Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-28 01:27 UTC

mosaic-media / sdk

Official SDK for developing Mosaic modules — connect external services, sources, and integrations to the Mosaic platform.

GoApache-2.0★ 0 зірок⑂ 1 форкз лип. 2026 р.Переглянути на GitHub ↗

mosaic-media/sdk має індекс здоров’я 36 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — AI Readiness (82/100), найнижчий — Security (16/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

36
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

36
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

MosaicОрганізація
0 підписників16 публічних репозиторіївз лип. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/mosaic-media/sdkv0.26.0-260 днів тому
Gogithub.com/mosaic-media/sdk/hostv0.8.0-80 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

66Помірний · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
1.4/36Ритм комітів — 2/52 тижнів із комітами
14.8/18Обсяг комітів — 43 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year43
human_commit_share1
days_since_last_push0
active_weeks_last_year2
Як обчислюється оцінка
16.2/27Випускає релізи — 26 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 0 дн. тому
27/27Ритм релізів — реліз кожні ~0,4 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count26
latest_release_tagv0.26.0
releases_from_tagsтак
days_since_latest_release0
mean_days_between_releases0,4
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

24Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 1 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks1
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

33У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, Прийняття PR. Залишкові ваги перенормовано.

Власність та опіка

39У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
0/25Охоплення власника — 0 підписників у mosaic-media
9/25Послужний список — 16 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers0
owner_typeOrganization
is_verified
owner_loginmosaic-media
public_repos16
account_age_days15

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 2 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 0 дн. тому
20/20Історія версій — 26 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/mosaic-media/sdk, github.com/mosaic-media/sdk/host
ecosystemsgo
any_deprecatedні
min_days_since_publish0

Інженерна якість

Чи наявні базові інженерні практики та документація?

34У зоні ризику · 20% загального індексу

Інженерні практики

30У зоні ризику
Як обчислюється оцінка
0/24Процеси CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciні
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

40У зоні ризику
Як обчислюється оцінка
30/30README
0/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
0/10Wiki
Використані вхідні дані
topics
has_wikiні
homepage
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

16Критичний · 16% загального індексу

Стан безпеки

16Критичний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — немає даних
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
0/5Pinned-Dependencies — немає даних
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — немає даних
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate1,6
Виключено з оцінювання (немає даних або не застосовно): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

82Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — CLAUDE.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 42 з 43 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,977
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes8 064
Як обчислюється оцінка
12.6/18Розгортання однією командою — go.mod, host/go.mod (домовленість інструментарію, без раннера задач)
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — Go (статично типізована)
10/10Відтворюване середовище — lockfile
10/10Підтверджена практика роботи з агентами — 41 з останніх 43 комітів створено агентом або з його зазначенням
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — немає даних
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configs
agent_commit_share0,953
toolchain_manifestsgo.mod, host/go.mod
dependency_bot_commit_share0
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Pinned-Dependencies. Залишкові ваги перенормовано.
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
55/55Керовані розміри файлів — 0/40 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes37 440
source_files_sampled40
oversized_source_files0

Ключові факти

0зірок GitHub
1контриб'юторів
43комітів за останні 12 місяців
0днів від останнього пушу
26релізів
1бас-фактор
0відкритих issue
Goпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 1.6 / 10
1.6сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-28 01:27 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
н/дDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackagingpackaging workflow not detected
н/дPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
н/дToken-PermissionsNo tokens found
1Vulnerabilities9 existing vulnerabilities detected
Прямі залежності 4
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/hashicorp/go-pluginv1.8.0host/go.mod
Gogithub.com/mosaic-media/contractsv0.60.0host/go.mod
Gogithub.com/mosaic-media/sdkv0.26.0host/go.mod
Gogoogle.golang.org/grpcv1.82.1host/go.mod
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 226,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 275676
      },
      "pushed_at": "2026-07-27T16:21:43Z",
      "created_at": "2026-07-19T21:23:24Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T16:23:40Z",
      "description": "Official SDK for developing Mosaic modules — connect external services, sources, and integrations to the Mosaic platform.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Mosaic",
      "type": "Organization",
      "login": "mosaic-media",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/304150337?v=4",
      "created_at": "2026-07-12T20:17:48Z",
      "is_verified": null,
      "public_repos": 16,
      "account_age_days": 15
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-07-27T16:15:37Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-07-27T02:44:42Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-07-25T14:44:38Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-25T04:19:57Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-24T22:56:16Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-24T01:03:15Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-23T22:14:33Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-23T21:36:17Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-23T21:20:49Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-23T20:58:00Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-23T20:39:11Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-23T19:49:50Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-23T15:43:39Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-22T19:53:33Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-22T15:50:49Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-22T14:43:16Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-22T13:39:39Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-22T09:34:40Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-21T14:52:32Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-21T01:10:42Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-21T00:21:00Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-20T22:54:28Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-20T18:07:58Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-20T01:36:22Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T00:21:32Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-19T21:23:43Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "b40995e9d81c12857b5dd222501571e537f65f40",
          "body": "StreamLink.Container/VideoCodec/AudioCodec and SubtitlesRequest.Season/Episode\ncompiled perfectly against a module.proto with no fields to hold them, which is\nthe third time that has happened here. contracts v0.60.0 carries the wire\nfields; this maps them, in both converters and on both requests.\n\nT\n[…]\n the client means the handler never runs. Found by\n-count=15 -race, which was red on TestLaterSDKFieldsCrossTheBoundary as well\nand is now clean.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Map the five v0.26.0 fields in each direction",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-27T16:21:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d3cab5f06032d6e0a1f4756183ef4ccacb3504af",
          "body": "…isode\n\nTwo gaps in the source roles, batched into one release because they cost the\nsame round of module bumps either way.\n\nStreamLink gains Container, VideoCodec and AudioCodec. A module parses all\nthree at its own boundary (ADR 0051) and had nowhere to put them, so the parse\nwas narrowed to Quali\n[…]\nh\nmodules filling the role called their own addressing helper with two zeroes.\n\nAdditive, and every zero value is the previous behaviour exactly.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "A candidate can say what it is, and a subtitle request can name an ep…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-27T16:15:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa9fba4f2695126083663c0e210106a9e0987224",
          "body": "`contracts v0.57.0` carries the wire fields `sdk v0.25.0` needs; this is\nthe mapping. `Catalog.Filters`, `CatalogItemsRequest.Filters`,\n`Node.Genres`, `AddContentWorkCommand.Genres` and\n`SearchContentQuery.Genres`, both ways.\n\n`CatalogItemsRequest.Filters` is the first field on that request a\n*calle\n[…]\newer titles than the library holds. The stub echoes Genres back on\nthe committed node so a converter that dropped one direction only cannot\npass.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Map the five new fields in each direction",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-27T02:48:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0424109e3f1b36080eaef83e60c478cfa4bcb00",
          "body": "The two halves of M2's faceting slice. They are independent surfaces that\nshare a release because they are one user-visible feature.\n\nProvider side: `CatalogItemsRequest` carried only `Skip`, so browsing a\nsource by genre was not expressible at all. `Catalog.Filters` declares the\nnarrowings a catalo\n[…]\nes sit on a Work and are empty beneath it, which is the one place this\ndiffers from artwork — an episode has its own still and not its own genre.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "A catalog can be narrowed, and a node carries its genres",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-27T02:44:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d41bce936dafa96b4a1613b331752b6b928b123",
          "body": "Three editor and OS artefacts were ignored in some repositories and not others,\nfor no reason beyond which one was set up when. Levelled up so the same three\nlines are in all twelve. Nothing was tracked, so this only stops them appearing\nin working trees.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Ignore .vscode/ and .DS_Store, matching the other repositories",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-26T19:21:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d72f66710aaba5cae8929673ff45c97ca0967df",
          "body": "JetBrains project files had been committed by accident — the .iml, modules.xml,\nvcs.xml and the IDE's own .idea/.gitignore. They are per-machine editor state\nrather than anything the repository needs, and the ignore rule alone would have\nchanged nothing, because an ignore does not apply to a file already tracked. So\nthey are untracked here as well, and left on disk.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Ignore .idea/, and stop tracking the IDE scaffolding already committed",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-26T19:18:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "05a339e97307b5b745769386f646813d642bb0f3",
          "body": "The SDK grew three fields the module wire had nothing to hold: Crew and\nRuntimeMinutes in v0.24.0, HasMore in v0.23.0. The converters here compiled\nagainst a module.proto with no matching fields and dropped all three, so an\nout-of-process module could populate them and the Platform received a zero.\n\n[…]\nsert on the far side of a real gRPC round trip rather than on the\nconverters, because arriving is the property that was missing. Both fail\nagainst the previous converters, checked one field at a time.",
          "is_bot": false,
          "headline": "Carry the crew, episode runtime and has-more across the boundary",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-26T15:34:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69f7265a19d25ee099e8d8fae05a5e64284d51c8",
          "body": "host required contracts v0.16.0 and sdk v0.22.0 while the Platform shipped\nv0.53.0 and v0.24.0. Nothing failed, because minimal version selection raises\nboth in any build that also includes the Platform — so this repository's gate\nwas compiling a harness nobody runs, and reporting green about it.\n\nNo source file changed. The wire package host imports, gen/mosaic/module/v1,\nis byte-identical from contracts v0.16.0 to v0.53.0, and the two sdk minors\nwere additive.",
          "is_bot": false,
          "headline": "Compile the harness against the contracts and SDK that ship",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-26T14:44:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7546432438e48417bf6cc96f6b590484bff45617",
          "body": "…ing kept\n\nTwo fields a detail screen needs and no provider had anywhere to put.\n\nContentMetadata.Crew is the handful of above-the-line credits a title is known\nby — creators and directors, with the job in Person.Role. Separate from Cast\nrather than merged into it because the two are shown different\n[…]\ne. TMDB returns credits.crew and created_by on\nevery detail read and a runtime on every episode of every season; the module\ndecoded none of them.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Carry the crew and a per-episode runtime, which sources send and noth…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-25T14:44:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e39fc212f6446178a65bedd3a327b60ecb04e60",
          "body": "CatalogItemsRequest has always had a Skip, so the Platform could ask for a later\npage and never knew whether one existed. It rendered the first page of every\ncatalog and stopped, because the only alternative was inferring more-availability\nfrom a full page — which is wrong exactly at the boundary, t\n[…]\n rewriting\nto keep working.\n\nThis discharges the debt ADR 0093 recorded: the catalog screen could not page\nbecause the SDK gave it no way to ask.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Let a catalog provider say whether there is another page",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-25T04:19:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30f21e66803920e07a366a7191d57eeac8cc03e6",
          "body": "contracts v0.16.0 for Manifest.description on the wire, sdk v0.22.0 for\nthe field on the SDK manifest the harness converts to and from.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump host to the published contracts and sdk",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T23:07:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc53389558e17b3fd7bd4c16722ae68581aac224",
          "body": "Both directions of the manifest conversion, and the --mosaic-manifest\ndocument a release publishes — which is what the registry catalogues and\nsigns, so the sentence a user reads before installing is the one the\nmodule's author shipped with the binary.\n\nRequires contracts >= 0.16.0 for the wire field; the go.mod bump lands\nwith that release.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Carry the description across the module boundary",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T22:56:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8d3ea558fb0f66ec28c2dbc5f98c2996af0eebf9",
          "body": "A module declares what it fills, and the Platform can read that off the\nmanifest and say what the module can DO. Nothing anywhere let it say what\nit IS — so an extension card offering to install somebody's binary could\nname it and list its roles, and not tell a user what the thing is for.\n\nDescripti\n[…]\nprose about other\npeople's modules kept centrally goes stale the day a third party\npublishes one, and it would not be signed by whoever wrote it.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Let a module describe itself in its manifest",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T22:56:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de8aece1c5aa3dc38a1e84d4f5b97be05ecac438",
          "body": "Run a module binary with --mosaic-manifest and it prints its Manifest()\n— id, version, name, roles — as JSON and exits instead of serving. A\nmodule's release uses this to learn its own identity for the\ndistribution manifest, so the identity has one source of truth (the Go\nManifest method) rather tha\n[…]\ning a real module\nbinary and running it with the flag — the os.Args parse and the os.Exit\nare the point, and a direct function call would reach neither.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "host/v0.3.0: a module can print its own manifest (ADR 0065)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T13:59:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6436234216647a44f69a9ef24feb707a2539896b",
          "body": "host.Serve now routes the process's default HTTP transport through the\nforward proxy named in MOSAIC_EGRESS_PROXY, so an out-of-process module's\noutbound calls carry the same deny list the in-process client had.\n\nThis is the \"pre-wired\" the record means, and it exists because\nHTTP_PROXY alone is not\n[…]\nstom transport with an\nexplicit nil Proxy can still bypass it; that residual gap is layer 3's\n(ADR 0064), and the code says so rather than overclaiming.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "host/v0.2.0: pre-wire module egress to the Platform's proxy (ADR 0064)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T11:34:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1de3c63624046b60e9dd85971841d44b619046ae",
          "body": "A nested Go module carrying the go-plugin harness for both sides of the\nextension boundary. A module's main.go becomes\n\n    func main() { host.Serve(mymodule.New()) }\n\nand nothing else it wrote changes — the property ADR 0064 is arranged\naround, and what makes moving a module between tiers a build c\n[…]\nst separately — `./...` does not descend\ninto a nested module, so a gate that ran only at the root would report\ngreen having never compiled the harness.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "sdk/host: run a module as its own process (ADR 0064, ADR 0077)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T03:06:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d2404d271f78df88803c274a4acd7175a8618361",
          "body": "github.com/mosaic-media/sdui is now github.com/mosaic-media/contracts.\nDocumentation only — the SDK takes no dependency on it, and this README\nis where the two published contract repositories are contrasted.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Point at the renamed contracts repository (ADR 0044)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T02:36:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cd4a74ac08a390816d0a00a77710c5bc2b26d7d2",
          "body": "ADR 0074 grows v1.Artwork with a Candidates set (ArtworkCandidate, ArtworkSlot)\nalongside the existing flat slots, whose meaning narrows from \"the artwork\" to\n\"the artwork that was selected\" -- additive and backward compatible with every\nrow already written, as migration 0019 anticipated.\n\nADR 0075 \n[…]\npdates an\nexisting node rather than creating one, closing the gap ADR 0071 recorded as\nowed (\"no command that updates a stored work's fields\").\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.21.0: Artwork becomes a candidate set; RoleArtwork; SetContentArtwork",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-24T01:03:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45e25023f173038364a49975aa7fe2a8560c7e28",
          "body": "Season and Episode, so a stream provider can be asked about content it did\nnot source.\n\nThe Ref in that case carries a shared external identity (imdb, tvdb) rather\nthan the provider's own id, and the provider composes its native addressing\nfrom the identity plus these two numbers. That is the whole \n[…]\nover\ncontent that was never this provider's to know.\n\nA provider handed its own native id ignores the new fields and behaves\nexactly as before.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.20.0: StreamRequest gains neutral episode coordinates (ADR 0073)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T22:14:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "60847588cde12ca804a5d3e39aa3c43ff1e6891e",
          "body": "A containment filter over a node's module-owned Attributes document, so a\ncapability can ask which of its works some module tagged a given way.\n\nContainment rather than a typed filter, and that is the whole design. A\nnode's attributes are opaque to the Platform by construction — ADR 0013\nassigns the\n[…]\nalidArgument rather than an empty result: a filter that\nsilently matched nothing would read as 'you own none of these' instead of as\na mistake.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.19.0: SearchContentQuery.AttributesContain",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T21:36:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1074995d4546fe8b05bda5d0d1b388ab964b76d3",
          "body": "… Mosaic\n\nWatchAvailability, WatchOffer and WatchOfferType.\n\nThis is the first read field that does not describe the title itself, and\nthe doc comments lean on one distinction because it is the easy thing to get\nwrong: an offer is not a source. Every other read role answers 'what can\nMosaic get you'\n[…]\ny require being\ncredited wherever it is shown — carrying it in the contract keeps the\nPlatform from having to know which upstream imposed that.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.18.0: ContentMetadata.Watch — where a title can be watched outside…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T21:20:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ba40eeac053ec6dd670f0e16d9be50fe7d91e5a",
          "body": "… title\n\nKeywords, Certification, Similar, Collection and Trailers, with RelatedItem,\nCollection and Trailer as new types.\n\nThree close gaps ADR 0034 recorded rather than invented — a franchise ('the\nother Avatar films'), related titles, and the finer-grained tags that make\n'more like this' mean any\n[…]\nhe client, not\nto the contract.\n\nCertification is display-only text for the same reason Runtime is: age\nscales are national and not comparable.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.17.0: ContentMetadata grows for a source that models more than one…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T20:58:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "502caad3bf3856e0c28d726a7591a9d2b308dd74",
          "body": "Wide 16:9 key art, distinct from Backdrop: a backdrop is scenery to sit *behind*\na hero, this is a composed card image to sit *in* one, which is what a resume\nrail wants.\n\nAdded because a real source supplies it and it was being dropped — Cinemeta has\nno such field, but an addon proxying an artwork database returns a\nlandscapePoster alongside the poster. Empty rather than substituted when a source\nhas none.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.16.0: Artwork.Landscape",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T20:39:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b045c47aa8f63b95dd72fa9663f262c022530278",
          "body": "Adds Artwork{Poster, Backdrop, Logo} on Node and on AddContentWorkCommand /\nAddContentChildCommand. The descriptive surface is otherwise re-derived live\nfrom the provider (ADR 0034); artwork alone is written at materialisation and\nread back, because it is rendered in bulk on list surfaces like the\ncontinue-watching rail — one node read instead of a metadata round-trip per\ncard — and is the one image a user may later want to override.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.15.0: store artwork on the node (ADR 0071)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T19:49:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "01f704ba6f42e90a6675d912e7549ec5d93649e8",
          "body": "Adds docker-compose.test.yml (golang:1.25, pinned to go.mod) running\ngofmt, build, vet and test. CLAUDE.md and README gain a \"nothing runs on\nthe host\" section.\n\nThe reason is weakest here of all the repositories and still worth\nkeeping: this module has no hidden dependency and `go build ./...` real\n[…]\nitory is a rule nobody applies\nreliably in the other six.\n\nVerified: `docker compose -f docker-compose.test.yml run --rm test`\npasses (exit 0).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Run gates in a container, not on the host",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T17:41:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "643f40fcfb52e51980e221fad8bce9c874e19d24",
          "body": "Resolving bytes made the library playable. It did not make it usable, and the\nwhole difference is position state — a media server without resume is a file\nbrowser with posters.\n\nFive methods and the types behind them. Three decisions in the shape are worth\nstating, because each rules out something t\n[…]\ns additive to `ContentService`, which is a breaking change for anything\nimplementing that interface — the Platform, and any module's test fake.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Playback state: the first per-user surface (ADR 0046)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-23T15:43:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fdc93b8971934759066bdc20ed8988e8574d67b9",
          "body": "Mosaic has two published contract repositories built in opposite ways: this\none is hand-written Go, and sdui is protobuf with Go and TypeScript generated\nfrom proto/. Nothing said so, and the question came up as a real one — worth\nfour commands to answer from evidence, which is three too many.\n\nADR \n[…]\nand the standing prohibition on a replace directive\nreaching a commit. Records v0.13.0 in the README's Status changelog, which the\ntagged commit missed.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Say plainly that this SDK is hand-written Go, not generated",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T19:57:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a721fc420197bb460372eaf6700794b90dcb33ab",
          "body": "A module is an anti-corruption layer against a system it does not control,\nwhich makes it the code most likely to meet a shape nobody predicted — and it\nhas had exactly two ways to say anything: return an error, or print.\n\nmodule-stremio-addons does the latter, from another repository into the\nPlatf\n[…]\nchoose.\n\nMetrics are absent on purpose. The Platform has none yet, and publishing a\ncounter that silently does nothing is worse than not publishing one.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Modules observe through the SDK (ADR 0059)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T19:53:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cd2f1acac22218037fc174afd4226890476c1431",
          "body": "…mbered\n\nEvery module carries a hand-maintained version constant for its Manifest, and\nboth modules that had one had drifted from their git tag: the Stremio module\nreported 0.7.0 across two releases, and the playback module 0.0.1 against a\nv0.1.0 tag. A number a human must remember to change is a nu\n[…]\nd. A local build answering with a\nplausible number is how this drift starts again, so a test asserts it cannot be\nmistaken for one at a glance.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ModuleVersion: report what was actually linked, not what someone reme…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T15:50:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e019bd001298914fb676df024074bf382bc14823",
          "body": "The cast surface could name a person and not show them. A source proxying a real\nmetadata database returns a headshot and a character name per cast member; the\ncontract had a field for neither the image nor, in practice, anything a renderer\ncould draw. The SDUI PersonChip has bound an avatar with an\n[…]\n and the zero value stays correct: a source with only names leaves it\nempty and a consumer falls back to initials, which is what happens today.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Person carries a photo",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T14:43:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7cb2f4883f400f66f0e5b13c875bc2d7d992a26",
          "body": "The surface could write a Part and never read one back. That hole has been open\nsince the content model landed -- a capability could not see what it had itself\ncreated -- and ADR 0045 named it while building the first consumer without\nneeding it, because the Platform passes the Part into a playback \n[…]\nreads relations --\nListFrom/ListTo remains open, and it should arrive with the feature that forces\nit rather than by guessing at the shape now.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ListContentParts: the read side of AttachContentPart",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T13:39:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "874019f1f73e887f1346f11404bd5f927d87f12b",
          "body": "Every role in provider.go is a source role -- it brings content in and\npopulates the virtual plane. RolePlayback is the first that does not: it acts\non what materialising created, resolving a Part to playable bytes. ADR 0036\nnamed the consumer concept and left it without an interface; this fills it.\n[…]\n passes it in, so a provider needs no graph read);\nthe client capability profile and candidate selection (ADR 0048); playback\nstate (ADR 0046).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Playback consumer role: the first sink-side entry (ADR 0045)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-22T09:34:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aade76e976d0188331e677d6f78fd97c865e5e80",
          "body": "Repos dropped the redundant mosaic- prefix on 2026-07-21 (ADR 0043):\narchitecture, platform, sdk, sdui, module-stremio-addons. Update repo names,\nGo module paths, sibling folder paths, and GitHub/Pages URLs in the living\ndocs. The three web repos (mosaic-shell, mosaic-sdui-react, mosaic-storybook)\nand the cmd/mosaic-platform code path are unchanged. Version numbers not\ntouched here.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: update repo references after mosaic- prefix drop (ADR 0043)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-21T16:18:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dba39382833495bfac4148364509eca683570030",
          "body": "Repo renamed mosaic-sdk -> sdk under the mosaic-media org. Update the\nmodule path and all internal import paths to match.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: rename module path github.com/mosaic-media/mosaic-sdk -> .../sdk",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-21T14:52:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1b2c0791f7da4de6ff1b2a258297bf7ab7ef0b7d",
          "body": "…R 0038)\n\nAdd RoleSettingsUI and the SettingsUIProvider interface, returning the settings\nscreen as serialised UINode JSON (SettingsUIResponse.UI []byte). The SDK stays\nSDUI-agnostic — the bytes are opaque here; the module builds them with the\nshared mosaic-sdui producer binding and the Platform validates and hosts them.\nAdditive; v0.7.0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "SettingsUIProvider role: modules contribute their own settings UI (AD…",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-21T01:10:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "00ecda7206cbc9f17324f85f2bb84ad8a6eecbb2",
          "body": "Add RoleSubtitles, the SubtitlesProvider interface and a Subtitle DTO — a source\nrole built ahead of its consumer (a player), since subtitles are inherently the\nsource module's job. Grow StreamLink with Title/Quality/SizeBytes/Seeders so a\nfuture source-picker can rank and display candidates. Additive; v0.6.0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Subtitles provider role + richer StreamLink (ADR 0037)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-21T00:21:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8cb57bcf11bc148c734769a3592305faf1dbe04d",
          "body": "Add Logo, Cast []Person, Rating, Runtime, and Episodes []EpisodePreview to\nContentMetadata, plus the Person and EpisodePreview types. The DTO stays a\nread-only projection a MetadataProvider returns — never a node, never written —\nbut is no longer artificially flat: it now backs a real detail screen.\n[…]\nad projection the UI groups by season), not\nthe materialised tree, which Import still builds from the source's structure.\nAdditive; SDK v0.5.0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Grow ContentMetadata into the rich detail surface (ADR 0034)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T22:54:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c7d9d42a5378680eb3244d89e616482769eb5a2",
          "body": "Turns the module contract from a single write verb into declared provider\nroles (ADR 0027), and introduces the virtual content plane (ADR 0028).\n\n- provider.go: Role vocabulary (metadata/search/catalog/stream) and the\n  four provider interfaces a module implements only if it fills the role;\n  the vi\n[…]\nerfaces the Platform discovers by type assertion. Tests\nprove all four roles are implementable from outside the package with no\nPlatform types.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.4.0: provider roles, virtual content types, narrowed import",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T18:07:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa56caa9e2a155e9293f24c6b36530f32f3aa7e9",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "README: SDK is published (v0.3.0)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T01:36:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e03bbd5deee952dad560a0bfbfd052678b18b7a4",
          "body": "The SDK is the contract a Module builds against, so it is deliberately\npermissive and independent of the Platform's license — a Module author can\ndepend on it under any license. Apache-2.0 over MIT for the explicit patent\ngrant, appropriate for a contract surface.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "License the SDK under Apache-2.0",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T01:27:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "09e8526d6eea97fed41aae3e7dcc25e78b3e7429",
          "body": "Building the Stremio module surfaced the first SDK gap: a module needs a\nuser's runtime configuration (the addon manifest URLs to source from),\nnot values baked in at composition. Import's parameter list becomes an\nImportRequest{Caller, Query, Settings} struct so the Platform can hand a\nmodule its s\n[…]\nthe module system matures — the next gap\n(module-declared jobs) will add to it, and a struct absorbs that without\nbreaking the interface again.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Hand a module its user-managed settings (SDK v0.3.0)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T00:58:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fad5b63b936f0678adbd9066daa5f9ceb5d39bc0",
          "body": "ADR 0008 always reserved a capability and registration surface for the\nSDK; ADR 0016 populated only the content services. This adds the\ncapability side: a Capability interface a Module implements\n(Manifest() plus Import(ctx, ContentService, Caller, query)), a minimal\nManifest (id, version, name), an\n[…]\nds the Capability and\nroutes to it. A stub-capability test proves the interface is satisfiable\nfrom outside the package with no Platform types.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the capability surface to the published SDK (v0.2.0)",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-20T00:21:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c8084d32f5731a6b867a68cdbda7f133a814ea7b",
          "body": "The published contract surface, lifted out of mosaic-platform into its own\nmodule (github.com/mosaic-media/mosaic-sdk) so a Module depends on it exactly\nas a third party would (ADR 0008). It carries the content models, the content\ncommand/query/result types, the ContentService interface and the opaq\n[…]\nion dry-run: the Platform consumes it through a replace\ndirective against this working tree. Publishing a tagged version is the\nremaining step.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Extract the Mosaic SDK content surface from the Platform",
          "author_name": "AdamNi-7080",
          "author_login": "Pickles2235",
          "committed_at": "2026-07-19T21:23:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 26,
      "commits_last_year": 43,
      "latest_release_at": "2026-07-27T16:15:37Z",
      "latest_release_tag": "v0.26.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 2,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/mosaic-media/sdk",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/mosaic-media/sdk",
          "is_deprecated": false,
          "latest_version": "v0.26.0",
          "repository_url": "https://github.com/mosaic-media/sdk",
          "versions_count": 26,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T16:15:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "github.com/mosaic-media/sdk/host",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/mosaic-media/sdk/host",
          "is_deprecated": false,
          "latest_version": "v0.8.0",
          "repository_url": "https://github.com/mosaic-media/sdk",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T16:21:40Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "host/go.mod"
      ],
      "largest_source_bytes": 37440,
      "source_files_sampled": 40,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 8064
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "host/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/hashicorp/go-plugin",
          "manifest": "host/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.0"
        },
        {
          "name": "github.com/mosaic-media/contracts",
          "manifest": "host/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.60.0"
        },
        {
          "name": "github.com/mosaic-media/sdk",
          "manifest": "host/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.26.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "host/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.82.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Pickles2235",
          "commits": 43,
          "avatar_url": "https://avatars.githubusercontent.com/u/32930825?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "b40995e9d81c12857b5dd222501571e537f65f40",
        "ran_at": "2026-07-28T01:27:35Z",
        "aggregate_score": 1.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T16:21:43Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/mosaic-media/sdk",
    "host": "github.com",
    "name": "sdk",
    "owner": "mosaic-media"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 36,
      "inputs": {
        "security": 16,
        "vitality": 66,
        "community": 24,
        "governance": 33,
        "engineering": 34
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 66,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "commits_last_year": 43,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 2
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "2/52 weeks with commits",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "43 commits in the last year",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 43
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.26.0",
              "releases_from_tags": true,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 33,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "mosaic-media",
              "public_repos": 16,
              "account_age_days": 15
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of mosaic-media",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "mosaic-media"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "16 public repos, account ~0 yr old",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 16
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/mosaic-media/sdk",
                "github.com/mosaic-media/sdk/host"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "26 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 34,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 16,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 16,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 1.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 82,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.977,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 8064
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "42 of 43 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 42,
                      "sampled": 43
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 73,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.953,
              "toolchain_manifests": [
                "go.mod",
                "host/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod, host/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod, host/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "41 of the last 43 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 41,
                      "sampled": 43
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 37440,
              "source_files_sampled": 40,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/40 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 40,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T01:27:39.982528Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/mosaic-media/sdk.svg",
  "full_name": "mosaic-media/sdk",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.