019 fix\nrather than gaming the gates:\n\n- Secrets discipline: TokenResponse/OAuthTokens token fields are now\n secrecy::SecretString (was String). OAuthTokens round-trips through a\n scoped secret_serde helper, so the only plainte\n[…]\n path.\n\n309 devboy-core + 266 devboy-mcp tests pass; fmt/clippy/rustdoc/\npublic-api/secrets-discipline verified locally.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): carry proxy tokens as SecretString + green hygiene gates …",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T06:22:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9f87ea5d036bff42d1812d5e9dafdd27a25503cf",
"body": "Review issue #2: adds a test for the exact sequence request_http/request_sse\nrun on a 401 — access_token() (pre-flight, valid token unchanged) -> refresh\n(sent) (single-flight) -> access_token() yields the rotated token. Full\ntransport-level e2e (with initialize/session/id echoing) is deferred as it\nadds flakiness for little extra coverage over this contract test.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(oauth): cover on-401 refresh-retry contract (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T05:51:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f16aa4949c40460622ef3a8c1de3718882d3de38",
"body": "…e (#306)\n\nReview issues #3/#4/#5:\n- cmd_login rejects non-oauth2 proxies with a clear message instead of\n attempting a device flow against a bearer/api_key upstream.\n- request_http/request_sse map a post-refresh 401 to an actionable error\n (\"run: devboy login <name>\") instead of a raw HTTP 401; r\n[…]\nt.\n- OAuthAuth::refresh documents the persist-before-swap failure semantics\n (dead-refresh -> re-login, no corruption).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(oauth): login guard + actionable 401 errors + persist-failure not…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T05:49:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c7892bd06ca0f720d25f72e70c2b4275d349f4f0",
"body": "Review issue #1: oauth2 was only injected into request_http (streamable-\nhttp). SSE proxies with auth_type=\"oauth2\" ran unauthenticated. Now the SSE\nGET stream is seeded with the access token at connect, and request_sse POSTs\ncarry a per-request Bearer with the same on-401 single-flight refresh-retry\nas request_http. Documented follow-up: stream reconnect-on-refresh (the GET\nstream header is fixed at connect).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(proxy): wire OAuth into SSE transport too (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-23T05:47:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "096181995c54692c9aa5f1cbbfa4683fff24700f",
"body": "proxy.md gains an \"OAuth 2.1 authentication (device flow)\" section (config +\n`devboy login` + doctor state); auth_type field row lists oauth2. Regenerated\ncli.md reference to include the new `login` command.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(oauth): document auth_type=oauth2 + devboy login (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T21:03:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cb81a3892d74dc3bbc0d0cb862b34e1d1708b37d",
"body": "doctor now accepts auth_type=\"oauth2\" (was flagged Invalid) and reports per\nproxy: Pass \"logged in; tokens auto-refresh\" when the proxy.<name>.oauth\nsecret + client_id exist, else Error \"not logged in\" with the exact fix\ncommand `devboy login <name>`. This is the stdio-side awareness signal for a\nhu\n[…]\nio-only, so http WWW-Authenticate passthrough is N/A — noted as a\nfollow-up if a remote http server mode is ever added.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(doctor): report OAuth login state for oauth2 proxies (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:59:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "860db46be2dbdf0ff8ba91daafa678b3a1d98d4e",
"body": "…nt (#306)\n\nProxyOAuthConfig gains token_endpoint, cached by devboy login after discovery\nso the proxy refreshes headlessly without re-discovery. build_oauth_auth loads\nthe stored OAuthTokens (proxy.<name>.oauth) + client_id/token_endpoint and\nconstructs the OAuthAuth holder; build_proxy_manager wir\n[…]\n, skipping — with a clear \"run: devboy login <name>\"\n— any proxy not yet logged in. bearer/api_key/none still pass None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(proxy): activate oauth2 at runtime — ProxyManager + token_endpoi…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:54:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0d1706d94e387ed78a633558a074c52c72d45f84",
"body": "McpProxyClient gains an optional OAuthAuth holder. For auth_type=\"oauth2\"\nthe Bearer is injected per request from the holder (pre-flight refresh),\nnot baked at connect; request_http sends in a retry loop that on a 401 runs\na single-flight refresh and retries once with the rotated token. bearer/\napi_\n[…]\nxyManager activation follows). Test asserts persistence\nvia store.exists (no expose_secret — ADR-023 guard stays green).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(proxy): per-request OAuth Bearer + on-401 refresh-retry (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:50:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6218d1d71be03eed73ddaf1e65acabeb8b10ed96",
"body": "…(#306)\n\nPer-upstream token holder for auth_type=\"oauth2\". access_token() refreshes\npre-flight within a 60s expiry skew; refresh(seen) is single-flight (gate +\naccess-token double-check so concurrent 401s trigger exactly one refresh)\nand persists the rotated pair to the credential store BEFORE the i\n[…]\ns a spent refresh_token. 2 tokio\ntests (rotation+persist, double-check short-circuit). Wired into the request\npath next.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(proxy): OAuthAuth holder — single-flight refresh, rotation-safe …",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:37:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0f43e960b802c6b02ace1322123fc8a267c5e433",
"body": "New top-level command orchestrating the RFC 8628 device flow against a proxy\nupstream: discover AS (WWW-Authenticate probe or configured authorization_\nserver) -> register client if needed (persisted to config) -> device\nauthorization -> print user_code + verification_uri_complete -> poll the\ntoken \n[…]\n and auto-refreshes these. Compiles clean; built on the tested oauth\nprimitives (discovery/registration/device/refresh).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(cli): devboy login <server> — OAuth 2.1 device flow (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:32:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e0f409cb4f42634e44d65fe8bdd45f0805fcf683",
"body": "Persisted token set for one proxy upstream (JSON into the credential store\nunder proxy.<name>.oauth). OAuthTokens::from_response computes expires_at\nfrom expires_in relative to now, with a prev_refresh fallback; is_near_expiry\ndrives pre-flight refresh. 5 unit tests (expiry compute, refresh fallback,\nmissing-refresh error, near-expiry threshold, JSON roundtrip).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): OAuthTokens model — access/refresh/expires_at (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:26:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "920619cfd498e9547bece03d2c387ab9dd4e4dcf",
"body": "refresh() exchanges a refresh_token for a fresh token set via the RFC 6749\n§6 grant. Documents the AS rotation contract: the server returns a NEW\nrefresh_token and deactivates the old, so callers must persist-first and\nsingle-flight (enforced later in the proxy layer). invalid_grant surfaces\nas OAut\n[…]\nOauth so the caller can trigger re-login.\nAdds httpmock dev-dep; 2 integration tests (rotation success + invalid_grant).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): refresh_token grant — RFC 6749 §6, rotation-aware (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:25:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "22b3cc7796cd22d6a4ab0b36b2fc64c302fc130c",
"body": "request_device_authorization posts the RFC 8628 §3.1 form (client_id +\noptional scope) and parses the §3.2 response (device_code, user_code,\nverification_uri[_complete], expires_in, interval defaulting to 5).\npoll_device_token_once polls the token endpoint with the device_code grant\nand maps outcome\n[…]\nResponse, other error codes -> OAuthError::Oauth.\nparse_oauth_error extracts the RFC 6749 §5.2 error code. 5 unit tests.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): device authorization grant + token poll — RFC 8628 (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:20:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7974b05e1acea3915040e4f7223f970c33cb52ee",
"body": "register_client posts a public device-flow client registration (grant_types\ndevice_code + refresh_token, token_endpoint_auth_method=\"none\") to the AS\nregistration_endpoint and returns the issued client_id. Callers persist it\ninto ProxyOAuthConfig.client_id so re-login reuses the same client.\nGRANT_DEVICE_CODE / GRANT_REFRESH_TOKEN constants shared with later grants.\n2 unit tests (request shape + response parse).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): dynamic client registration — RFC 7591 (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:16:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6f07ada25ab46899f96e2d8fb40d911590f876bf",
"body": "…(#306)\n\nNew devboy-core::oauth module (client half of the MCP auth spec, standard\nRFCs only). This commit: discovery.\n- parse_www_authenticate: extract resource_metadata URL (RFC 9728), quoted\n or bare, ignoring other challenge params.\n- discover: WWW-Authenticate -> protected-resource metadata ->\n[…]\n9 unit tests (parsing + metadata deserialization).\n\nRegistration (RFC 7591), device grant (RFC 8628) and refresh follow.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(oauth): OAuth 2.1 discovery — WWW-Authenticate -> RFC 9728/8414 …",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T20:01:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "73d21b6882d2a7a2fa8952f273fb9f2439e99e04",
"body": "Additive config surface for OAuth 2.1 proxy auth. ProxyMcpServerConfig\ngains an optional `oauth` block (ProxyOAuthConfig: client_id / scopes /\nauthorization_server, all optional). A minimal config sets only\nauth_type = \"oauth2\" and lets discovery (RFC 9728/8414) + dynamic\nregistration (RFC 7591) fil\n[…]\ndevboy login`.\n\nBackward compatible: bearer / api_key / none unchanged. All 16 struct\nliterals updated with oauth: None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(config): add auth_type=\"oauth2\" + ProxyOAuthConfig (#306)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-07-22T19:57:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd7176471447d1ab7d5d82afb6d508a89a662558",
"body": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
"is_bot": false,
"headline": "Merge pull request #303 from meteora-pro/fix/crates-io-publish-secrets",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-07-01T07:50:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5730a6bf3c6a68d7d34ceddb5f4842ad6b2ee4b",
"body": "The crates.io release failed at `Publish devboy-mcp` with \"no matching\npackage named devboy-secret-kdbx found\": devboy-mcp depends on\ndevboy-secret-kdbx, but none of the 8 secrets crates were in the publish\norder, so they were never uploaded before the crates that need them\n(devboy-mcp via kdbx, dev\n[…]\neds secrets-agent).\nUses the same publish_if_new idempotency, so it survives partial-retry of\nthe already-published 0.31.1 crates.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
"author_name": "Maxim Dymov",
"author_login": null,
"committed_at": "2026-06-30T18:26:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c4ee9bedf5a81e3018d7df585cdef46773a487f1",
"body": "chore(release): bump workspace to 0.31.1",
"is_bot": false,
"headline": "Merge pull request #302 from meteora-pro/chore/release-0.31.1",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-06-30T15:58:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eee3eca94d2f5b4fff23e8ac66ab6a5623c1ee84",
"body": "Per docs/guide/contributing/release.md Step 1:\n- [workspace.package].version 0.31.0 -> 0.31.1\n- all [workspace.dependencies] devboy-* version pins -> 0.31.1\n- sync plugin manifests (claude/codex plugin.json + marketplace.json)\n via scripts/release/sync-plugin-version.sh\n- regenerate docs/guide/refe\n[…]\nersion, skills, readme sync,\ntools/cli reference). Tag v0.31.1 after this merges to fan out the\nnpm + crates.io release workflows.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.31.1",
"author_name": "Maxim Dymov",
"author_login": null,
"committed_at": "2026-06-30T15:55:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0324e0c52176a38babe0f6093da20a019075185f",
"body": "…down-blocks\n\nfix(clickup): render comment markdown via comment blocks (#300)",
"is_bot": false,
"headline": "Merge pull request #301 from meteora-pro/fix/300-clickup-comment-mark…",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-06-30T15:49:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "159fbe85c824114bb93b35d3018a4eea98bc49ee",
"body": "The public-api drift job ran on a floating `dtolnay/rust-toolchain@nightly`.\ncargo-public-api prints fully-qualified type paths, so a toolchain change\n(std::io::Error becoming a re-export of core::io::Error) shifted every\nbaseline that mentions io::Error, failing CI on unrelated crates.\n\nPin the job\n[…]\nthe std::io::error -> core::io::error path rename; no\nreal public API changed. Bump the pin deliberately + regenerate when needed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(public-api): pin nightly toolchain, regenerate baselines (#300)",
"author_name": "Maxim Dymov",
"author_login": null,
"committed_at": "2026-06-30T15:36:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "75155e6d7b56a1bcb05dc72ac822cc774105f157",
"body": "… (#300)\n\nBuilds on the existing comment_format.rs converter (markdown -> ClickUp\n`comment` rich-text runs) rather than duplicating it. Adds:\n\n- italic (`*x*` / `_x_`) and `[text](url)` links as inline run attributes\n- GFM tables -> aligned monospace `code-block` (comments have no table\n mark); col\n[…]\nting bold rendering\n\nThe inline parser is char-based, so all additions are UTF-8 safe.\nVerified against the real ClickUp API + UI.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(clickup): extend comment markdown — italic, links, tables, tasks…",
"author_name": "Maxim Dymov",
"author_login": null,
"committed_at": "2026-06-30T12:41:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "32724cf4e0355e40141d2123fc82daef60422d1b",
"body": "…y-status\n\nfeat(clickup): surface display status + category in get_issue (DEV-1578)",
"is_bot": false,
"headline": "Merge pull request #298 from meteora-pro/feat/DEV-1578-clickup-displa…",
"author_name": "ai-dev-2-meteora-pro",
"author_login": "ai-dev-2-meteora-pro",
"committed_at": "2026-06-09T14:55:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc325febc2bd414bdd418f11741c5d5c3f6213f4",
"body": "…ion (DEV-1578b)\n\nAddresses PR #298 merge-readiness review (test-coverage gaps). Adds\ntest_resolve_custom_field_display_degrades_gracefully asserting every\nnon-resolving branch yields display=None with the raw value preserved\n(never a wrong label / panic):\n- drop_down order index out of u32 range (t\n[…]\no matching option\n- drop_down option id with no match\n- type_config present but options empty\n- labels ids with no matching option\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(clickup): cover graceful-degradation branches in display resolut…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T10:41:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "13f99c22449ba71d0b858914321341bc9a15de3a",
"body": "Follow-on to the workspace 0.31.0 bump — regenerate the version-derived\nartifacts the CI drift checks enforce:\n- plugins/{claude,codex}/.../plugin.json + .claude-plugin/marketplace.json\n (via scripts/release/sync-plugin-version.sh)\n- docs/guide/reference/tools.md header (\"DevBoy Tools v0.31.0 …\")\n (via `devboy tools docs`)\n\nFixes the red \"Plugin manifests drift check\" and \"Docs\" CI jobs. Only the\nversion string changed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): sync plugin manifests + tools reference to 0.31.0",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T10:34:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6a6dff8aeaab2ea973594a897bbb54c04e859a7e",
"body": "DEV-1578 / DEV-1578b add public API (Issue.status/status_category,\nCustomFieldValue.display, ClickUp type_config resolution types) — a\nsemver-minor change. Bump [workspace.package].version and all internal\ndevboy-* dependency pins 0.30.1 → 0.31.0 so a crates.io publish resolves\nthe registry version consistently. (Publish itself stays gated: DEV-1579.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.31.0",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T10:29:59Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1ca6a4ca34b523acf9c31aab8a800161cb2de18b",
"body": "Address PR #298 review (Copilot): resolve the drop_down order index with\n`u32::try_from(..).ok()?` instead of `as u32`, so an out-of-range value\nfails cleanly to `display = None` (raw value preserved) rather than\ntruncating to a wrong option label.\n\nAdd an httpmock end-to-end test (test_get_issues_r\n[…]\nved label in the\nserialized agent-facing JSON. Validates the serde wiring against the real\npayload, not just the in-memory mapper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): guard dropdown index + e2e wire-shape test (DEV-1578b)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T10:29:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "588bb03a3dc4d5f77b8bdc0a4cc0548fc551a149",
"body": "Reflow only — `cargo fmt --all` (stable, matching the Format CI job)\ntouched nothing outside the new DEV-1578b code in client.rs. Fixes the\nred Format check on PR #298.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "style(clickup): rustfmt the DEV-1578b resolver + tests (DEV-1578b)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T09:01:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "df828a87fcda5aa675984d7e5ddcf2f8ddfb0fd4",
"body": "…ditions (DEV-1578)\n\nDEV-1578 added Issue.status / Issue.status_category, DEV-1578b added\nCustomFieldValue.display and the ClickUp drop_down/labels resolution types\n(ClickUpFieldTypeConfig / ClickUpFieldOptionInline, re-exported via\n`pub use types::*`). Regenerate the cargo-public-api baselines (pin\n[…]\ns:: + crate root)\n- devboy-clickup: 2 new public types + ClickUpCustomField.type_config\n\nAll 12 other first-wave crates: no drift.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(public-api): regenerate baselines for Issue/CustomFieldValue ad…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T08:21:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8fa4f408c0bb15d4ffb28e741c12805cdf30c6fb",
"body": "…abels (DEV-1578b)\n\n`map_task` surfaced custom fields with ClickUp's opaque raw value — a\ndrop_down came back as its order index (`0`), a labels multi-select as an\narray of option ids — so an agent reading the field saw `0`, not `dev`.\nClickUp already embeds `type_config.options` (id/orderindex/name\n[…]\n display None\n\nPart of epic DEV-1577; surfaces the Shipped Version / Dev Env Host dropdowns\nas readable values instead of indices.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): resolve drop_down/labels custom-field values to human l…",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-09T08:12:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e8402287e803e43c71452754bb0ce5f29068cb9a",
"body": "ClickUp's rich workflow statuses (e.g. \"in progress\", \"review\", \"ready\nto release\", \"complete\") drive the team's \"what's deployed where\" board,\nbut get_issue/get_issues only exposed the binary `state` (open/closed),\ncollapsing the promotion stage. This is the read-path foundation for\nADR-114 (deploy\n[…]\n test_map_task; add test_map_task_surfaces_display_status\n (clickup) + test_encode_issues_standard_includes_display_status (toon)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(clickup): surface display status + category in get_issue (DEV-1578)",
"author_name": "Andrey Maznyak",
"author_login": "andreymaznyak",
"committed_at": "2026-06-06T06:42:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bf0a19468466aeaef511b0f21bc9be1dbf3d3a2a",
"body": "fix(clickup): render comments via structured comment[] rich-text (#294)",
"is_bot": false,
"headline": "Merge pull request #295 from meteora-pro/fix/clickup-comment-rich-text",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:45:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3c64573d489bfd1f30dd4ea886b267cebb16b8b",
"body": "…line (#294)\n\nCI resolves bitflags 2.12.1 (the repo doesn't commit Cargo.lock, so CI\nalways builds against latest deps). bitflags 2.12 adds an `all_named()`\nmethod to the macro-generated flags API, so `Capabilities::all_named()`\nnow appears in devboy-storage's public surface and the public-api drift\n[…]\nurely the two\n`all_named()` lines, no other changes. Unblocks unrelated PRs (this one\nonly touches the ClickUp comment converter).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(storage): add bitflags-generated all_named() to public-api base…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:29:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5fbf92a964180d3c97bf6143c82d627350830825",
"body": "Making `comment_format` public (for the markdown→comment[] converter) and\nadding `CreateCommentRequest::comment` extends the crate's public surface.\nRegenerate the cargo-public-api baseline so the drift check passes. The\ndiff is purely additive: the new `comment_format` module types\n(CommentBlock, CommentAttributes, CodeBlockAttr, ListAttr),\nmarkdown_to_comment_blocks, and the new request field — no removals.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(clickup): regenerate public-api baseline for comment_format (#294)",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:17:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9691ecb80980d0e1b2a0d9b151819fc2a480ed64",
"body": "…#294)\n\nAddress PR review: the trailing-newline trim only popped a single plain\n`\"\\n\"` block, so a body ending in multiple newlines (e.g. \"a\\n\\n\") left a\ndangling blank-line separator. Loop until no trailing plain newline\nremains, while preserving block-attribute separators (code-block / list)\nwhich are structurally significant. Add regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): trim all trailing plain newlines in comment converter (…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:17:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "52bb490b30355b69addd19469be34d3987b77a10",
"body": "…er (#294)\n\nThe inline parser treated **bold** content as opaque, so **`code`** kept\nits literal backticks and rendered as a bold run containing backtick\ncharacters. Parse the bold span's inner content recursively and OR the\nbold mark onto each resulting run, so an overlapping span carries both\n`bol\n[…]\nple\n(stdin markdown → comment[] JSON), used to repair existing comments via\nPUT /comment/{id} with the exact same rendering logic.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): handle nested bold+code inline marks in comment convert…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:17:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e5ca2e330aa7a06c92091280829dcda9bc8d4928",
"body": "ClickUp's Comments API does not render markdown. `comment_text` is run\nthrough a lossy auto-formatter that turns every backtick span into an\nisolated inline-code chip, so a comment with many code tokens renders as\ndisconnected gray boxes with the prose shattered around them. The\n`markdown_content` f\n[…]\n,\nfenced block renders as a code block, list items keep their inline marks,\nand there is no duplicated raw-text tail.\n\nCloses #294\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): render comments via structured comment[] rich-text (#294)",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-06-02T21:17:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f93edfff2d9e63087e2fe3bdcfd4beb97032c383",
"body": "v0.30.0 publish run failed at devboy-executor because the new\ndevboy-telegram crate (#262) had never been published to crates.io —\nthe release workflow's Layer 2 list didn't include it, and the\ncrate's manifest was missing crates.io metadata (keywords/categories/\nreadme/homepage and workspace-resolv\n[…]\n\nDocs:\n - tools.md regenerated for the new version header\n\nVersions: 0.30.0 → 0.30.1 across [workspace.package].version,\n[workspace.dependencies] (27 internal crates), and the three plugin\nmanifests.",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.30.1 + fix telegram publish",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-27T18:29:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "083403d7ecb2eac296d372e6e2f8a0fce8dfa717",
"body": "Minor release — telegram messenger provider added (#262, gh#86).\n\nVersions bumped: [workspace.package].version, [workspace.dependencies]\n(27 internal crates incl. new devboy-telegram), plus three plugin\nmanifests (.claude-plugin/marketplace, plugins/{claude,codex}/.../plugin.json).",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.30.0",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-27T17:53:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "404dce121e85dfd73db34cee68f37e067bfc5c32",
"body": "…er-provider\n\nfeat: add telegram messenger provider (#86)",
"is_bot": false,
"headline": "Merge pull request #262 from meteora-pro/feat/86-add-telegram-messeng…",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-05-27T17:49:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6e97438da7b3c74e3976d24958765868b94fc935",
"body": "…hub.com/meteora-pro/devboy-tools into feat/86-add-telegram-messenger-provider",
"is_bot": false,
"headline": "Merge branch 'feat/86-add-telegram-messenger-provider' of https://git…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-26T19:45:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f7568ef46d5e6720b655525fe45832f7d0e4a35",
"body": "…to feat/86-add-telegram-messenger-provider",
"is_bot": false,
"headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-26T19:45:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9883a8db83148aae020125e977611463d2dd9fa0",
"body": "crates.io rejected devboy-token-catalog 0.29.2 publish with:\n > The following category slugs are not currently supported on\n > crates.io: configuration\n\nThe slug for configuration-related crates is `config`, not\n`configuration`. Verified against\nhttps://crates.io/api/v1/categories — `config` is va\n[…]\n\nUnblocks the 0.29.2 release pipeline (Layer 1 step 4 of 4). Other\ncrates (devboy-core, devboy-secret-patterns, devboy-vault-crypto)\nalready shipped, so this is a cherry-pick fix on the trailing leaf.",
"is_bot": false,
"headline": "fix(token-catalog): use valid crates.io category slug `config`",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T18:39:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "13b79ba6c5899120d21f7e46d4a699792adfad09",
"body": "`release.yml` step `Verify reference docs match the tagged binary` runs\n`devboy tools docs --check` which compares the committed snapshot to\nthe binary-generated one. After bumping workspace to 0.29.2 the header\n\"DevBoy Tools v{version}\" went out of sync and the check failed,\nblocking the GitHub release + npm publish pipeline.\n\nOnly the version line changed; all tool schemas are identical to the\n0.29.1 generation.",
"is_bot": false,
"headline": "docs(tools): regenerate reference for 0.29.2 header",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T17:52:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee004191d7f9d1d6adcd0cc22f7dadf376be4cde",
"body": "v0.29.1 publish run failed at devboy-storage because devboy-storage now\ndepends on devboy-secret-patterns (epic #247 secrets framework) which\nhad never been published to crates.io — the release workflow's Layer 1\nonly knew about devboy-core. Layer 1 succeeded (devboy-core 0.29.1\nshipped), Layer 2 bl\n[…]\npace.package].version,\n[workspace.dependencies] (15 lib crates + 10 internal secret/plugin\ncrates), and the three plugin manifests (.claude-plugin/marketplace,\nplugins/{claude,codex}/.../plugin.json).",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.29.2 + extend release pipeline",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T17:43:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a8c28f98e8ce1d3913d1a3c865b00b9b7decb2f",
"body": "Patch release picking up:\n - gh#287 (PR #289): wire ClickUp assignees through POST/PUT /task — the\n `update_issue` / `create_issue` paths in the ClickUp adapter were\n accepting an `assignees` arg and silently dropping it before sending\n to ClickUp.\n - gh#288 (PR #290): support setting Cli\n[…]\nmps:\n - [workspace.package].version: 0.29.0 → 0.29.1\n - [workspace.dependencies] internal devboy-* crates: 0.29.0 → 0.29.1\n - .claude-plugin/marketplace.json, plugins/{claude,codex}/.../plugin.json",
"is_bot": false,
"headline": "chore(release): bump workspace to 0.29.1",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T17:24:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6db36ec7747a1f6c3a0a2d44965d1273c86d3107",
"body": "feat(clickup): support setting custom statuses via update_issue (#288)",
"is_bot": false,
"headline": "Merge pull request #290 from meteora-pro/feat/288-clickup-custom-status",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-05-26T15:32:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aecd47a008a8afc95e097777d99f8a9b1b3cb1db",
"body": "…t-pagination-schema\n\nfix(executor): restore get_meeting_transcript pagination/filter schema (#291)",
"is_bot": false,
"headline": "Merge pull request #292 from meteora-pro/fix/gh-291-restore-transcrip…",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-05-26T15:10:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5bf86b2c4ebf363d599c65049d68bbfd8d3ce64a",
"body": "…om-status\n\n# Conflicts:\n#\tcrates/plugins/api/clickup/src/client.rs",
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/main' into feat/288-clickup-cust…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T15:09:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "abc8e4f61a9faeaef9c5c895d66364bcbd961589",
"body": "fix(clickup): wire assignees through PUT/POST /task (#287)",
"is_bot": false,
"headline": "Merge pull request #289 from meteora-pro/fix/287-clickup-assignees-no-op",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-05-26T15:02:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d4f1ff8e26d14414ce6bb4a5f34c0d193de6ae9",
"body": "… grouped]\n\nCopilot review feedback on PR #292: format was declared as free-form string\neven though dispatcher only accepts 'flat' / 'grouped'. Switch to\n`PropertySchema::string_enum` so MCP client-side validators reject invalid\nvalues up-front and the generated docs render the allowed set explicitly.",
"is_bot": false,
"headline": "fix(executor): constrain get_meeting_transcript.format to enum [flat,…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T09:01:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bad7e3c2809e61465f90270ec0a57ef5be08e68",
"body": "…gh#291)",
"is_bot": false,
"headline": "docs(tools): regenerate after get_meeting_transcript schema restore (…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T08:59:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "918cf049e633410fdd29012a4de9563f90d43403",
"body": "…a (gh#291)\n\nThe `get_meeting_transcript` tool definition currently advertises only\nthe `meeting_id` property to MCP clients, but the consumer backend\n(devboy-api-rs `TranscriptArgs`) parses 5 additional optional fields —\n`offset`, `limit`, `speaker_filter`, `search_text`, `format`. Without\nthese in\n[…]\nconsumer code change needed beyond bumping the dependency.\n\nTests:\n- New `test_get_meeting_transcript_exposes_pagination_and_filters`\n regression guard\n- All existing tool-schema tests pass (241/241)",
"is_bot": false,
"headline": "fix(executor): restore get_meeting_transcript pagination/filter schem…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-26T08:50:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a14a77f50ecf16cf4612e38bbb88c6609236c16",
"body": "CI failures on PR #290 v2 (commit eec44ac):\n\n- Docs job: docs/guide/reference/tools.md generator picks up the new\n `status` field on update_issue + update_epic schemas. Regenerated\n via `cargo run -p devboy-cli -- tools docs --output ...`. Also\n trimmed the trailing period on the state field's de\n[…]\ndevboy-clickup unchanged (the new\n validate_status_name and fetch_list_statuses helpers are private,\n no public surface change).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: refresh tools.md + devboy-core baseline for status field (#288)",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-26T07:51:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d6d1218657804ed86b184b7faad3e0f68f46a778",
"body": "…pTeams*\n\nBakes the four new pub structs introduced in this PR into the\ncargo-public-api baseline:\n\n- AssigneeDiff (PUT /task assignees envelope)\n- ClickUpTeamsResponse / ClickUpTeam / ClickUpTeamMember\n (GET /team response shape used by resolve_assignee_ids)\n\nPlus the new `assignees: Option<Assign\n[…]\naskRequest.\n\nPattern matches existing types (CreateTaskRequest, ClickUpUser, …)\nwhich are all pub-exported via `pub use types::*`.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(clickup): refresh public-api baseline for AssigneeDiff + ClickU…",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-26T07:48:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "eec44acd52d2cd69cb16a8088964da5775140948",
"body": "Review feedback on #290:\n\n1. execute_update_epic was hardcoding UpdateIssueInput.status to None\n while execute_update_issue threaded params.status. Epics are stored\n as ClickUp tasks too, so the same custom-status workflow applies.\n Added a status field to UpdateEpicParams, threaded it through\n[…]\n 11th status not leaked\n\nWorkspace clippy / fmt / test all green; 102 clickup tests (94 +\nexisting 5 status + 2 new + 1 epic).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): address PR #290 review (epic status + error hints + DRY)",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-26T03:43:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "31f9cf49c0c9f39f4b02bd5cee45daacd502f46f",
"body": "…287)\n\nAddress review feedback on PR #289:\n\n- resolve_assignee_ids: spell out the three resolution paths (numeric\n ID pass-through with no verification, /team lookup with case-\n insensitive email/username match, fail-loud on unresolvable). Notes\n why numeric IDs skip the workspace fetch and the A\n[…]\nctical\n impact is small because assignee changes are rare and idempotent.\n\nBehavior unchanged; 8 / 8 assignees tests still green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(clickup): clarify assignee resolution semantics + race window (#…",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-26T03:38:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d72b6c10ad704e351cffa1291d7ebe129f9b31e9",
"body": "…rver instance",
"is_bot": false,
"headline": "test(telegram): refactor search_messages tests to use a single MockSe…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-25T22:06:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5128e3a2ea6bacaa0b2d42797c1073ddb28d60d",
"body": "…update handling",
"is_bot": false,
"headline": "refactor(telegram): simplify filter logic and improve readability in …",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-25T21:48:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "521e6c733fc7dec35d51de2cb0250d62e50d1c97",
"body": "…te handling",
"is_bot": false,
"headline": "feat(telegram): enhance TelegramClient with state management and upda…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-25T21:48:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9619675728b2c4ef0e5b9a5dce2a7074930966e7",
"body": null,
"is_bot": false,
"headline": "feat(telegram): add Telegram provider tests and configuration handling",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-25T21:39:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9a3dd40f02d875fdd72788bc1722519f9acf518",
"body": "The unified update_issue MCP tool exposed only a generic\nstate: enum(\"open\", \"closed\") field. ClickUp custom statuses like\n\"in progress\", \"review\", or any list-defined status were unreachable\nthrough the MCP layer — callers had to open the ClickUp UI to move a\ntask forward in its workflow. This bloc\n[…]\n mapping are scoped to follow-up PRs.\n\nWorkspace clippy clean, fmt clean, 99 / 99 clickup tests + full\nworkspace test suite green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(clickup): support setting custom statuses via update_issue (#288)",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-25T13:06:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c79180acf44c0f728a054aaa67c8170b6e43c731",
"body": "ClickUp's PUT /task/:id silently ignored the assignees field because the\nunderlying UpdateTaskRequest struct didn't declare it. POST /task also\nhardcoded assignees: None. Result: any assignees passed via the unified\nupdate_issue / create_issue MCP tool were dropped on the floor with a\n200 OK — silen\n[…]\nomits the field\n - unknown email fails before PUT\n - POST sends flat array\n\n102/102 clickup tests green (94 existing + 8 new).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(clickup): wire assignees through PUT/POST /task (#287)",
"author_name": "Mikhail KItaev",
"author_login": null,
"committed_at": "2026-05-25T12:57:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "db74a11a70fef393feb0b64870c5d34da4bc803b",
"body": null,
"is_bot": false,
"headline": "doc(telegram): update provider count and add Telegram to messenger tools",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-21T10:51:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec91ac083cd6ae70e5fc38c2c6bea96bb8239c0b",
"body": "… tracing dependency",
"is_bot": false,
"headline": "feat(telegram): add Telegram provider configuration and remove unused…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-21T10:42:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62c884fb85d121096d5801dd6ecc9d5e93fa056f",
"body": "…to feat/86-add-telegram-messenger-provider",
"is_bot": false,
"headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-21T09:47:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "48d2765527f615d8caa62bdbb1f7537f154dbc49",
"body": null,
"is_bot": false,
"headline": "feat(telegram): add Telegram provider to workspace and CLI",
"author_name": "mikhailova-klavdia",
"author_login": "mikhailova-klavdia",
"committed_at": "2026-05-21T09:45:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b51e6bffc1b535c8bddb9cb37aa423757c1e74eb",
"body": "…dispatch\n\nfix(confluence): KB dispatch + self-hosted Server payloads + with_instance_url",
"is_bot": false,
"headline": "Merge pull request #286 from meteora-pro/fix/confluence-proxy-and-kb-…",
"author_name": "qumagis",
"author_login": "qumagis",
"committed_at": "2026-05-20T17:56:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9cc414ba52affc46720583addaef35c52f38b81e",
"body": "…pi baseline\n\nThree review comments and the public-api CI gate:\n\n1. **`send_json` body allocation** (review on `client.rs:297`). Switched\n from `response.text()` + `serde_json::from_str` to `response.bytes()`\n + `serde_json::from_slice`, so the happy path skips the extra UTF-8\n validation pass\n[…]\nnst\na real self-hosted Confluence Server — 100 spaces, all URLs on the\nreal instance host (same as before, because `_links.base` echoes the\nreal host in non-proxy deployments).\n\nRefs: gh#285, PR #286.",
"is_bot": false,
"headline": "fix(confluence): address PR #286 Copilot review + regenerate public-a…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-20T17:44:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5cd315cb06cc1243709eb9a3d2da16480f4d37e3",
"body": "Mirrors `JiraClient::with_instance_url`. Splits two roles previously\nserved by `base_url`:\n\n- **`base_url`** — API target. Stays the proxy host in proxy mode so\n every request transits the proxy.\n- **`instance_url`** — host used to render browse links\n (`_links.webui`, `/pages/<id>`). Stays the re\n[…]\nt_providers` reading\n`proxy_mcp_servers` to derive a Confluence HTTP proxy) is out of\nscope here — the schema has no Confluence HTTP-proxy section yet.\nTracked as a follow-up in gh#285.\n\nRefs: gh#285.",
"is_bot": false,
"headline": "feat(confluence): with_instance_url + browse-link host separation",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-20T17:24:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "872094eb3bac795d4bfa20426504300e14efc7c7",
"body": "…teger ids\n\nThree coupled bugs that combined to surface as a misleading\n\"No knowledge base provider supports '<tool>'\" against self-hosted\nConfluence Server / Data Center:\n\n1. **dispatch_builtin_tool** (KB/messenger/meeting arms) used\n `Err(e) => continue` unconditionally, swallowing real errors f\n[…]\ner id.\n- `send_json_decode_failure_surfaces_status_and_body_preview` — 200\n OK + HTML body must produce a diagnostic error message.\n\nRefs: gh#285 (Confluence proxy / KB dispatch / self-hosted reads).",
"is_bot": false,
"headline": "fix(confluence,mcp): KB dispatch hides real errors + accept Server in…",
"author_name": "Maxim Dymov",
"author_login": "qumagis",
"committed_at": "2026-05-20T17:20:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d736f202873ee3ae30a8b5d20d04f9d7d731f7a",
"body": "feat(secrets): implement secret framework — ADR-020/021/023 (epic #247, full history)",
"is_bot": false,
"headline": "Merge pull request #265 from meteora-pro/epic/247-secret-framework-impl",
"author_name": "ai-dev-2-meteora-pro",
"author_login": "ai-dev-2-meteora-pro",
"committed_at": "2026-05-18T22:03:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d4cad3a4e9ff45895569b13cc6b1e854e48a7be",
"body": "CI's `Unused deps (cargo-machete)` flagged `tokio` in\ncrates/devboy-secrets-ui-bin/Cargo.toml — the only reference in\nthe bin's source is now a doc comment (\"…switch to\ntokio::spawn_blocking\" on the attachment-save path), not a real\nuse. The HTTP-Vault block_on() path that needed tokio was\nremoved i\n[…]\ned; the failure\nwas the Swatinem/rust-cache@v2 post-step uploading the cache.\nTransient infrastructural; the next push retries it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(ci): drop unused tokio dep from devboy-secrets-ui-bin (DEV-247)",
"author_name": "Slava Kazarinov",
"author_login": "slavik-kazarinov",
"committed_at": "2026-05-18T10:10:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8f50096ab3c195ad54c93ea53e8fc123920ee2d7",
"body": "Five reviewable items from the inline review on PR #265.\nAll have regression tests; only R5 doesn't add a test (the\nfix is a single RegexBuilder swap with no observable behaviour\ndifference on legitimate inputs).\n\nR1 MED — verify_fresh_unlock TOCTOU/stale-state\n crates/devboy-secrets-agent/src/serv\n[…]\nev-dependency with the async_closure\n feature.\n\nBuild green, fmt clean, clippy -D warnings clean, all 1800+\nworkspace tests pass.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(secrets): address 5 PR-265 review findings (R1-R6) (DEV-247)",
"author_name": "Slava Kazarinov",
"author_login": "slavik-kazarinov",
"committed_at": "2026-05-18T09:11:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3be04a43825be01b7245297e10af4506f22daf22",
"body": "…DEV-247)\n\nCI's Windows test runner caught a Unix-only assumption in\n`derive_working_copy_path_drops_into_source_dir_with_timestamp`\n— the assertion did a string prefix match against\n`/tmp/x.devboy-working-`, which fails on Windows where the\n`PathBuf::with_file_name` call returns `/tmp\\x.devboy-work\n[…]\nand\n`p.file_name()` so the test passes regardless of how the OS\nchooses to spell the separator. Underlying behaviour is\nunchanged.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(secrets-kdbx): cross-platform path test for working-copy helper (…",
"author_name": "Slava Kazarinov",
"author_login": "slavik-kazarinov",
"committed_at": "2026-05-17T22:17:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "22490feecd8f40fa320f321986515cee6d8d1fb4",
"body": "…ne (DEV-247)\n\nPR #265 CI's `Public API drift (cargo-public-api)` flagged\ndevboy-gitlab: my earlier squash inadvertently dropped main's\n`AuthScheme` refactor (PAT vs OAuth header detection, #263).\n\nResolution:\n* Reset `crates/plugins/api/gitlab/src/client.rs` to the main\n version (restores `AuthSch\n[…]\ntlab/.public-api/baseline.txt`\n— only legitimate addition is `pub mod devboy_gitlab::liveness`\n(the epic's liveness probe module).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): restore main's AuthScheme in gitlab, regen public-api baseli…",
"author_name": "Slava Kazarinov",
"author_login": "slavik-kazarinov",
"committed_at": "2026-05-17T22:04:39Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 39,
"commits_last_year": 1798,
"latest_release_at": "2026-07-25T12:01:23Z",
"latest_release_tag": "v0.32.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 22,
"days_since_latest_release": 0,
"mean_days_between_releases": 9.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "devboy-cli",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"ai-agents",
"cli",
"devboy",
"developer-tools",
"mcp",
"command-line-utilities",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-cli",
"is_deprecated": false,
"latest_version": "0.28.1",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 3,
"total_downloads": 55,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 18,
"first_published_at": "2026-05-09T23:14:17.755383Z",
"latest_published_at": "2026-05-17T19:34:36.553031Z",
"latest_version_yanked": false,
"days_since_latest_publish": 68
},
{
"name": "devboy-mcp",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"ai-agents",
"claude",
"devboy",
"json-rpc",
"mcp",
"api-bindings",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-mcp",
"is_deprecated": false,
"latest_version": "0.28.1",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 3,
"total_downloads": 95,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 32,
"first_published_at": "2026-05-09T22:54:14.779703Z",
"latest_published_at": "2026-05-17T19:33:31.467335Z",
"latest_version_yanked": false,
"days_since_latest_publish": 68
},
{
"name": "devboy-core",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"ai-agents",
"devboy",
"developer-tools",
"mcp",
"providers",
"api-bindings",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-core",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 11,
"total_downloads": 7064,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2355,
"first_published_at": "2026-05-09T21:33:35.173319Z",
"latest_published_at": "2026-07-25T09:41:09.017534Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
},
{
"name": "@devboy-tools/cli",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"mcp",
"model-context-protocol",
"devboy",
"code-review",
"ai-agent",
"gitlab",
"github",
"clickup",
"jira"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@devboy-tools/cli",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 39,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 435,
"first_published_at": "2026-02-19T18:20:44.705000Z",
"latest_published_at": "2026-07-25T12:02:20.476000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
},
{
"name": "devboy-assets",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"ai-agents",
"assets",
"cache",
"devboy",
"filesystem",
"development-tools",
"caching",
"filesystem"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-assets",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 9,
"total_downloads": 6525,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2175,
"first_published_at": "2026-05-09T21:34:25.421466Z",
"latest_published_at": "2026-07-25T09:42:50.457971Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
},
{
"name": "devboy-skills",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"ai-agents",
"claude",
"devboy",
"manifest",
"skills",
"development-tools",
"parser-implementations"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-skills",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 4,
"total_downloads": 98,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 33,
"first_published_at": "2026-05-09T23:04:11.524448Z",
"latest_published_at": "2026-07-25T12:12:43.795419Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
},
{
"name": "devboy-storage",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"credentials",
"devboy",
"keychain",
"secrets",
"storage",
"authentication",
"development-tools",
"os"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/devboy-storage",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/meteora-pro/devboy-tools",
"versions_count": 9,
"total_downloads": 199,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 66,
"first_published_at": "2026-05-09T21:33:57.151193Z",
"latest_published_at": "2026-07-25T09:42:28.108262Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 4,
"stars": 13,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-02-16",
"count": 1
},
{
"date": "2026-03-11",
"count": 1
},
{
"date": "2026-03-27",
"count": 1
},
{
"date": "2026-06-08",
"count": 1
}
],
"complete": true,
"collected": 4,
"total_forks": 4
},
"star_history": null,
"open_issues_and_prs": 51
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples",
"notebooks"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [
"docs/research/paper1-repro/Makefile"
],
"api_schema_files": [],
"has_devcontainer": true,
"typecheck_configs": [
"docs/tsconfig.json"
],
"toolchain_manifests": [
"Cargo.toml",
"crates/devboy-assets/Cargo.toml",
"crates/devboy-cli/Cargo.toml",
"crates/devboy-core/Cargo.toml",
"crates/devboy-executor/Cargo.toml",
"crates/devboy-mcp/Cargo.toml",
"crates/devboy-secret-patterns/Cargo.toml",
"crates/devboy-secrets-agent/Cargo.toml",
"crates/devboy-secrets-ui-bin/Cargo.toml",
"crates/devboy-secrets-ui/Cargo.toml",
"crates/devboy-skills/Cargo.toml",
"crates/devboy-storage/Cargo.toml",
"crates/devboy-token-catalog/Cargo.toml",
"crates/devboy-vault-crypto/Cargo.toml",
"crates/llm-eval/Cargo.toml",
"crates/plugins/api/clickup/Cargo.toml",
"crates/plugins/api/confluence/Cargo.toml",
"crates/plugins/api/fireflies/Cargo.toml",
"crates/plugins/api/github/Cargo.toml",
"crates/plugins/api/gitlab/Cargo.toml",
"crates/plugins/api/jira/Cargo.toml",
"crates/plugins/api/slack/Cargo.toml",
"crates/plugins/api/telegram/Cargo.toml",
"crates/plugins/format-pipeline/Cargo.toml",
"crates/plugins/secrets/1password/Cargo.toml",
"crates/plugins/secrets/env-store/Cargo.toml",
"crates/plugins/secrets/kdbx/Cargo.toml",
"crates/plugins/secrets/keychain/Cargo.toml",
"crates/plugins/secrets/local-vault/Cargo.toml",
"crates/plugins/secrets/vault/Cargo.toml"
],
"largest_source_bytes": 381128,
"source_files_sampled": 329,
"oversized_source_files": 22,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"Cargo.toml",
"docs/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"crates",
"npm"
],
"dependencies": [
{
"name": "devboy-core",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tempfile",
"manifest": "crates/devboy-assets/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-core",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-executor",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-mcp",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-storage",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-patterns",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secrets-agent",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secrets-ui",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-token-catalog",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "regex",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "ratatui",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.30"
},
{
"name": "crossterm",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.28"
},
{
"name": "devboy-secret-keychain",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-local-vault",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-1password",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-kdbx",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-env-store",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-github",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-gitlab",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-clickup",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-jira",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-confluence",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-fireflies",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-slack",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-telegram",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-format-pipeline",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-skills",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_yaml",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.9"
},
{
"name": "tokio",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap-markdown",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.1"
},
{
"name": "tracing",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing-subscriber",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "anyhow",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "async-trait",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "futures",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dialoguer",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.11"
},
{
"name": "chrono",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "toml",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "flate2",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.1"
},
{
"name": "tar",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "zip",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8.4"
},
{
"name": "secrecy",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sentry",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sentry-tracing",
"manifest": "crates/devboy-cli/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "anyhow",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "async-trait",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "url",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sentry",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chrono",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "which",
"manifest": "crates/devboy-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8.0"
},
{
"name": "devboy-core",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-assets",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-gitlab",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-github",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-clickup",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-jira",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-confluence",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-fireflies",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-slack",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-telegram",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-format-pipeline",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tokio",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "async-trait",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "base64",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.22"
},
{
"name": "secrecy",
"manifest": "crates/devboy-executor/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-core",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-assets",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-executor",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-confluence",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-format-pipeline",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-storage",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-kdbx",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chrono",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "tokio",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest-eventsource",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "futures",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tokio-util",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.7"
},
{
"name": "async-trait",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-mcp/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-secret-patterns/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-secret-patterns/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-secret-patterns/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "regex",
"manifest": "crates/devboy-secret-patterns/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-secret-patterns/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-vault-crypto",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tokio",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-secrets-agent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secrets-ui",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-storage",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-token-catalog",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-vault-crypto",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-patterns",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-vault",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-kdbx",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "eframe",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.34"
},
{
"name": "egui_kittest",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.34.2"
},
{
"name": "image",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.25"
},
{
"name": "anyhow",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "regex",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "rfd",
"manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.15"
},
{
"name": "secrecy",
"manifest": "crates/devboy-secrets-ui/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chrono",
"manifest": "crates/devboy-secrets-ui/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "ratatui",
"manifest": "crates/devboy-secrets-ui/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.30"
},
{
"name": "crossterm",
"manifest": "crates/devboy-secrets-ui/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.28"
},
{
"name": "egui",
"manifest": "crates/devboy-secrets-ui/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.34"
},
{
"name": "thiserror",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "async-trait",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_yaml",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.9"
},
{
"name": "rust-embed",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8.5"
},
{
"name": "chrono",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "ulid",
"manifest": "crates/devboy-skills/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.1"
},
{
"name": "devboy-core",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-secret-patterns",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tracing",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "async-trait",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "bitflags",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.6"
},
{
"name": "regex",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chrono",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "sha2",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "hex",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "tokio",
"manifest": "crates/devboy-storage/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "thiserror",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "dirs",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chrono",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4"
},
{
"name": "rust-embed",
"manifest": "crates/devboy-token-catalog/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8"
},
{
"name": "thiserror",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "zeroize",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.8"
},
{
"name": "toml",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "base64",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tempfile",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "chacha20poly1305",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "getrandom",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "argon2",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "bip39",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "hkdf",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/devboy-vault-crypto/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "devboy-format-pipeline",
"manifest": "crates/llm-eval/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "anyhow",
"manifest": "crates/llm-eval/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/llm-eval/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "reqwest",
"manifest": "crates/llm-eval/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "secrecy",
"manifest": "crates/llm-eval/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 6,
"merged_prs": 123,
"open_issues": 45,
"closed_ratio": 0.729,
"closed_issues": 121,
"closed_unmerged_prs": 15
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "slavik-kazarinov",
"commits": 1081,
"avatar_url": "https://avatars.githubusercontent.com/u/126971369?v=4"
},
{
"type": "User",
"login": "qumagis",
"commits": 339,
"avatar_url": "https://avatars.githubusercontent.com/u/126944225?v=4"
},
{
"type": "User",
"login": "andreymaznyak",
"commits": 119,
"avatar_url": "https://avatars.githubusercontent.com/u/4545924?v=4"
},
{
"type": "User",
"login": "mikhailova-klavdia",
"commits": 98,
"avatar_url": "https://avatars.githubusercontent.com/u/114179767?v=4"
},
{
"type": "User",
"login": "ai-dev-2-meteora-pro",
"commits": 91,
"avatar_url": "https://avatars.githubusercontent.com/u/207333965?v=4"
},
{
"type": "User",
"login": "mikhkit",
"commits": 34,
"avatar_url": "https://avatars.githubusercontent.com/u/12929152?v=4"
},
{
"type": "User",
"login": "mkitaev",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/26816897?v=4"
}
],
"contributors_sampled": 7,
"top_contributor_share": 0.605
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"deploy-docs.yml",
"fixtures-update.yml",
"release-crates-io.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
"biome.json"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/5 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "21 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
"ran_at": "2026-07-25T13:14:27Z",
"aggregate_score": 3.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T12:14:05Z",
"oldest_open_prs": [
{
"number": 249,
"created_at": "2026-05-07T21:51:47Z",
"last_comment_at": "2026-05-07T21:54:13Z",
"last_comment_author": "codecov"
},
{
"number": 293,
"created_at": "2026-05-28T16:13:15Z",
"last_comment_at": "2026-05-28T16:22:23Z",
"last_comment_author": "codecov"
},
{
"number": 296,
"created_at": "2026-06-08T00:42:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 299,
"created_at": "2026-06-21T23:45:57Z",
"last_comment_at": "2026-06-30T23:15:08Z",
"last_comment_author": "codecov"
},
{
"number": 304,
"created_at": "2026-06-30T22:37:38Z",
"last_comment_at": "2026-07-01T00:30:19Z",
"last_comment_author": "codecov"
},
{
"number": 305,
"created_at": "2026-07-09T00:28:52Z",
"last_comment_at": "2026-07-09T00:33:59Z",
"last_comment_author": "codecov"
}
],
"last_merged_pr_at": "2026-07-25T12:02:48Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 64,
"created_at": "2026-03-26T10:28:49Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 65,
"created_at": "2026-03-26T10:29:59Z",
"last_comment_at": "2026-05-02T21:17:00Z",
"last_comment_author": "andreymaznyak"
},
{
"number": 68,
"created_at": "2026-03-26T17:38:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 69,
"created_at": "2026-03-26T17:39:00Z",
"last_comment_at": "2026-05-02T21:17:42Z",
"last_comment_author": "andreymaznyak"
},
{
"number": 73,
"created_at": "2026-03-27T15:09:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 87,
"created_at": "2026-03-28T20:09:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 88,
"created_at": "2026-03-28T20:10:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 89,
"created_at": "2026-03-28T20:10:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 90,
"created_at": "2026-03-28T20:10:34Z",
"last_comment_at": "2026-05-02T21:17:02Z",
"last_comment_author": "andreymaznyak"
},
{
"number": 99,
"created_at": "2026-03-30T08:41:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 100,
"created_at": "2026-03-30T08:41:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 112,
"created_at": "2026-04-03T08:44:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 120,
"created_at": "2026-04-10T21:23:47Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 124,
"created_at": "2026-04-10T21:24:28Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 125,
"created_at": "2026-04-11T09:31:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 210,
"created_at": "2026-04-26T21:59:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 211,
"created_at": "2026-04-28T03:46:50Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 213,
"created_at": "2026-04-30T06:17:53Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 240,
"created_at": "2026-05-04T17:18:56Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 241,
"created_at": "2026-05-04T17:19:23Z",
"last_comment_at": "2026-06-21T06:09:52Z",
"last_comment_author": "Necmttn"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/meteora-pro/devboy-tools",
"host": "github.com",
"name": "devboy-tools",
"owner": "meteora-pro"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": "High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "jurisdiction_overall_adjustment",
"params": {
"cap": 49,
"pct": 50
}
}
],
"value": 31,
"inputs": {
"security": 18,
"vitality": 83,
"community": 49,
"governance": 60,
"engineering": 86,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 50,
"weighted_overall_before_jurisdiction": 62,
"overall_after_jurisdiction_multiplier": 31
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"commits_last_year": 1798,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 22
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "22/52 weeks with commits",
"points": 15.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 22
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1798 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1798
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 39,
"latest_release_tag": "v0.32.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 9.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "39 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 39
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~9.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 9.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 49,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 22,
"inputs": {
"forks": 4,
"stars": 13,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "13 stars",
"points": 17.5,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 13
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "4 forks",
"points": 4,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 4
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"packages": [
"devboy-cli",
"devboy-mcp",
"devboy-core",
"@devboy-tools/cli",
"devboy-assets",
"devboy-skills",
"devboy-storage"
],
"dependents": null,
"ecosystems": "crates, npm",
"total_downloads": 14036,
"monthly_downloads": 5114
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "5,114 downloads/month across crates, npm",
"points": 49.5,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 5114,
"ecosystems": "crates, npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 60,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 33,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 7,
"top_contributor_share": 0.605
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 60% of commits",
"points": 8.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 60
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "7 contributors",
"points": 9.5,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 7
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"merged_prs": 123,
"open_issues": 45,
"closed_issues": 121,
"issue_closed_ratio": 0.729,
"closed_unmerged_prs": 15
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "73% of issues closed",
"points": 34.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 73
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "123/138 decided PRs merged",
"points": 34.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 123,
"decided": 138
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/5 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"followers": 4,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "meteora-pro",
"public_repos": 9,
"account_age_days": 2118
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "4 followers of meteora-pro",
"points": 5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 4,
"login": "meteora-pro"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "9 public repos, account ~5 yr old",
"points": 18.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 9
}
},
{
"code": "account_age_years",
"params": {
"years": 5
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"devboy-cli",
"devboy-mcp",
"devboy-core",
"@devboy-tools/cli",
"devboy-assets",
"devboy-skills",
"devboy-storage"
],
"ecosystems": "crates, npm",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "7 package(s) on crates, npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 7,
"ecosystems": "crates, npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "39 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 39
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 86,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "biome.json",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://meteora-pro.github.io/devboy-tools/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://meteora-pro.github.io/devboy-tools/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 18,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "High-Risk Jurisdiction Policy applies a 50% multiplier to Security posture and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "jurisdiction_posture_adjustment",
"params": {
"cap": 49,
"pct": 50
}
}
],
"value": 18,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 3.5,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 50,
"security_posture_after_multiplier": 18,
"security_posture_before_jurisdiction": 35
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/5 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "21 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "moderate",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 50,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": true,
"exposures": [
{
"role": "top_contributor",
"count": 1,
"country": "Russia"
}
],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "Russia: top_contributor (1)",
"points": 50,
"status": "partial",
"details": [
{
"code": "jurisdiction_exposure",
"params": {
"role": "top_contributor",
"count": 1,
"country": "Russia"
}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 68,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.96,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 96,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"docs/research/paper1-repro/Makefile"
],
"has_devcontainer": true,
"has_linter_config": true,
"typecheck_configs": [
"docs/tsconfig.json"
],
"agent_commit_share": 0.61,
"toolchain_manifests": [
"Cargo.toml",
"crates/devboy-assets/Cargo.toml",
"crates/devboy-cli/Cargo.toml",
"crates/devboy-core/Cargo.toml",
"crates/devboy-executor/Cargo.toml",
"crates/devboy-mcp/Cargo.toml",
"crates/devboy-secret-patterns/Cargo.toml",
"crates/devboy-secrets-agent/Cargo.toml",
"crates/devboy-secrets-ui-bin/Cargo.toml",
"crates/devboy-secrets-ui/Cargo.toml",
"crates/devboy-skills/Cargo.toml",
"crates/devboy-storage/Cargo.toml",
"crates/devboy-token-catalog/Cargo.toml",
"crates/devboy-vault-crypto/Cargo.toml",
"crates/llm-eval/Cargo.toml",
"crates/plugins/api/clickup/Cargo.toml",
"crates/plugins/api/confluence/Cargo.toml",
"crates/plugins/api/fireflies/Cargo.toml",
"crates/plugins/api/github/Cargo.toml",
"crates/plugins/api/gitlab/Cargo.toml",
"crates/plugins/api/jira/Cargo.toml",
"crates/plugins/api/slack/Cargo.toml",
"crates/plugins/api/telegram/Cargo.toml",
"crates/plugins/format-pipeline/Cargo.toml",
"crates/plugins/secrets/1password/Cargo.toml",
"crates/plugins/secrets/env-store/Cargo.toml",
"crates/plugins/secrets/kdbx/Cargo.toml",
"crates/plugins/secrets/keychain/Cargo.toml",
"crates/plugins/secrets/local-vault/Cargo.toml",
"crates/plugins/secrets/vault/Cargo.toml"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "docs/research/paper1-repro/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/research/paper1-repro/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "biome.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "docs/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "devcontainer, Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "devcontainer, Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "61 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 61,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 96,
"inputs": {
"primary_language": "Rust",
"largest_source_bytes": 381128,
"source_files_sampled": 329,
"oversized_source_files": 22
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Rust (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "22/329 source files over 60KB",
"points": 51.3,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 329,
"oversized": 22
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples",
"notebooks"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples, notebooks",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples, notebooks"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch crates package 'llm-eval' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T13:14:45.021201Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/meteora-pro/devboy-tools.svg",
"full_name": "meteora-pro/devboy-tools",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}