Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 13:14 UTC

meteora-pro / devboy-tools

Configurable tool bundle for AI coding agents — use via MCP server, CLI, or agent skills. npm wrapper for the Rust binary.

RustApache-2.0★ 13 зірок⑂ 4 форкиз січ. 2026 р.Переглянути на GitHub ↗

meteora-pro/devboy-tools має індекс здоров’я 31 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Engineering Quality (86/100), найнижчий — Security (18/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

31
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

31
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Політика юрисдикцій високого ризику застосовує множник 50% до зваженого загального індексу здоров’я і встановлює для нього межу «У зоні ризику» на рівні 49.

Власність

Meteora ProОрганізація
4 підписники9 публічних репозиторіївз жовт. 2020 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
crates.iodevboy-cli0.28.118368 днів томуai-agentsclidevboydeveloper-toolsmcpcommand-line-utilitiesdevelopment-tools
crates.iodevboy-mcp0.28.132368 днів томуai-agentsclaudedevboyjson-rpcmcpapi-bindingsdevelopment-tools
crates.iodevboy-core0.32.02 355110 днів томуai-agentsdevboydeveloper-toolsmcpprovidersapi-bindingsdevelopment-tools
npm@devboy-tools/cli0.32.0435390 днів томуmcpmodel-context-protocoldevboycode-reviewai-agentgitlabgithubclickupjira
crates.iodevboy-assets0.32.02 17590 днів томуai-agentsassetscachedevboyfilesystemdevelopment-toolscaching
crates.iodevboy-skills0.32.03340 днів томуai-agentsclaudedevboymanifestskillsdevelopment-toolsparser-implementations
crates.iodevboy-storage0.32.06690 днів томуcredentialsdevboykeychainsecretsstorageauthenticationdevelopment-toolsos

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

83Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
15.2/36Ритм комітів — 22/52 тижнів із комітами
18/18Обсяг комітів — 1 798 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year1 798
human_commit_share1
days_since_last_push0
active_weeks_last_year22
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 39 релізів
36/36Свіжість релізів — останній реліз 0 дн. тому
27/27Ритм релізів — реліз кожні ~9,1 дн.
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Використані вхідні дані
releases_count39
latest_release_tagv0.32.0
releases_from_tagsні
days_since_latest_release0
mean_days_between_releases9,1

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

49У зоні ризику · 18% загального індексу
Як обчислюється оцінка
17.5/60Зірки — 13 зірок
4/25Форки — 4 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks4
stars13
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
18/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
49.5/80Щомісячні завантаження — 5 114 завантажень/місяць у crates, npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagesdevboy-cli, devboy-mcp, devboy-core, @devboy-tools/cli, devboy-assets, devboy-skills, devboy-storage
dependents
ecosystemscrates, npm
total_downloads14 036
monthly_downloads5 114
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

60Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
8.9/22.5Розподіл комітів — головний контриб’ютор — автор 60% комітів
9.5/13.5Широта контриб’юторів — 7 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled7
top_contributor_share0,605
Як обчислюється оцінка
34.1/46.8Вирішення issue — закрито 73% issue
34.1/38.3Прийняття PR — злито 123/138 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/5 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs123
open_issues45
closed_issues121
issue_closed_ratio0,729
closed_unmerged_prs15
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
5/25Охоплення власника — 4 підписників у meteora-pro
18.9/25Послужний список — 9 публічних репозиторіїв, вік облікового запису ~5 р.
Використані вхідні дані
followers4
owner_typeOrganization
is_verified
owner_loginmeteora-pro
public_repos9
account_age_days2 118

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 7 пакет(ів) у crates, npm
35/35Свіжість публікацій — остання публікація 0 дн. тому
20/20Історія версій — 39 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesdevboy-cli, devboy-mcp, devboy-core, @devboy-tools/cli, devboy-assets, devboy-skills, devboy-storage
ecosystemscrates, npm
any_deprecatedні
min_days_since_publish0

Інженерна якість

Чи наявні базові інженерні практики та документація?

86Відмінний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 5 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — biome.json
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні

Документація

90Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://meteora-pro.github.io/devboy-tools/
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepagehttps://meteora-pro.github.io/devboy-tools/
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

18Критичний · 16% загального індексу

Стан безпеки

18Критичний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/5 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 21 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3,5
high_risk_jurisdiction_cap49
high_risk_jurisdiction_multiplier50
security_posture_after_multiplier18
security_posture_before_jurisdiction35
Політика юрисдикцій високого ризику застосовує множник 50% і встановлює для стану безпеки межу «У зоні ризику» на рівні 49.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

68Помірний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 96 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,96
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
18/18Розгортання однією командою — docs/research/paper1-repro/Makefile
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — biome.json
11/11Статична перевірка типів — docs/tsconfig.json
10/10Відтворюване середовище — devcontainer, Dockerfile, lockfile
10/10Підтверджена практика роботи з агентами — 61 з останніх 100 комітів створено агентом або з його зазначенням
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfilespnpm-lock.yaml
has_dockerfileтак
typed_languageтак
bootstrap_filesdocs/research/paper1-repro/Makefile
has_devcontainerтак
has_linter_configтак
typecheck_configsdocs/tsconfig.json
agent_commit_share0,61
toolchain_manifestsCargo.toml, crates/devboy-assets/Cargo.toml, crates/devboy-cli/Cargo.toml, crates/devboy-core/Cargo.toml, crates/devboy-executor/Cargo.toml, crates/devboy-mcp/Cargo.toml, crates/devboy-secret-patterns/Cargo.toml, crates/devboy-secrets-agent/Cargo.toml, crates/devboy-secrets-ui-bin/Cargo.toml, crates/devboy-secrets-ui/Cargo.toml, crates/devboy-skills/Cargo.toml, crates/devboy-storage/Cargo.toml, crates/devboy-token-catalog/Cargo.toml, crates/devboy-vault-crypto/Cargo.toml, crates/llm-eval/Cargo.toml, crates/plugins/api/clickup/Cargo.toml, crates/plugins/api/confluence/Cargo.toml, crates/plugins/api/fireflies/Cargo.toml, crates/plugins/api/github/Cargo.toml, crates/plugins/api/gitlab/Cargo.toml, crates/plugins/api/jira/Cargo.toml, crates/plugins/api/slack/Cargo.toml, crates/plugins/api/telegram/Cargo.toml, crates/plugins/format-pipeline/Cargo.toml, crates/plugins/secrets/1password/Cargo.toml, crates/plugins/secrets/env-store/Cargo.toml, crates/plugins/secrets/kdbx/Cargo.toml, crates/plugins/secrets/keychain/Cargo.toml, crates/plugins/secrets/local-vault/Cargo.toml, crates/plugins/secrets/vault/Cargo.toml
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Rust (статично типізована)
51.3/55Керовані розміри файлів — 22/329 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageRust
largest_source_bytes381 128
source_files_sampled329
oversized_source_files22
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
40/40Придатні до запуску приклади — examples, notebooks
Використані вхідні дані
example_dirsexamples, notebooks
has_mcp_signalтак
api_schema_files

Ключові факти

13зірок GitHub
7контриб'юторів
1 798комітів за останні 12 місяців
0днів від останнього пушу
39релізів
1бас-фактор
45відкритих issue
crates.io, npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'llm-eval' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

Історія зірок і форків 0 ★ / 4 ⇿
0Зірки
4Форки
36Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

1223344412026-022026-042026-06
Мажорні 0Мінорні 29Патчі 7
OpenSSF Scorecard 3.5 / 10
3.5сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 13:14 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/5 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities21 existing vulnerabilities detected
Прямі залежності 198
РеєстрПакетОбмеження версіїМаніфест
crates.iodevboy-corecrates/devboy-assets/Cargo.toml
crates.iothiserrorcrates/devboy-assets/Cargo.toml
crates.ioserdecrates/devboy-assets/Cargo.toml
crates.ioserde_jsoncrates/devboy-assets/Cargo.toml
crates.iotracingcrates/devboy-assets/Cargo.toml
crates.iotomlcrates/devboy-assets/Cargo.toml
crates.iodirscrates/devboy-assets/Cargo.toml
crates.iosha2crates/devboy-assets/Cargo.toml
crates.iotempfilecrates/devboy-assets/Cargo.toml
crates.iodevboy-corecrates/devboy-cli/Cargo.toml
crates.iodevboy-executorcrates/devboy-cli/Cargo.toml
crates.iodevboy-mcpcrates/devboy-cli/Cargo.toml
crates.iodevboy-storagecrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-cli/Cargo.toml
crates.iodevboy-secrets-agentcrates/devboy-cli/Cargo.toml
crates.iodevboy-secrets-uicrates/devboy-cli/Cargo.toml
crates.iodevboy-token-catalogcrates/devboy-cli/Cargo.toml
crates.ioregexcrates/devboy-cli/Cargo.toml
crates.ioratatui0.30crates/devboy-cli/Cargo.toml
crates.iocrossterm0.28crates/devboy-cli/Cargo.toml
crates.iodevboy-secret-keychaincrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-local-vaultcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-1passwordcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-env-storecrates/devboy-cli/Cargo.toml
crates.iodevboy-githubcrates/devboy-cli/Cargo.toml
crates.iodevboy-gitlabcrates/devboy-cli/Cargo.toml
crates.iodevboy-clickupcrates/devboy-cli/Cargo.toml
crates.iodevboy-jiracrates/devboy-cli/Cargo.toml
crates.iodevboy-confluencecrates/devboy-cli/Cargo.toml
crates.iodevboy-firefliescrates/devboy-cli/Cargo.toml
crates.iodevboy-slackcrates/devboy-cli/Cargo.toml
crates.iodevboy-telegramcrates/devboy-cli/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-cli/Cargo.toml
crates.iodevboy-skillscrates/devboy-cli/Cargo.toml
crates.ioserde_yaml0.9crates/devboy-cli/Cargo.toml
crates.iotokiocrates/devboy-cli/Cargo.toml
crates.ioserdecrates/devboy-cli/Cargo.toml
crates.ioserde_jsoncrates/devboy-cli/Cargo.toml
crates.ioclapcrates/devboy-cli/Cargo.toml
crates.ioclap-markdown0.1crates/devboy-cli/Cargo.toml
crates.iotracingcrates/devboy-cli/Cargo.toml
crates.iotracing-subscribercrates/devboy-cli/Cargo.toml
crates.ioanyhowcrates/devboy-cli/Cargo.toml
crates.ioasync-traitcrates/devboy-cli/Cargo.toml
crates.iofuturescrates/devboy-cli/Cargo.toml
crates.ioreqwestcrates/devboy-cli/Cargo.toml
crates.iodialoguer0.11crates/devboy-cli/Cargo.toml
crates.iochrono0.4crates/devboy-cli/Cargo.toml
crates.iotomlcrates/devboy-cli/Cargo.toml
crates.iodirscrates/devboy-cli/Cargo.toml
crates.ioflate21.1crates/devboy-cli/Cargo.toml
crates.iotar0.4crates/devboy-cli/Cargo.toml
crates.iozip8.4crates/devboy-cli/Cargo.toml
crates.iosecrecycrates/devboy-cli/Cargo.toml
crates.iosentrycrates/devboy-cli/Cargo.toml
crates.iosentry-tracingcrates/devboy-cli/Cargo.toml
crates.iothiserrorcrates/devboy-core/Cargo.toml
crates.ioanyhowcrates/devboy-core/Cargo.toml
crates.ioserdecrates/devboy-core/Cargo.toml
crates.ioserde_jsoncrates/devboy-core/Cargo.toml
crates.ioasync-traitcrates/devboy-core/Cargo.toml
crates.iotracingcrates/devboy-core/Cargo.toml
crates.iotomlcrates/devboy-core/Cargo.toml
crates.iodirscrates/devboy-core/Cargo.toml
crates.ioreqwestcrates/devboy-core/Cargo.toml
crates.iourlcrates/devboy-core/Cargo.toml
crates.iosecrecycrates/devboy-core/Cargo.toml
crates.iosentrycrates/devboy-core/Cargo.toml
crates.iochrono0.4crates/devboy-core/Cargo.toml
crates.iowhich8.0crates/devboy-core/Cargo.toml
crates.iodevboy-corecrates/devboy-executor/Cargo.toml
crates.iodevboy-assetscrates/devboy-executor/Cargo.toml
crates.iodevboy-gitlabcrates/devboy-executor/Cargo.toml
crates.iodevboy-githubcrates/devboy-executor/Cargo.toml
crates.iodevboy-clickupcrates/devboy-executor/Cargo.toml
crates.iodevboy-jiracrates/devboy-executor/Cargo.toml
crates.iodevboy-confluencecrates/devboy-executor/Cargo.toml
crates.iodevboy-firefliescrates/devboy-executor/Cargo.toml
crates.iodevboy-slackcrates/devboy-executor/Cargo.toml
crates.iodevboy-telegramcrates/devboy-executor/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-executor/Cargo.toml
crates.iotokiocrates/devboy-executor/Cargo.toml
crates.ioserdecrates/devboy-executor/Cargo.toml
crates.ioserde_jsoncrates/devboy-executor/Cargo.toml
crates.ioasync-traitcrates/devboy-executor/Cargo.toml
crates.iotracingcrates/devboy-executor/Cargo.toml
crates.iothiserrorcrates/devboy-executor/Cargo.toml
crates.iobase640.22crates/devboy-executor/Cargo.toml
crates.iosecrecycrates/devboy-executor/Cargo.toml
crates.iodevboy-corecrates/devboy-mcp/Cargo.toml
crates.iodevboy-assetscrates/devboy-mcp/Cargo.toml
crates.iodevboy-executorcrates/devboy-mcp/Cargo.toml
crates.iodevboy-confluencecrates/devboy-mcp/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-mcp/Cargo.toml
crates.iodevboy-storagecrates/devboy-mcp/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-mcp/Cargo.toml
crates.iochrono0.4crates/devboy-mcp/Cargo.toml
crates.iotokiocrates/devboy-mcp/Cargo.toml
crates.ioserdecrates/devboy-mcp/Cargo.toml
crates.ioserde_jsoncrates/devboy-mcp/Cargo.toml
crates.iotracingcrates/devboy-mcp/Cargo.toml
crates.ioreqwestcrates/devboy-mcp/Cargo.toml
crates.ioreqwest-eventsourcecrates/devboy-mcp/Cargo.toml
crates.iofuturescrates/devboy-mcp/Cargo.toml
crates.iotokio-util0.7crates/devboy-mcp/Cargo.toml
crates.ioasync-traitcrates/devboy-mcp/Cargo.toml
crates.iothiserrorcrates/devboy-mcp/Cargo.toml
crates.iosecrecycrates/devboy-mcp/Cargo.toml
crates.iothiserrorcrates/devboy-secret-patterns/Cargo.toml
crates.ioserdecrates/devboy-secret-patterns/Cargo.toml
crates.iotomlcrates/devboy-secret-patterns/Cargo.toml
crates.ioregexcrates/devboy-secret-patterns/Cargo.toml
crates.iotracingcrates/devboy-secret-patterns/Cargo.toml
crates.iodevboy-vault-cryptocrates/devboy-secrets-agent/Cargo.toml
crates.iothiserrorcrates/devboy-secrets-agent/Cargo.toml
crates.ioserdecrates/devboy-secrets-agent/Cargo.toml
crates.ioserde_jsoncrates/devboy-secrets-agent/Cargo.toml
crates.iotokiocrates/devboy-secrets-agent/Cargo.toml
crates.iotracingcrates/devboy-secrets-agent/Cargo.toml
crates.iosecrecycrates/devboy-secrets-agent/Cargo.toml
crates.iodirscrates/devboy-secrets-agent/Cargo.toml
crates.iodevboy-secrets-uicrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-storagecrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-token-catalogcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-vault-cryptocrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-vaultcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioeframe0.34crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioegui_kittest0.34.2crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioimage0.25crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioanyhowcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioclapcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iosecrecycrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioregexcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioreqwestcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodirscrates/devboy-secrets-ui-bin/Cargo.toml
crates.iotomlcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iorfd0.15crates/devboy-secrets-ui-bin/Cargo.toml
crates.iosecrecycrates/devboy-secrets-ui/Cargo.toml
crates.iochrono0.4crates/devboy-secrets-ui/Cargo.toml
crates.ioratatui0.30crates/devboy-secrets-ui/Cargo.toml
crates.iocrossterm0.28crates/devboy-secrets-ui/Cargo.toml
crates.ioegui0.34crates/devboy-secrets-ui/Cargo.toml
crates.iothiserrorcrates/devboy-skills/Cargo.toml
crates.ioserdecrates/devboy-skills/Cargo.toml
crates.ioserde_jsoncrates/devboy-skills/Cargo.toml
crates.ioasync-traitcrates/devboy-skills/Cargo.toml
crates.iodirscrates/devboy-skills/Cargo.toml
crates.iosha2crates/devboy-skills/Cargo.toml
crates.ioserde_yaml0.9crates/devboy-skills/Cargo.toml
crates.iorust-embed8.5crates/devboy-skills/Cargo.toml
crates.iochrono0.4crates/devboy-skills/Cargo.toml
crates.ioulid1.1crates/devboy-skills/Cargo.toml
crates.iodevboy-corecrates/devboy-storage/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-storage/Cargo.toml
crates.iothiserrorcrates/devboy-storage/Cargo.toml
crates.ioserdecrates/devboy-storage/Cargo.toml
crates.ioserde_jsoncrates/devboy-storage/Cargo.toml
crates.iotomlcrates/devboy-storage/Cargo.toml
crates.iotracingcrates/devboy-storage/Cargo.toml
crates.iodirscrates/devboy-storage/Cargo.toml
crates.iosecrecycrates/devboy-storage/Cargo.toml
crates.ioasync-traitcrates/devboy-storage/Cargo.toml
crates.iobitflags2.6crates/devboy-storage/Cargo.toml
crates.ioregexcrates/devboy-storage/Cargo.toml
crates.iochrono0.4crates/devboy-storage/Cargo.toml
crates.iosha2crates/devboy-storage/Cargo.toml
crates.iohex0.4crates/devboy-storage/Cargo.toml
crates.iotokiocrates/devboy-storage/Cargo.toml
crates.ioserdecrates/devboy-token-catalog/Cargo.toml
crates.ioserde_jsoncrates/devboy-token-catalog/Cargo.toml
crates.iothiserrorcrates/devboy-token-catalog/Cargo.toml
crates.iodirscrates/devboy-token-catalog/Cargo.toml
crates.iotomlcrates/devboy-token-catalog/Cargo.toml
crates.ioreqwestcrates/devboy-token-catalog/Cargo.toml
crates.iosha2crates/devboy-token-catalog/Cargo.toml
crates.iochrono0.4crates/devboy-token-catalog/Cargo.toml
crates.iorust-embed8crates/devboy-token-catalog/Cargo.toml
crates.iothiserrorcrates/devboy-vault-crypto/Cargo.toml
crates.ioserdecrates/devboy-vault-crypto/Cargo.toml
crates.iosecrecycrates/devboy-vault-crypto/Cargo.toml
crates.iozeroize1.8crates/devboy-vault-crypto/Cargo.toml
crates.iotomlcrates/devboy-vault-crypto/Cargo.toml
crates.iobase64crates/devboy-vault-crypto/Cargo.toml
crates.iotempfilecrates/devboy-vault-crypto/Cargo.toml
crates.iochacha20poly1305crates/devboy-vault-crypto/Cargo.toml
crates.iogetrandomcrates/devboy-vault-crypto/Cargo.toml
crates.ioargon2crates/devboy-vault-crypto/Cargo.toml
crates.iobip39crates/devboy-vault-crypto/Cargo.toml
crates.iohkdfcrates/devboy-vault-crypto/Cargo.toml
crates.iosha2crates/devboy-vault-crypto/Cargo.toml
crates.iodevboy-format-pipelinecrates/llm-eval/Cargo.toml
crates.ioanyhowcrates/llm-eval/Cargo.toml
crates.ioserde_jsoncrates/llm-eval/Cargo.toml
crates.ioreqwestcrates/llm-eval/Cargo.toml
crates.iosecrecycrates/llm-eval/Cargo.toml
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 20179,
      "has_wiki": true,
      "homepage": "https://meteora-pro.github.io/devboy-tools/",
      "languages": {
        "Rust": 6328763,
        "Shell": 23652,
        "Python": 206422,
        "Dockerfile": 1042,
        "JavaScript": 2655
      },
      "pushed_at": "2026-07-25T12:02:50Z",
      "created_at": "2026-01-26T02:26:36Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T12:02:53Z",
      "description": "Configurable tool bundle for AI coding agents — use via MCP server, CLI, or agent skills. npm wrapper for the Rust binary.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "https://meteora.pro",
      "name": "Meteora Pro",
      "type": "Organization",
      "login": "meteora-pro",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/72404657?v=4",
      "created_at": "2020-10-05T16:16:24Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 2118
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-07-25T12:01:23Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-07-01T06:46:06Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-06-09T16:31:36Z"
        },
        {
          "tag": "v0.30.1",
          "kind": "patch",
          "published_at": "2026-05-27T18:49:30Z"
        },
        {
          "tag": "v0.29.2",
          "kind": "patch",
          "published_at": "2026-05-26T18:55:00Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-05-19T08:00:39Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2026-05-17T19:39:06Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-05-10T20:49:18Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-05-09T21:42:01Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-05-04T16:14:32Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-05-02T20:43:42Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-05-02T09:51:23Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-05-01T19:36:43Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-04-29T22:41:23Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2026-04-25T15:54:28Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-04-25T13:16:14Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-04-25T12:59:30Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-04-24T22:29:01Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-04-24T14:58:14Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-04-23T21:33:54Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2026-04-16T06:19:23Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-04-15T11:38:18Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-04-14T19:34:38Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-04-07T09:28:00Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-04-07T09:14:33Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-04-03T10:07:33Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-03-29T21:37:04Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-03-28T13:48:21Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-03-28T09:25:57Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-03-23T15:45:02Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-03-23T12:49:57Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-03-23T06:56:12Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-17T13:59:40Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-17T10:41:38Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-17T08:44:09Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T09:30:54Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:01:26Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-03T10:09:16Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-02-19T18:20:14Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
          "body": "ci(release): crates.io = libraries only + metadata-derived publish + dry-run gate",
          "is_bot": false,
          "headline": "Merge pull request #312 from meteora-pro/feat/crates-io-lib-only-publish",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T12:02:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b291203525e99847019f4e563e694cd0e7179f17",
          "body": "Option A for the chronically-broken crates.io release (#308):\n\n- Mark devboy-cli (app binary) + devboy-mcp publish=false — they hard-depend on\n  the internal secrets plugins (publish=false), so they can never publish to\n  crates.io. Distributed via npm + release binaries instead.\n- Replace the hardc\n[…]\ns on every PR, before the release tag.\n\nValidated: dry-run packages exactly the 17 clean libs, skips cli/mcp/plugins.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): crates.io = libraries only, metadata-derived + dry-run gate",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T11:52:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8a9ec73a0f066df21668863da20eecb3401eeb2",
          "body": "…able\n\nci(release): skip publish=false crates in crates.io publish",
          "is_bot": false,
          "headline": "Merge pull request #311 from meteora-pro/fix/crates-io-skip-unpublish…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T10:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63acd9ec551739bcc1e6cc5e00f0530207f7f73d",
          "body": "The secrets epic (#247) added publish=false crates (devboy-secrets-agent,\nsecrets-ui, all secrets plugins), but release-crates-io.yml's publish loop\nstill lists them and publish_if_new only tolerated \"already exists\" — so\n`cargo publish` on an unpublishable crate aborted the whole release\n(v0.32.0 p\n[…]\nied on\ndevboy-secrets-agent). Guard publish_if_new to skip crates whose\ncargo-metadata `publish` is [] (publish=false).\n\nRefs #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): skip publish=false crates in crates.io publish",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T10:08:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62326cadfa29b81f123b3b71a2c2f4d81fe1c3fd",
          "body": "docs: clarify wayland-scanner transitive + fold dep note into 0.32.0 (#309 review)",
          "is_bot": false,
          "headline": "Merge pull request #310 from meteora-pro/fix/dep-note-accuracy",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T07:19:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24f36d82ec59497fe0093e882a4bf5c9ab44cfed",
          "body": "Addresses Copilot review on #309: wayland-scanner is not a direct dependency —\nit resolves transitively (via eframe) to >= 0.31.11; only ratatui and keepass\nare direct bumps. Also moves the dep-upgrade entry from [Unreleased] into the\nunpublished [0.32.0] release (where it actually ships).\n\nDocs-only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: clarify wayland-scanner is transitive; fold dep note into 0.32.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T07:09:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3da2453af52e6e16d2fc3de14f5009622c2e747f",
          "body": "fix(deps): drop all RustSec ignores via ratatui/keepass/wayland-scanner upgrades",
          "is_bot": false,
          "headline": "Merge pull request #309 from meteora-pro/fix/rustsec-drop-ignores",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:45:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "498db1a03d978df7745c6839cd43f17b372d55e5",
          "body": "- ratatui 0.29 → 0.30 (removes unmaintained `paste`, RUSTSEC-2024-0436)\n- keepass 0.12 → 0.13 + wayland-scanner → 0.31.11 (both pull quick-xml >= 0.41,\n  fixing RUSTSEC-2026-0194 / -0195 DoS)\n- deny.toml [advisories].ignore is now empty\n\nFresh dependency resolve confirmed: no `paste`, quick-xml 0.41.0 only.\nNo first-party API/behavior changes; build/clippy/tests/fmt/cargo-deny green.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): drop all RustSec ignores via dependency upgrades",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:32:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "39171aa96f0e9307c5840add902079bdbd2328b5",
          "body": "feat: OAuth 2.1 auth for proxy MCP upstreams (device flow + auto-refresh)",
          "is_bot": false,
          "headline": "Merge pull request #307 from meteora-pro/feat/oauth2-proxy",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:12:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04527ee884c0def1b68cc270e9c586e011e3155e",
          "body": "The tools reference embeds the version banner; sync it after the 0.32.0 bump\n(Docs --check gate).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(docs): regenerate tools reference for v0.32.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:56:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f782dea01a99747ccc57a5dfb16d0b29493b4c79",
          "body": "Bump workspace + plugin manifests 0.31.1 → 0.32.0; cut CHANGELOG [0.32.0].\nPublish (crates.io + npm) is gated on pushing the v0.32.0 tag — not done here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.32.0 — OAuth 2.1 proxy auth",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:52:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5f89a8da9717d4cf8aacdf17a8f90ecffbdbe78",
          "body": "…llback, full initialize probe\n\n- well_known_url: bracket IPv6 authority (host_str() yields unbracketed ::1,\n  building a malformed URL; require_web_url permits http loopback IPv6). +test.\n- OAuthAuth::new: drop the reqwest::Client::new() fallback that re-enabled the\n  default redirect policy on the\n[…]\n436 note (paste is pulled by ratatui, not\n  egui/eframe; compile-time proc-macro only).\n\nAddresses Copilot review threads on #307.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): address review feedback — IPv6 well-known, no-redirect fa…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:52:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e116eea390656a59844c5bab2d60edd2a616931",
          "body": "… (#306)\n\nThe MCP authorization spec requires the client to pass `resource=<mcp-url>`\non the authorization, token, and refresh requests so the AS binds the\nissued token's audience to the target MCP server. Thread the resource\nindicator through request_device_authorization, poll_device_token_once,\nan\n[…]\ns no introspection endpoint — so end-to-end tool calls are\nblocked on server-side token validation, tracked separately.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): send RFC 8707 resource indicator on device/token/refresh…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T15:46:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2bb0f1a47f9b6b45ef0a5b0d57cff6a5100d1d09",
          "body": "…(#306)\n\nThree integration bugs found by end-to-end testing `devboy login` against\nthe real app.devboy.pro authorization server (unit/integration tests and\nstatic review missed all three — they only surface against a live server):\n\n- Config source mismatch: cmd_login loaded via Config::load() (the g\n[…]\nrough discovery → registration → device\nauthorization → poll (clean `expired_token` termination) against\napp.devboy.pro.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): make `devboy login` work against a live RFC-compliant AS …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T14:43:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1780b322058969185baf8c01fcf7c2c59445b7a",
          "body": "…ate (#306)\n\nRemaining review findings:\n\n- cmd_login's device-poll loop had no client-side deadline (`expires_in`\n  was parsed but unused); a misbehaving AS answering `authorization_pending`\n  forever hung the CLI. Bound it by the device code's lifetime.\n- request_sse pushed the pending (id, tx) reg\n[…]\nd token_endpoint — so a config\n  missing it showed green while the proxy was silently skipped. Doctor\n  now checks both.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): bound device poll, plug SSE pending leak, align doctor st…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "daac829a18b53eb60b5d8c81382349c1978b623e",
          "body": "The single-flight gate was in-process only, but a multi-agent setup runs\nseveral `devboy` processes (one proxy per agent) against the same\nkeychain key. When the access token expired, each independently spent\nthe same rotating refresh token; the AS rotates once, so every loser got\n`invalid_grant` an\n[…]\nopts the winner's pair rather than surfacing a re-login.\n\nAdds a test simulating another process having already rotated.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): store-reconcile refresh to survive rotation races (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb5590d0e7e545c4938aa3fecf20db32cee3e0f8",
          "body": "…306)\n\nTwo token-response hardening fixes from the independent review:\n\n- Panic-DoS: `now + Duration::seconds(expires_in)` panicked on an\n  attacker-controlled `expires_in` (e.g. i64::MAX — a valid JSON\n  integer). In OAuthAuth::refresh that aborts the running MCP proxy on a\n  live tool call. Clamp \n[…]\ncess, refresh success); metadata parses keep\n  their detail.\n\nAdds a from_response test for the out-of-range expires_in.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): clamp expires_in + stop echoing token bodies in errors (#…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41b83a006ad4dd41391cc4a9279636005b0669a1",
          "body": "…ints (#306)\n\nIndependent review (Kimi K3 + a second reviewer) found the discovery\ntrust boundary was porous. Harden it:\n\n- require_web_url now parses with `url::Url` instead of string prefixes.\n  It rejects credentials in the authority (`http://localhost@evil/`),\n  non-http(s) schemes, and — for ht\n[…]\nurned `issuer` matches (§3.3).\n\nAdds tests for the bypasses, IP-range rejection, and path-aware\nwell-known construction.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): close SSRF holes in discovery + validate advertised endpo…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:36:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9234a6813f046a856f2ca7480ee5edcda39bef2",
          "body": "…h (#306)\n\nCopilot review: the request_http oauth2 behavior (pre-flight token, then\nrefresh-and-retry-once on 401) had no test at the proxy request layer —\nonly the OAuthAuth contract was covered. Add a focused test that mocks a\npersistent 401 on tools/call and asserts exactly one refresh\n(single-flight) + one retry, ending in the actionable re-login error.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(proxy): cover oauth2 refresh-and-retry on 401 in the request pat…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "384faff414f3d28b7e3b14d737bdfbd44a481005",
          "body": "…d (#306)\n\nCopilot review: `devboy doctor` marked an oauth2 proxy \"logged_in\" on the\nmere presence of a stored secret, but the proxy path needs it to\ndeserialize as OAuthTokens. A corrupt/partial blob now reads as\nnot-logged-in (with the actionable `devboy login` fix) instead of a\nfalse-positive session.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(doctor): report oauth2 logged_in only when the token blob is vali…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3fd6d62036067d88fd9fe34c8c724dc2d293c4d",
          "body": "Address Copilot review findings on the login/discovery path:\n\n- SSRF guard: validate every outbound discovery URL (resource_metadata\n  from the WWW-Authenticate challenge, and the AS issuer) via\n  require_web_url — https required, http only for loopback. A crafted\n  upstream challenge can no longer \n[…]\ntted entirely).\n\nAdds require_web_url unit tests (https/loopback ok; remote-http, file,\nftp, gopher, hostless rejected).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): harden discovery + honor advertised scopes (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b6ee42560e8ea846727d9b0462129e49c074c09",
          "body": "CI's stable clippy rolled to 1.97, whose stricter lints flag pre-existing\ncode (unrelated to this PR, but it blocks the shared Clippy gate under\nRUSTFLAGS=-Dwarnings):\n\n- question_mark: collapse `match opt { Some/None=>return }` and an\n  `else if let … else { return None }` chain into `?`\n  (devboy-\n[…]\nll behavior-preserving. Full-workspace `clippy --all-targets\n--all-features` under -Dwarnings is clean on stable 1.97.1.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clippy): resolve rust-1.97 lints across workspace (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:36:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b9ea1285811731450d242d5a12fe5eff83e740f0",
          "body": "cargo-deny went red on freshly-published RUSTSEC-2026-0194/0195\n(quick-xml DoS via malicious XML, patched >= 0.41.0) — a pre-existing\necosystem issue, not introduced by this PR. quick-xml enters only via\nkeepass (parses the user's own local .kdbx password DB) and\nwayland-scanner (build-time proc-mac\n[…]\needs upstream releases.\nIgnore with a documented reachability analysis, matching the existing\nRUSTSEC-2024-0436 pattern.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): ignore unreachable quick-xml XML-DoS advisories (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:22:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da7c2d2e4ba082be6deed866e1770ebd176caa62",
          "body": "…(#306)\n\nBring PR #307's red hygiene jobs to green with the honest ADR-019 fix\nrather than gaming the gates:\n\n- Secrets discipline: TokenResponse/OAuthTokens token fields are now\n  secrecy::SecretString (was String). OAuthTokens round-trips through a\n  scoped secret_serde helper, so the only plainte\n[…]\n path.\n\n309 devboy-core + 266 devboy-mcp tests pass; fmt/clippy/rustdoc/\npublic-api/secrets-discipline verified locally.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): carry proxy tokens as SecretString + green hygiene gates …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:22:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f87ea5d036bff42d1812d5e9dafdd27a25503cf",
          "body": "Review issue #2: adds a test for the exact sequence request_http/request_sse\nrun on a 401 — access_token() (pre-flight, valid token unchanged) -> refresh\n(sent) (single-flight) -> access_token() yields the rotated token. Full\ntransport-level e2e (with initialize/session/id echoing) is deferred as it\nadds flakiness for little extra coverage over this contract test.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(oauth): cover on-401 refresh-retry contract (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:51:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f16aa4949c40460622ef3a8c1de3718882d3de38",
          "body": "…e (#306)\n\nReview issues #3/#4/#5:\n- cmd_login rejects non-oauth2 proxies with a clear message instead of\n  attempting a device flow against a bearer/api_key upstream.\n- request_http/request_sse map a post-refresh 401 to an actionable error\n  (\"run: devboy login <name>\") instead of a raw HTTP 401; r\n[…]\nt.\n- OAuthAuth::refresh documents the persist-before-swap failure semantics\n  (dead-refresh -> re-login, no corruption).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): login guard + actionable 401 errors + persist-failure not…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:49:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7892bd06ca0f720d25f72e70c2b4275d349f4f0",
          "body": "Review issue #1: oauth2 was only injected into request_http (streamable-\nhttp). SSE proxies with auth_type=\"oauth2\" ran unauthenticated. Now the SSE\nGET stream is seeded with the access token at connect, and request_sse POSTs\ncarry a per-request Bearer with the same on-401 single-flight refresh-retry\nas request_http. Documented follow-up: stream reconnect-on-refresh (the GET\nstream header is fixed at connect).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(proxy): wire OAuth into SSE transport too (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:47:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "096181995c54692c9aa5f1cbbfa4683fff24700f",
          "body": "proxy.md gains an \"OAuth 2.1 authentication (device flow)\" section (config +\n`devboy login` + doctor state); auth_type field row lists oauth2. Regenerated\ncli.md reference to include the new `login` command.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(oauth): document auth_type=oauth2 + devboy login (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T21:03:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cb81a3892d74dc3bbc0d0cb862b34e1d1708b37d",
          "body": "doctor now accepts auth_type=\"oauth2\" (was flagged Invalid) and reports per\nproxy: Pass \"logged in; tokens auto-refresh\" when the proxy.<name>.oauth\nsecret + client_id exist, else Error \"not logged in\" with the exact fix\ncommand `devboy login <name>`. This is the stdio-side awareness signal for a\nhu\n[…]\nio-only, so http WWW-Authenticate passthrough is N/A — noted as a\nfollow-up if a remote http server mode is ever added.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(doctor): report OAuth login state for oauth2 proxies (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:59:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "860db46be2dbdf0ff8ba91daafa678b3a1d98d4e",
          "body": "…nt (#306)\n\nProxyOAuthConfig gains token_endpoint, cached by devboy login after discovery\nso the proxy refreshes headlessly without re-discovery. build_oauth_auth loads\nthe stored OAuthTokens (proxy.<name>.oauth) + client_id/token_endpoint and\nconstructs the OAuthAuth holder; build_proxy_manager wir\n[…]\n, skipping — with a clear \"run: devboy login <name>\"\n— any proxy not yet logged in. bearer/api_key/none still pass None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): activate oauth2 at runtime — ProxyManager + token_endpoi…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:54:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d1706d94e387ed78a633558a074c52c72d45f84",
          "body": "McpProxyClient gains an optional OAuthAuth holder. For auth_type=\"oauth2\"\nthe Bearer is injected per request from the holder (pre-flight refresh),\nnot baked at connect; request_http sends in a retry loop that on a 401 runs\na single-flight refresh and retries once with the rotated token. bearer/\napi_\n[…]\nxyManager activation follows). Test asserts persistence\nvia store.exists (no expose_secret — ADR-023 guard stays green).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): per-request OAuth Bearer + on-401 refresh-retry (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:50:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6218d1d71be03eed73ddaf1e65acabeb8b10ed96",
          "body": "…(#306)\n\nPer-upstream token holder for auth_type=\"oauth2\". access_token() refreshes\npre-flight within a 60s expiry skew; refresh(seen) is single-flight (gate +\naccess-token double-check so concurrent 401s trigger exactly one refresh)\nand persists the rotated pair to the credential store BEFORE the i\n[…]\ns a spent refresh_token. 2 tokio\ntests (rotation+persist, double-check short-circuit). Wired into the request\npath next.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): OAuthAuth holder — single-flight refresh, rotation-safe …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:37:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f43e960b802c6b02ace1322123fc8a267c5e433",
          "body": "New top-level command orchestrating the RFC 8628 device flow against a proxy\nupstream: discover AS (WWW-Authenticate probe or configured authorization_\nserver) -> register client if needed (persisted to config) -> device\nauthorization -> print user_code + verification_uri_complete -> poll the\ntoken \n[…]\n and auto-refreshes these. Compiles clean; built on the tested oauth\nprimitives (discovery/registration/device/refresh).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): devboy login <server> — OAuth 2.1 device flow (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:32:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e0f409cb4f42634e44d65fe8bdd45f0805fcf683",
          "body": "Persisted token set for one proxy upstream (JSON into the credential store\nunder proxy.<name>.oauth). OAuthTokens::from_response computes expires_at\nfrom expires_in relative to now, with a prev_refresh fallback; is_near_expiry\ndrives pre-flight refresh. 5 unit tests (expiry compute, refresh fallback,\nmissing-refresh error, near-expiry threshold, JSON roundtrip).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): OAuthTokens model — access/refresh/expires_at (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "920619cfd498e9547bece03d2c387ab9dd4e4dcf",
          "body": "refresh() exchanges a refresh_token for a fresh token set via the RFC 6749\n§6 grant. Documents the AS rotation contract: the server returns a NEW\nrefresh_token and deactivates the old, so callers must persist-first and\nsingle-flight (enforced later in the proxy layer). invalid_grant surfaces\nas OAut\n[…]\nOauth so the caller can trigger re-login.\nAdds httpmock dev-dep; 2 integration tests (rotation success + invalid_grant).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): refresh_token grant — RFC 6749 §6, rotation-aware (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:25:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22b3cc7796cd22d6a4ab0b36b2fc64c302fc130c",
          "body": "request_device_authorization posts the RFC 8628 §3.1 form (client_id +\noptional scope) and parses the §3.2 response (device_code, user_code,\nverification_uri[_complete], expires_in, interval defaulting to 5).\npoll_device_token_once polls the token endpoint with the device_code grant\nand maps outcome\n[…]\nResponse, other error codes -> OAuthError::Oauth.\nparse_oauth_error extracts the RFC 6749 §5.2 error code. 5 unit tests.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): device authorization grant + token poll — RFC 8628 (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:20:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7974b05e1acea3915040e4f7223f970c33cb52ee",
          "body": "register_client posts a public device-flow client registration (grant_types\ndevice_code + refresh_token, token_endpoint_auth_method=\"none\") to the AS\nregistration_endpoint and returns the issued client_id. Callers persist it\ninto ProxyOAuthConfig.client_id so re-login reuses the same client.\nGRANT_DEVICE_CODE / GRANT_REFRESH_TOKEN constants shared with later grants.\n2 unit tests (request shape + response parse).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): dynamic client registration — RFC 7591 (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:16:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6f07ada25ab46899f96e2d8fb40d911590f876bf",
          "body": "…(#306)\n\nNew devboy-core::oauth module (client half of the MCP auth spec, standard\nRFCs only). This commit: discovery.\n- parse_www_authenticate: extract resource_metadata URL (RFC 9728), quoted\n  or bare, ignoring other challenge params.\n- discover: WWW-Authenticate -> protected-resource metadata ->\n[…]\n9 unit tests (parsing + metadata deserialization).\n\nRegistration (RFC 7591), device grant (RFC 8628) and refresh follow.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): OAuth 2.1 discovery — WWW-Authenticate -> RFC 9728/8414 …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:01:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73d21b6882d2a7a2fa8952f273fb9f2439e99e04",
          "body": "Additive config surface for OAuth 2.1 proxy auth. ProxyMcpServerConfig\ngains an optional `oauth` block (ProxyOAuthConfig: client_id / scopes /\nauthorization_server, all optional). A minimal config sets only\nauth_type = \"oauth2\" and lets discovery (RFC 9728/8414) + dynamic\nregistration (RFC 7591) fil\n[…]\ndevboy login`.\n\nBackward compatible: bearer / api_key / none unchanged. All 16 struct\nliterals updated with oauth: None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): add auth_type=\"oauth2\" + ProxyOAuthConfig (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T19:57:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd7176471447d1ab7d5d82afb6d508a89a662558",
          "body": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
          "is_bot": false,
          "headline": "Merge pull request #303 from meteora-pro/fix/crates-io-publish-secrets",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-07-01T07:50:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5730a6bf3c6a68d7d34ceddb5f4842ad6b2ee4b",
          "body": "The crates.io release failed at `Publish devboy-mcp` with \"no matching\npackage named devboy-secret-kdbx found\": devboy-mcp depends on\ndevboy-secret-kdbx, but none of the 8 secrets crates were in the publish\norder, so they were never uploaded before the crates that need them\n(devboy-mcp via kdbx, dev\n[…]\neds secrets-agent).\nUses the same publish_if_new idempotency, so it survives partial-retry of\nthe already-published 0.31.1 crates.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T18:26:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c4ee9bedf5a81e3018d7df585cdef46773a487f1",
          "body": "chore(release): bump workspace to 0.31.1",
          "is_bot": false,
          "headline": "Merge pull request #302 from meteora-pro/chore/release-0.31.1",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-30T15:58:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eee3eca94d2f5b4fff23e8ac66ab6a5623c1ee84",
          "body": "Per docs/guide/contributing/release.md Step 1:\n- [workspace.package].version 0.31.0 -> 0.31.1\n- all [workspace.dependencies] devboy-* version pins -> 0.31.1\n- sync plugin manifests (claude/codex plugin.json + marketplace.json)\n  via scripts/release/sync-plugin-version.sh\n- regenerate docs/guide/refe\n[…]\nersion, skills, readme sync,\ntools/cli reference). Tag v0.31.1 after this merges to fan out the\nnpm + crates.io release workflows.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.31.1",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T15:55:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0324e0c52176a38babe0f6093da20a019075185f",
          "body": "…down-blocks\n\nfix(clickup): render comment markdown via comment blocks (#300)",
          "is_bot": false,
          "headline": "Merge pull request #301 from meteora-pro/fix/300-clickup-comment-mark…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-30T15:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "159fbe85c824114bb93b35d3018a4eea98bc49ee",
          "body": "The public-api drift job ran on a floating `dtolnay/rust-toolchain@nightly`.\ncargo-public-api prints fully-qualified type paths, so a toolchain change\n(std::io::Error becoming a re-export of core::io::Error) shifted every\nbaseline that mentions io::Error, failing CI on unrelated crates.\n\nPin the job\n[…]\nthe std::io::error -> core::io::error path rename; no\nreal public API changed. Bump the pin deliberately + regenerate when needed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(public-api): pin nightly toolchain, regenerate baselines (#300)",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T15:36:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "75155e6d7b56a1bcb05dc72ac822cc774105f157",
          "body": "… (#300)\n\nBuilds on the existing comment_format.rs converter (markdown -> ClickUp\n`comment` rich-text runs) rather than duplicating it. Adds:\n\n- italic (`*x*` / `_x_`) and `[text](url)` links as inline run attributes\n- GFM tables -> aligned monospace `code-block` (comments have no table\n  mark); col\n[…]\nting bold rendering\n\nThe inline parser is char-based, so all additions are UTF-8 safe.\nVerified against the real ClickUp API + UI.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): extend comment markdown — italic, links, tables, tasks…",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T12:41:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "32724cf4e0355e40141d2123fc82daef60422d1b",
          "body": "…y-status\n\nfeat(clickup): surface display status + category in get_issue (DEV-1578)",
          "is_bot": false,
          "headline": "Merge pull request #298 from meteora-pro/feat/DEV-1578-clickup-displa…",
          "author_name": "ai-dev-2-meteora-pro",
          "author_login": "ai-dev-2-meteora-pro",
          "committed_at": "2026-06-09T14:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc325febc2bd414bdd418f11741c5d5c3f6213f4",
          "body": "…ion (DEV-1578b)\n\nAddresses PR #298 merge-readiness review (test-coverage gaps). Adds\ntest_resolve_custom_field_display_degrades_gracefully asserting every\nnon-resolving branch yields display=None with the raw value preserved\n(never a wrong label / panic):\n- drop_down order index out of u32 range (t\n[…]\no matching option\n- drop_down option id with no match\n- type_config present but options empty\n- labels ids with no matching option\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(clickup): cover graceful-degradation branches in display resolut…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:41:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "13f99c22449ba71d0b858914321341bc9a15de3a",
          "body": "Follow-on to the workspace 0.31.0 bump — regenerate the version-derived\nartifacts the CI drift checks enforce:\n- plugins/{claude,codex}/.../plugin.json + .claude-plugin/marketplace.json\n  (via scripts/release/sync-plugin-version.sh)\n- docs/guide/reference/tools.md header (\"DevBoy Tools v0.31.0 …\")\n  (via `devboy tools docs`)\n\nFixes the red \"Plugin manifests drift check\" and \"Docs\" CI jobs. Only the\nversion string changed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): sync plugin manifests + tools reference to 0.31.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:34:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a6dff8aeaab2ea973594a897bbb54c04e859a7e",
          "body": "DEV-1578 / DEV-1578b add public API (Issue.status/status_category,\nCustomFieldValue.display, ClickUp type_config resolution types) — a\nsemver-minor change. Bump [workspace.package].version and all internal\ndevboy-* dependency pins 0.30.1 → 0.31.0 so a crates.io publish resolves\nthe registry version consistently. (Publish itself stays gated: DEV-1579.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.31.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:29:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1ca6a4ca34b523acf9c31aab8a800161cb2de18b",
          "body": "Address PR #298 review (Copilot): resolve the drop_down order index with\n`u32::try_from(..).ok()?` instead of `as u32`, so an out-of-range value\nfails cleanly to `display = None` (raw value preserved) rather than\ntruncating to a wrong option label.\n\nAdd an httpmock end-to-end test (test_get_issues_r\n[…]\nved label in the\nserialized agent-facing JSON. Validates the serde wiring against the real\npayload, not just the in-memory mapper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): guard dropdown index + e2e wire-shape test (DEV-1578b)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:29:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "588bb03a3dc4d5f77b8bdc0a4cc0548fc551a149",
          "body": "Reflow only — `cargo fmt --all` (stable, matching the Format CI job)\ntouched nothing outside the new DEV-1578b code in client.rs. Fixes the\nred Format check on PR #298.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "style(clickup): rustfmt the DEV-1578b resolver + tests (DEV-1578b)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T09:01:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df828a87fcda5aa675984d7e5ddcf2f8ddfb0fd4",
          "body": "…ditions (DEV-1578)\n\nDEV-1578 added Issue.status / Issue.status_category, DEV-1578b added\nCustomFieldValue.display and the ClickUp drop_down/labels resolution types\n(ClickUpFieldTypeConfig / ClickUpFieldOptionInline, re-exported via\n`pub use types::*`). Regenerate the cargo-public-api baselines (pin\n[…]\ns:: + crate root)\n- devboy-clickup: 2 new public types + ClickUpCustomField.type_config\n\nAll 12 other first-wave crates: no drift.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(public-api): regenerate baselines for Issue/CustomFieldValue ad…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T08:21:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8fa4f408c0bb15d4ffb28e741c12805cdf30c6fb",
          "body": "…abels (DEV-1578b)\n\n`map_task` surfaced custom fields with ClickUp's opaque raw value — a\ndrop_down came back as its order index (`0`), a labels multi-select as an\narray of option ids — so an agent reading the field saw `0`, not `dev`.\nClickUp already embeds `type_config.options` (id/orderindex/name\n[…]\n display None\n\nPart of epic DEV-1577; surfaces the Shipped Version / Dev Env Host dropdowns\nas readable values instead of indices.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): resolve drop_down/labels custom-field values to human l…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T08:12:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e8402287e803e43c71452754bb0ce5f29068cb9a",
          "body": "ClickUp's rich workflow statuses (e.g. \"in progress\", \"review\", \"ready\nto release\", \"complete\") drive the team's \"what's deployed where\" board,\nbut get_issue/get_issues only exposed the binary `state` (open/closed),\ncollapsing the promotion stage. This is the read-path foundation for\nADR-114 (deploy\n[…]\n test_map_task; add test_map_task_surfaces_display_status\n  (clickup) + test_encode_issues_standard_includes_display_status (toon)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): surface display status + category in get_issue (DEV-1578)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-06T06:42:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bf0a19468466aeaef511b0f21bc9be1dbf3d3a2a",
          "body": "fix(clickup): render comments via structured comment[] rich-text (#294)",
          "is_bot": false,
          "headline": "Merge pull request #295 from meteora-pro/fix/clickup-comment-rich-text",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:45:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c64573d489bfd1f30dd4ea886b267cebb16b8b",
          "body": "…line (#294)\n\nCI resolves bitflags 2.12.1 (the repo doesn't commit Cargo.lock, so CI\nalways builds against latest deps). bitflags 2.12 adds an `all_named()`\nmethod to the macro-generated flags API, so `Capabilities::all_named()`\nnow appears in devboy-storage's public surface and the public-api drift\n[…]\nurely the two\n`all_named()` lines, no other changes. Unblocks unrelated PRs (this one\nonly touches the ClickUp comment converter).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(storage): add bitflags-generated all_named() to public-api base…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:29:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5fbf92a964180d3c97bf6143c82d627350830825",
          "body": "Making `comment_format` public (for the markdown→comment[] converter) and\nadding `CreateCommentRequest::comment` extends the crate's public surface.\nRegenerate the cargo-public-api baseline so the drift check passes. The\ndiff is purely additive: the new `comment_format` module types\n(CommentBlock, CommentAttributes, CodeBlockAttr, ListAttr),\nmarkdown_to_comment_blocks, and the new request field — no removals.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(clickup): regenerate public-api baseline for comment_format (#294)",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9691ecb80980d0e1b2a0d9b151819fc2a480ed64",
          "body": "…#294)\n\nAddress PR review: the trailing-newline trim only popped a single plain\n`\"\\n\"` block, so a body ending in multiple newlines (e.g. \"a\\n\\n\") left a\ndangling blank-line separator. Loop until no trailing plain newline\nremains, while preserving block-attribute separators (code-block / list)\nwhich are structurally significant. Add regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): trim all trailing plain newlines in comment converter (…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "52bb490b30355b69addd19469be34d3987b77a10",
          "body": "…er (#294)\n\nThe inline parser treated **bold** content as opaque, so **`code`** kept\nits literal backticks and rendered as a bold run containing backtick\ncharacters. Parse the bold span's inner content recursively and OR the\nbold mark onto each resulting run, so an overlapping span carries both\n`bol\n[…]\nple\n(stdin markdown → comment[] JSON), used to repair existing comments via\nPUT /comment/{id} with the exact same rendering logic.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): handle nested bold+code inline marks in comment convert…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e5ca2e330aa7a06c92091280829dcda9bc8d4928",
          "body": "ClickUp's Comments API does not render markdown. `comment_text` is run\nthrough a lossy auto-formatter that turns every backtick span into an\nisolated inline-code chip, so a comment with many code tokens renders as\ndisconnected gray boxes with the prose shattered around them. The\n`markdown_content` f\n[…]\n,\nfenced block renders as a code block, list items keep their inline marks,\nand there is no duplicated raw-text tail.\n\nCloses #294\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): render comments via structured comment[] rich-text (#294)",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f93edfff2d9e63087e2fe3bdcfd4beb97032c383",
          "body": "v0.30.0 publish run failed at devboy-executor because the new\ndevboy-telegram crate (#262) had never been published to crates.io —\nthe release workflow's Layer 2 list didn't include it, and the\ncrate's manifest was missing crates.io metadata (keywords/categories/\nreadme/homepage and workspace-resolv\n[…]\n\nDocs:\n  - tools.md regenerated for the new version header\n\nVersions: 0.30.0 → 0.30.1 across [workspace.package].version,\n[workspace.dependencies] (27 internal crates), and the three plugin\nmanifests.",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.30.1 + fix telegram publish",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T18:29:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "083403d7ecb2eac296d372e6e2f8a0fce8dfa717",
          "body": "Minor release — telegram messenger provider added (#262, gh#86).\n\nVersions bumped: [workspace.package].version, [workspace.dependencies]\n(27 internal crates incl. new devboy-telegram), plus three plugin\nmanifests (.claude-plugin/marketplace, plugins/{claude,codex}/.../plugin.json).",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.30.0",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T17:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "404dce121e85dfd73db34cee68f37e067bfc5c32",
          "body": "…er-provider\n\nfeat: add telegram messenger provider (#86)",
          "is_bot": false,
          "headline": "Merge pull request #262 from meteora-pro/feat/86-add-telegram-messeng…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T17:49:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e97438da7b3c74e3976d24958765868b94fc935",
          "body": "…hub.com/meteora-pro/devboy-tools into feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'feat/86-add-telegram-messenger-provider' of https://git…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-26T19:45:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f7568ef46d5e6720b655525fe45832f7d0e4a35",
          "body": "…to feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-26T19:45:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9883a8db83148aae020125e977611463d2dd9fa0",
          "body": "crates.io rejected devboy-token-catalog 0.29.2 publish with:\n  > The following category slugs are not currently supported on\n  > crates.io: configuration\n\nThe slug for configuration-related crates is `config`, not\n`configuration`. Verified against\nhttps://crates.io/api/v1/categories — `config` is va\n[…]\n\nUnblocks the 0.29.2 release pipeline (Layer 1 step 4 of 4). Other\ncrates (devboy-core, devboy-secret-patterns, devboy-vault-crypto)\nalready shipped, so this is a cherry-pick fix on the trailing leaf.",
          "is_bot": false,
          "headline": "fix(token-catalog): use valid crates.io category slug `config`",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T18:39:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13b79ba6c5899120d21f7e46d4a699792adfad09",
          "body": "`release.yml` step `Verify reference docs match the tagged binary` runs\n`devboy tools docs --check` which compares the committed snapshot to\nthe binary-generated one. After bumping workspace to 0.29.2 the header\n\"DevBoy Tools v{version}\" went out of sync and the check failed,\nblocking the GitHub release + npm publish pipeline.\n\nOnly the version line changed; all tool schemas are identical to the\n0.29.1 generation.",
          "is_bot": false,
          "headline": "docs(tools): regenerate reference for 0.29.2 header",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:52:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee004191d7f9d1d6adcd0cc22f7dadf376be4cde",
          "body": "v0.29.1 publish run failed at devboy-storage because devboy-storage now\ndepends on devboy-secret-patterns (epic #247 secrets framework) which\nhad never been published to crates.io — the release workflow's Layer 1\nonly knew about devboy-core. Layer 1 succeeded (devboy-core 0.29.1\nshipped), Layer 2 bl\n[…]\npace.package].version,\n[workspace.dependencies] (15 lib crates + 10 internal secret/plugin\ncrates), and the three plugin manifests (.claude-plugin/marketplace,\nplugins/{claude,codex}/.../plugin.json).",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.29.2 + extend release pipeline",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:43:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a8c28f98e8ce1d3913d1a3c865b00b9b7decb2f",
          "body": "Patch release picking up:\n  - gh#287 (PR #289): wire ClickUp assignees through POST/PUT /task — the\n    `update_issue` / `create_issue` paths in the ClickUp adapter were\n    accepting an `assignees` arg and silently dropping it before sending\n    to ClickUp.\n  - gh#288 (PR #290): support setting Cli\n[…]\nmps:\n  - [workspace.package].version: 0.29.0 → 0.29.1\n  - [workspace.dependencies] internal devboy-* crates: 0.29.0 → 0.29.1\n  - .claude-plugin/marketplace.json, plugins/{claude,codex}/.../plugin.json",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.29.1",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6db36ec7747a1f6c3a0a2d44965d1273c86d3107",
          "body": "feat(clickup): support setting custom statuses via update_issue (#288)",
          "is_bot": false,
          "headline": "Merge pull request #290 from meteora-pro/feat/288-clickup-custom-status",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aecd47a008a8afc95e097777d99f8a9b1b3cb1db",
          "body": "…t-pagination-schema\n\nfix(executor): restore get_meeting_transcript pagination/filter schema (#291)",
          "is_bot": false,
          "headline": "Merge pull request #292 from meteora-pro/fix/gh-291-restore-transcrip…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:10:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf86b2c4ebf363d599c65049d68bbfd8d3ce64a",
          "body": "…om-status\n\n# Conflicts:\n#\tcrates/plugins/api/clickup/src/client.rs",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into feat/288-clickup-cust…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:09:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abc8e4f61a9faeaef9c5c895d66364bcbd961589",
          "body": "fix(clickup): wire assignees through PUT/POST /task (#287)",
          "is_bot": false,
          "headline": "Merge pull request #289 from meteora-pro/fix/287-clickup-assignees-no-op",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f1ff8e26d14414ce6bb4a5f34c0d193de6ae9",
          "body": "… grouped]\n\nCopilot review feedback on PR #292: format was declared as free-form string\neven though dispatcher only accepts 'flat' / 'grouped'. Switch to\n`PropertySchema::string_enum` so MCP client-side validators reject invalid\nvalues up-front and the generated docs render the allowed set explicitly.",
          "is_bot": false,
          "headline": "fix(executor): constrain get_meeting_transcript.format to enum [flat,…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T09:01:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bad7e3c2809e61465f90270ec0a57ef5be08e68",
          "body": "…gh#291)",
          "is_bot": false,
          "headline": "docs(tools): regenerate after get_meeting_transcript schema restore (…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T08:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "918cf049e633410fdd29012a4de9563f90d43403",
          "body": "…a (gh#291)\n\nThe `get_meeting_transcript` tool definition currently advertises only\nthe `meeting_id` property to MCP clients, but the consumer backend\n(devboy-api-rs `TranscriptArgs`) parses 5 additional optional fields —\n`offset`, `limit`, `speaker_filter`, `search_text`, `format`. Without\nthese in\n[…]\nconsumer code change needed beyond bumping the dependency.\n\nTests:\n- New `test_get_meeting_transcript_exposes_pagination_and_filters`\n  regression guard\n- All existing tool-schema tests pass (241/241)",
          "is_bot": false,
          "headline": "fix(executor): restore get_meeting_transcript pagination/filter schem…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T08:50:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a14a77f50ecf16cf4612e38bbb88c6609236c16",
          "body": "CI failures on PR #290 v2 (commit eec44ac):\n\n- Docs job: docs/guide/reference/tools.md generator picks up the new\n  `status` field on update_issue + update_epic schemas. Regenerated\n  via `cargo run -p devboy-cli -- tools docs --output ...`. Also\n  trimmed the trailing period on the state field's de\n[…]\ndevboy-clickup unchanged (the new\n  validate_status_name and fetch_list_statuses helpers are private,\n  no public surface change).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: refresh tools.md + devboy-core baseline for status field (#288)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T07:51:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6d1218657804ed86b184b7faad3e0f68f46a778",
          "body": "…pTeams*\n\nBakes the four new pub structs introduced in this PR into the\ncargo-public-api baseline:\n\n- AssigneeDiff (PUT /task assignees envelope)\n- ClickUpTeamsResponse / ClickUpTeam / ClickUpTeamMember\n  (GET /team response shape used by resolve_assignee_ids)\n\nPlus the new `assignees: Option<Assign\n[…]\naskRequest.\n\nPattern matches existing types (CreateTaskRequest, ClickUpUser, …)\nwhich are all pub-exported via `pub use types::*`.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(clickup): refresh public-api baseline for AssigneeDiff + ClickU…",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T07:48:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eec44acd52d2cd69cb16a8088964da5775140948",
          "body": "Review feedback on #290:\n\n1. execute_update_epic was hardcoding UpdateIssueInput.status to None\n   while execute_update_issue threaded params.status. Epics are stored\n   as ClickUp tasks too, so the same custom-status workflow applies.\n   Added a status field to UpdateEpicParams, threaded it through\n[…]\n     11th status not leaked\n\nWorkspace clippy / fmt / test all green; 102 clickup tests (94 +\nexisting 5 status + 2 new + 1 epic).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): address PR #290 review (epic status + error hints + DRY)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T03:43:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f9cf49c0c9f39f4b02bd5cee45daacd502f46f",
          "body": "…287)\n\nAddress review feedback on PR #289:\n\n- resolve_assignee_ids: spell out the three resolution paths (numeric\n  ID pass-through with no verification, /team lookup with case-\n  insensitive email/username match, fail-loud on unresolvable). Notes\n  why numeric IDs skip the workspace fetch and the A\n[…]\nctical\n  impact is small because assignee changes are rare and idempotent.\n\nBehavior unchanged; 8 / 8 assignees tests still green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(clickup): clarify assignee resolution semantics + race window (#…",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T03:38:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d72b6c10ad704e351cffa1291d7ebe129f9b31e9",
          "body": "…rver instance",
          "is_bot": false,
          "headline": "test(telegram): refactor search_messages tests to use a single MockSe…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T22:06:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5128e3a2ea6bacaa0b2d42797c1073ddb28d60d",
          "body": "…update handling",
          "is_bot": false,
          "headline": "refactor(telegram): simplify filter logic and improve readability in …",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:48:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "521e6c733fc7dec35d51de2cb0250d62e50d1c97",
          "body": "…te handling",
          "is_bot": false,
          "headline": "feat(telegram): enhance TelegramClient with state management and upda…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:48:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9619675728b2c4ef0e5b9a5dce2a7074930966e7",
          "body": null,
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider tests and configuration handling",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:39:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a3dd40f02d875fdd72788bc1722519f9acf518",
          "body": "The unified update_issue MCP tool exposed only a generic\nstate: enum(\"open\", \"closed\") field. ClickUp custom statuses like\n\"in progress\", \"review\", or any list-defined status were unreachable\nthrough the MCP layer — callers had to open the ClickUp UI to move a\ntask forward in its workflow. This bloc\n[…]\n mapping are scoped to follow-up PRs.\n\nWorkspace clippy clean, fmt clean, 99 / 99 clickup tests + full\nworkspace test suite green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): support setting custom statuses via update_issue (#288)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-25T13:06:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c79180acf44c0f728a054aaa67c8170b6e43c731",
          "body": "ClickUp's PUT /task/:id silently ignored the assignees field because the\nunderlying UpdateTaskRequest struct didn't declare it. POST /task also\nhardcoded assignees: None. Result: any assignees passed via the unified\nupdate_issue / create_issue MCP tool were dropped on the floor with a\n200 OK — silen\n[…]\nomits the field\n   - unknown email fails before PUT\n   - POST sends flat array\n\n102/102 clickup tests green (94 existing + 8 new).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): wire assignees through PUT/POST /task (#287)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-25T12:57:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db74a11a70fef393feb0b64870c5d34da4bc803b",
          "body": null,
          "is_bot": false,
          "headline": "doc(telegram): update provider count and add Telegram to messenger tools",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T10:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec91ac083cd6ae70e5fc38c2c6bea96bb8239c0b",
          "body": "… tracing dependency",
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider configuration and remove unused…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T10:42:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62c884fb85d121096d5801dd6ecc9d5e93fa056f",
          "body": "…to feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T09:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48d2765527f615d8caa62bdbb1f7537f154dbc49",
          "body": null,
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider to workspace and CLI",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T09:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b51e6bffc1b535c8bddb9cb37aa423757c1e74eb",
          "body": "…dispatch\n\nfix(confluence): KB dispatch + self-hosted Server payloads + with_instance_url",
          "is_bot": false,
          "headline": "Merge pull request #286 from meteora-pro/fix/confluence-proxy-and-kb-…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:56:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cc414ba52affc46720583addaef35c52f38b81e",
          "body": "…pi baseline\n\nThree review comments and the public-api CI gate:\n\n1. **`send_json` body allocation** (review on `client.rs:297`). Switched\n   from `response.text()` + `serde_json::from_str` to `response.bytes()`\n   + `serde_json::from_slice`, so the happy path skips the extra UTF-8\n   validation pass\n[…]\nnst\na real self-hosted Confluence Server — 100 spaces, all URLs on the\nreal instance host (same as before, because `_links.base` echoes the\nreal host in non-proxy deployments).\n\nRefs: gh#285, PR #286.",
          "is_bot": false,
          "headline": "fix(confluence): address PR #286 Copilot review + regenerate public-a…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:44:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5cd315cb06cc1243709eb9a3d2da16480f4d37e3",
          "body": "Mirrors `JiraClient::with_instance_url`. Splits two roles previously\nserved by `base_url`:\n\n- **`base_url`** — API target. Stays the proxy host in proxy mode so\n  every request transits the proxy.\n- **`instance_url`** — host used to render browse links\n  (`_links.webui`, `/pages/<id>`). Stays the re\n[…]\nt_providers` reading\n`proxy_mcp_servers` to derive a Confluence HTTP proxy) is out of\nscope here — the schema has no Confluence HTTP-proxy section yet.\nTracked as a follow-up in gh#285.\n\nRefs: gh#285.",
          "is_bot": false,
          "headline": "feat(confluence): with_instance_url + browse-link host separation",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:24:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "872094eb3bac795d4bfa20426504300e14efc7c7",
          "body": "…teger ids\n\nThree coupled bugs that combined to surface as a misleading\n\"No knowledge base provider supports '<tool>'\" against self-hosted\nConfluence Server / Data Center:\n\n1. **dispatch_builtin_tool** (KB/messenger/meeting arms) used\n   `Err(e) => continue` unconditionally, swallowing real errors f\n[…]\ner id.\n- `send_json_decode_failure_surfaces_status_and_body_preview` — 200\n  OK + HTML body must produce a diagnostic error message.\n\nRefs: gh#285 (Confluence proxy / KB dispatch / self-hosted reads).",
          "is_bot": false,
          "headline": "fix(confluence,mcp): KB dispatch hides real errors + accept Server in…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:20:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d736f202873ee3ae30a8b5d20d04f9d7d731f7a",
          "body": "feat(secrets): implement secret framework — ADR-020/021/023 (epic #247, full history)",
          "is_bot": false,
          "headline": "Merge pull request #265 from meteora-pro/epic/247-secret-framework-impl",
          "author_name": "ai-dev-2-meteora-pro",
          "author_login": "ai-dev-2-meteora-pro",
          "committed_at": "2026-05-18T22:03:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4cad3a4e9ff45895569b13cc6b1e854e48a7be",
          "body": "CI's `Unused deps (cargo-machete)` flagged `tokio` in\ncrates/devboy-secrets-ui-bin/Cargo.toml — the only reference in\nthe bin's source is now a doc comment (\"…switch to\ntokio::spawn_blocking\" on the attachment-save path), not a real\nuse. The HTTP-Vault block_on() path that needed tokio was\nremoved i\n[…]\ned; the failure\nwas the Swatinem/rust-cache@v2 post-step uploading the cache.\nTransient infrastructural; the next push retries it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ci): drop unused tokio dep from devboy-secrets-ui-bin (DEV-247)",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-18T10:10:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f50096ab3c195ad54c93ea53e8fc123920ee2d7",
          "body": "Five reviewable items from the inline review on PR #265.\nAll have regression tests; only R5 doesn't add a test (the\nfix is a single RegexBuilder swap with no observable behaviour\ndifference on legitimate inputs).\n\nR1 MED — verify_fresh_unlock TOCTOU/stale-state\n  crates/devboy-secrets-agent/src/serv\n[…]\nev-dependency with the async_closure\n  feature.\n\nBuild green, fmt clean, clippy -D warnings clean, all 1800+\nworkspace tests pass.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secrets): address 5 PR-265 review findings (R1-R6) (DEV-247)",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-18T09:11:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3be04a43825be01b7245297e10af4506f22daf22",
          "body": "…DEV-247)\n\nCI's Windows test runner caught a Unix-only assumption in\n`derive_working_copy_path_drops_into_source_dir_with_timestamp`\n— the assertion did a string prefix match against\n`/tmp/x.devboy-working-`, which fails on Windows where the\n`PathBuf::with_file_name` call returns `/tmp\\x.devboy-work\n[…]\nand\n`p.file_name()` so the test passes regardless of how the OS\nchooses to spell the separator. Underlying behaviour is\nunchanged.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secrets-kdbx): cross-platform path test for working-copy helper (…",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-17T22:17:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22490feecd8f40fa320f321986515cee6d8d1fb4",
          "body": "…ne (DEV-247)\n\nPR #265 CI's `Public API drift (cargo-public-api)` flagged\ndevboy-gitlab: my earlier squash inadvertently dropped main's\n`AuthScheme` refactor (PAT vs OAuth header detection, #263).\n\nResolution:\n* Reset `crates/plugins/api/gitlab/src/client.rs` to the main\n  version (restores `AuthSch\n[…]\ntlab/.public-api/baseline.txt`\n— only legitimate addition is `pub mod devboy_gitlab::liveness`\n(the epic's liveness probe module).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): restore main's AuthScheme in gitlab, regen public-api baseli…",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-17T22:04:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 39,
      "commits_last_year": 1798,
      "latest_release_at": "2026-07-25T12:01:23Z",
      "latest_release_tag": "v0.32.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 22,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 9.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "devboy-cli",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "cli",
            "devboy",
            "developer-tools",
            "mcp",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-cli",
          "is_deprecated": false,
          "latest_version": "0.28.1",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 3,
          "total_downloads": 55,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 18,
          "first_published_at": "2026-05-09T23:14:17.755383Z",
          "latest_published_at": "2026-05-17T19:34:36.553031Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 68
        },
        {
          "name": "devboy-mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "claude",
            "devboy",
            "json-rpc",
            "mcp",
            "api-bindings",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-mcp",
          "is_deprecated": false,
          "latest_version": "0.28.1",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 3,
          "total_downloads": 95,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 32,
          "first_published_at": "2026-05-09T22:54:14.779703Z",
          "latest_published_at": "2026-05-17T19:33:31.467335Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 68
        },
        {
          "name": "devboy-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "devboy",
            "developer-tools",
            "mcp",
            "providers",
            "api-bindings",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-core",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 11,
          "total_downloads": 7064,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2355,
          "first_published_at": "2026-05-09T21:33:35.173319Z",
          "latest_published_at": "2026-07-25T09:41:09.017534Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "@devboy-tools/cli",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "devboy",
            "code-review",
            "ai-agent",
            "gitlab",
            "github",
            "clickup",
            "jira"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@devboy-tools/cli",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 39,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 435,
          "first_published_at": "2026-02-19T18:20:44.705000Z",
          "latest_published_at": "2026-07-25T12:02:20.476000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-assets",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "assets",
            "cache",
            "devboy",
            "filesystem",
            "development-tools",
            "caching",
            "filesystem"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-assets",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 9,
          "total_downloads": 6525,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2175,
          "first_published_at": "2026-05-09T21:34:25.421466Z",
          "latest_published_at": "2026-07-25T09:42:50.457971Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-skills",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "claude",
            "devboy",
            "manifest",
            "skills",
            "development-tools",
            "parser-implementations"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-skills",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 4,
          "total_downloads": 98,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 33,
          "first_published_at": "2026-05-09T23:04:11.524448Z",
          "latest_published_at": "2026-07-25T12:12:43.795419Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-storage",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "credentials",
            "devboy",
            "keychain",
            "secrets",
            "storage",
            "authentication",
            "development-tools",
            "os"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-storage",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 9,
          "total_downloads": 199,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 66,
          "first_published_at": "2026-05-09T21:33:57.151193Z",
          "latest_published_at": "2026-07-25T09:42:28.108262Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 4,
      "stars": 13,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-03-11",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 4,
        "total_forks": 4
      },
      "star_history": null,
      "open_issues_and_prs": 51
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "notebooks"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "docs/research/paper1-repro/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "docs/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/devboy-assets/Cargo.toml",
        "crates/devboy-cli/Cargo.toml",
        "crates/devboy-core/Cargo.toml",
        "crates/devboy-executor/Cargo.toml",
        "crates/devboy-mcp/Cargo.toml",
        "crates/devboy-secret-patterns/Cargo.toml",
        "crates/devboy-secrets-agent/Cargo.toml",
        "crates/devboy-secrets-ui-bin/Cargo.toml",
        "crates/devboy-secrets-ui/Cargo.toml",
        "crates/devboy-skills/Cargo.toml",
        "crates/devboy-storage/Cargo.toml",
        "crates/devboy-token-catalog/Cargo.toml",
        "crates/devboy-vault-crypto/Cargo.toml",
        "crates/llm-eval/Cargo.toml",
        "crates/plugins/api/clickup/Cargo.toml",
        "crates/plugins/api/confluence/Cargo.toml",
        "crates/plugins/api/fireflies/Cargo.toml",
        "crates/plugins/api/github/Cargo.toml",
        "crates/plugins/api/gitlab/Cargo.toml",
        "crates/plugins/api/jira/Cargo.toml",
        "crates/plugins/api/slack/Cargo.toml",
        "crates/plugins/api/telegram/Cargo.toml",
        "crates/plugins/format-pipeline/Cargo.toml",
        "crates/plugins/secrets/1password/Cargo.toml",
        "crates/plugins/secrets/env-store/Cargo.toml",
        "crates/plugins/secrets/kdbx/Cargo.toml",
        "crates/plugins/secrets/keychain/Cargo.toml",
        "crates/plugins/secrets/local-vault/Cargo.toml",
        "crates/plugins/secrets/vault/Cargo.toml"
      ],
      "largest_source_bytes": 381128,
      "source_files_sampled": 329,
      "oversized_source_files": 22,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "docs/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-executor",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-mcp",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-agent",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-ui",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-token-catalog",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ratatui",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.30"
        },
        {
          "name": "crossterm",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.28"
        },
        {
          "name": "devboy-secret-keychain",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-local-vault",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-1password",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-env-store",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-github",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-gitlab",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-clickup",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-jira",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-fireflies",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-slack",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-telegram",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-skills",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_yaml",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap-markdown",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dialoguer",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "flate2",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1"
        },
        {
          "name": "tar",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "zip",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.4"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry-tracing",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "url",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "which",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.0"
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-assets",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-gitlab",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-github",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-clickup",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-jira",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-fireflies",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-slack",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-telegram",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-assets",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-executor",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest-eventsource",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio-util",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-vault-crypto",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-ui",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-token-catalog",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-vault-crypto",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-vault",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "eframe",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34"
        },
        {
          "name": "egui_kittest",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34.2"
        },
        {
          "name": "image",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.25"
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rfd",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.15"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "ratatui",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.30"
        },
        {
          "name": "crossterm",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.28"
        },
        {
          "name": "egui",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34"
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_yaml",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "rust-embed",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.5"
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "ulid",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1"
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bitflags",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.6"
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hex",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "rust-embed",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8"
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "zeroize",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.8"
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chacha20poly1305",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "getrandom",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "argon2",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bip39",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hkdf",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 123,
        "open_issues": 45,
        "closed_ratio": 0.729,
        "closed_issues": 121,
        "closed_unmerged_prs": 15
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "slavik-kazarinov",
          "commits": 1081,
          "avatar_url": "https://avatars.githubusercontent.com/u/126971369?v=4"
        },
        {
          "type": "User",
          "login": "qumagis",
          "commits": 339,
          "avatar_url": "https://avatars.githubusercontent.com/u/126944225?v=4"
        },
        {
          "type": "User",
          "login": "andreymaznyak",
          "commits": 119,
          "avatar_url": "https://avatars.githubusercontent.com/u/4545924?v=4"
        },
        {
          "type": "User",
          "login": "mikhailova-klavdia",
          "commits": 98,
          "avatar_url": "https://avatars.githubusercontent.com/u/114179767?v=4"
        },
        {
          "type": "User",
          "login": "ai-dev-2-meteora-pro",
          "commits": 91,
          "avatar_url": "https://avatars.githubusercontent.com/u/207333965?v=4"
        },
        {
          "type": "User",
          "login": "mikhkit",
          "commits": 34,
          "avatar_url": "https://avatars.githubusercontent.com/u/12929152?v=4"
        },
        {
          "type": "User",
          "login": "mkitaev",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/26816897?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.605
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "deploy-docs.yml",
        "fixtures-update.yml",
        "release-crates-io.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/5 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "21 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
        "ran_at": "2026-07-25T13:14:27Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T12:14:05Z",
      "oldest_open_prs": [
        {
          "number": 249,
          "created_at": "2026-05-07T21:51:47Z",
          "last_comment_at": "2026-05-07T21:54:13Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 293,
          "created_at": "2026-05-28T16:13:15Z",
          "last_comment_at": "2026-05-28T16:22:23Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 296,
          "created_at": "2026-06-08T00:42:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 299,
          "created_at": "2026-06-21T23:45:57Z",
          "last_comment_at": "2026-06-30T23:15:08Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 304,
          "created_at": "2026-06-30T22:37:38Z",
          "last_comment_at": "2026-07-01T00:30:19Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 305,
          "created_at": "2026-07-09T00:28:52Z",
          "last_comment_at": "2026-07-09T00:33:59Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-25T12:02:48Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 64,
          "created_at": "2026-03-26T10:28:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 65,
          "created_at": "2026-03-26T10:29:59Z",
          "last_comment_at": "2026-05-02T21:17:00Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 68,
          "created_at": "2026-03-26T17:38:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 69,
          "created_at": "2026-03-26T17:39:00Z",
          "last_comment_at": "2026-05-02T21:17:42Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 73,
          "created_at": "2026-03-27T15:09:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 87,
          "created_at": "2026-03-28T20:09:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 88,
          "created_at": "2026-03-28T20:10:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 89,
          "created_at": "2026-03-28T20:10:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 90,
          "created_at": "2026-03-28T20:10:34Z",
          "last_comment_at": "2026-05-02T21:17:02Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 99,
          "created_at": "2026-03-30T08:41:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 100,
          "created_at": "2026-03-30T08:41:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 112,
          "created_at": "2026-04-03T08:44:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 120,
          "created_at": "2026-04-10T21:23:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 124,
          "created_at": "2026-04-10T21:24:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 125,
          "created_at": "2026-04-11T09:31:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 210,
          "created_at": "2026-04-26T21:59:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 211,
          "created_at": "2026-04-28T03:46:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 213,
          "created_at": "2026-04-30T06:17:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 240,
          "created_at": "2026-05-04T17:18:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 241,
          "created_at": "2026-05-04T17:19:23Z",
          "last_comment_at": "2026-06-21T06:09:52Z",
          "last_comment_author": "Necmttn"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/meteora-pro/devboy-tools",
    "host": "github.com",
    "name": "devboy-tools",
    "owner": "meteora-pro"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": "High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
      "notes": [
        {
          "code": "jurisdiction_overall_adjustment",
          "params": {
            "cap": 49,
            "pct": 50
          }
        }
      ],
      "value": 31,
      "inputs": {
        "security": 18,
        "vitality": 83,
        "community": 49,
        "governance": 60,
        "engineering": 86,
        "high_risk_jurisdiction_cap": 49,
        "high_risk_jurisdiction_multiplier": 50,
        "weighted_overall_before_jurisdiction": 62,
        "overall_after_jurisdiction_multiplier": 31
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "commits_last_year": 1798,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 22
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "22/52 weeks with commits",
                "points": 15.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1798 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1798
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 39,
              "latest_release_tag": "v0.32.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 9.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "39 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~9.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 9.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 49,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 4,
              "stars": 13,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "4 forks",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "devboy-cli",
                "devboy-mcp",
                "devboy-core",
                "@devboy-tools/cli",
                "devboy-assets",
                "devboy-skills",
                "devboy-storage"
              ],
              "dependents": null,
              "ecosystems": "crates, npm",
              "total_downloads": 14036,
              "monthly_downloads": 5114
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,114 downloads/month across crates, npm",
                "points": 49.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5114,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.605
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 60% of commits",
                "points": 8.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 60
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "merged_prs": 123,
              "open_issues": 45,
              "closed_issues": 121,
              "issue_closed_ratio": 0.729,
              "closed_unmerged_prs": 15
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "73% of issues closed",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 73
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "123/138 decided PRs merged",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 123,
                      "decided": 138
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "meteora-pro",
              "public_repos": 9,
              "account_age_days": 2118
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of meteora-pro",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "meteora-pro"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~5 yr old",
                "points": 18.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "devboy-cli",
                "devboy-mcp",
                "devboy-core",
                "@devboy-tools/cli",
                "devboy-assets",
                "devboy-skills",
                "devboy-storage"
              ],
              "ecosystems": "crates, npm",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "7 package(s) on crates, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 7,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "39 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 86,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://meteora-pro.github.io/devboy-tools/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://meteora-pro.github.io/devboy-tools/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 18,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "High-Risk Jurisdiction Policy applies a 50% multiplier to Security posture and gives it an At risk ceiling of 49.",
            "notes": [
              {
                "code": "jurisdiction_posture_adjustment",
                "params": {
                  "cap": 49,
                  "pct": 50
                }
              }
            ],
            "value": 18,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.5,
              "high_risk_jurisdiction_cap": 49,
              "high_risk_jurisdiction_multiplier": 50,
              "security_posture_after_multiplier": 18,
              "security_posture_before_jurisdiction": 35
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "21 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "moderate",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": true,
              "exposures": [
                {
                  "role": "top_contributor",
                  "count": 1,
                  "country": "Russia"
                }
              ],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "Russia: top_contributor (1)",
                "points": 50,
                "status": "partial",
                "details": [
                  {
                    "code": "jurisdiction_exposure",
                    "params": {
                      "role": "top_contributor",
                      "count": 1,
                      "country": "Russia"
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.96,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "docs/research/paper1-repro/Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "docs/tsconfig.json"
              ],
              "agent_commit_share": 0.61,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/devboy-assets/Cargo.toml",
                "crates/devboy-cli/Cargo.toml",
                "crates/devboy-core/Cargo.toml",
                "crates/devboy-executor/Cargo.toml",
                "crates/devboy-mcp/Cargo.toml",
                "crates/devboy-secret-patterns/Cargo.toml",
                "crates/devboy-secrets-agent/Cargo.toml",
                "crates/devboy-secrets-ui-bin/Cargo.toml",
                "crates/devboy-secrets-ui/Cargo.toml",
                "crates/devboy-skills/Cargo.toml",
                "crates/devboy-storage/Cargo.toml",
                "crates/devboy-token-catalog/Cargo.toml",
                "crates/devboy-vault-crypto/Cargo.toml",
                "crates/llm-eval/Cargo.toml",
                "crates/plugins/api/clickup/Cargo.toml",
                "crates/plugins/api/confluence/Cargo.toml",
                "crates/plugins/api/fireflies/Cargo.toml",
                "crates/plugins/api/github/Cargo.toml",
                "crates/plugins/api/gitlab/Cargo.toml",
                "crates/plugins/api/jira/Cargo.toml",
                "crates/plugins/api/slack/Cargo.toml",
                "crates/plugins/api/telegram/Cargo.toml",
                "crates/plugins/format-pipeline/Cargo.toml",
                "crates/plugins/secrets/1password/Cargo.toml",
                "crates/plugins/secrets/env-store/Cargo.toml",
                "crates/plugins/secrets/kdbx/Cargo.toml",
                "crates/plugins/secrets/keychain/Cargo.toml",
                "crates/plugins/secrets/local-vault/Cargo.toml",
                "crates/plugins/secrets/vault/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "docs/research/paper1-repro/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/research/paper1-repro/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "docs/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "61 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 61,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 381128,
              "source_files_sampled": 329,
              "oversized_source_files": 22
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "22/329 source files over 60KB",
                "points": 51.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 329,
                      "oversized": 22
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples",
                "notebooks"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, notebooks",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, notebooks"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'llm-eval' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T13:14:45.021201Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/meteora-pro/devboy-tools.svg",
  "full_name": "meteora-pro/devboy-tools",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаcrates.io, npm.