Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-24 02:33 UTC

pivoshenko / kasetto

📼 A declarative AI agent environment manager, written in Rust

Rust · MDXВласна ліцензія★ 117 зірок⑂ 7 форківз бер. 2026 р.Переглянути на GitHub ↗

pivoshenko/kasetto має індекс здоров’я 62 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (82/100), найнижчий — Security (49/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

62
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

62
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Volodymyr PivoshenkoОсобистий обліковий запис
49 підписників25 публічних репозиторіївз черв. 2018 р.Bally's Interactive

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
crates.iokasetto3.6.0128296 днів томуcursorclaude-codecodexskillsmcps

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

82Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
11.8/36Ритм комітів — 17/52 тижнів із комітами
18/18Обсяг комітів — 409 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year409
human_commit_share0,93
days_since_last_push5
active_weeks_last_year17
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 30 релізів
36/36Свіжість релізів — останній реліз 6 дн. тому
27/27Ритм релізів — реліз кожні ~6,6 дн.
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Використані вхідні дані
releases_count30
latest_release_tagv3.6.0
releases_from_tagsні
days_since_latest_release6
mean_days_between_releases6,6

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

55Помірний · 18% загального індексу
Як обчислюється оцінка
33.5/60Зірки — 117 зірок
6.5/25Форки — 7 форків
0/15Спостерігачі — 2 спостерігачів
Використані вхідні дані
forks7
stars117
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
16.9/22.5Ліцензія — файл ліцензії наявний, не є визнаною ліцензією
18/18Настанови CONTRIBUTING
13.5/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductтак
has_pull_request_templateтак
Як обчислюється оцінка
28.1/80Щомісячні завантаження — 128 завантажень/місяць у crates
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packageskasetto
dependents
ecosystemscrates
total_downloads485
monthly_downloads128
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

55Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0.6/22.5Розподіл комітів — головний контриб’ютор — автор 97% комітів
2.7/13.5Широта контриб’юторів — 2 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled2
top_contributor_share0,973
Як обчислюється оцінка
38.9/46.8Вирішення issue — закрито 83% issue
25.2/38.3Прийняття PR — злито 25/38 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/13 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs25
open_issues2
closed_issues10
issue_closed_ratio0,833
closed_unmerged_prs13
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
12.2/25Охоплення власника — 49 підписників у pivoshenko
22.3/25Послужний список — 25 публічних репозиторіїв, вік облікового запису ~8 р.
Використані вхідні дані
followers49
owner_typeUser
is_verified
owner_loginpivoshenko
public_repos25
account_age_days2 953
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у crates
35/35Свіжість публікацій — остання публікація 6 дн. тому
20/20Історія версій — 29 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packageskasetto
ecosystemscrates
any_deprecatedні
min_days_since_publish6

Інженерна якість

Чи наявні базові інженерні практики та документація?

66Помірний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 4 процес(ів) CI
0/24Наявні тести
16/16Конфігурація лінтера — biome.json
0/9.6Pre-commit-хуки
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsні
has_editorconfigтак
has_linter_configтак
has_precommit_configні

Документація

65Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
15/15Сайт документації / домашня сторінка — https://www.kasetto.dev
10/10Опис репозиторію
10/10Теми — 20 тем
0/10Wiki
Використані вхідні дані
topicsai, skills, claude-code, copilot, cursor, mcp, codex, openclaw, opencode, mcps, ai-agent, ai-skills-manager, antigravity, claude, claude-skills, developer-tool, gemini, kiro, pi, ai-commands
has_wikiні
homepagehttps://www.kasetto.dev
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

49У зоні ризику · 16% загального індексу

Стан безпеки

49У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/13 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate4,9

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

71Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — CLAUDE.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 93 з 93 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes23 446
Як обчислюється оцінка
18/18Розгортання однією командою — justfile
0/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — biome.json
11/11Статична перевірка типів — site/tsconfig.json
10/10Відтворюване середовище — lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsні
lockfilesCargo.lock, pnpm-lock.yaml
has_dockerfileні
typed_languageтак
bootstrap_filesjustfile
has_devcontainerні
has_linter_configтак
typecheck_configssite/tsconfig.json
agent_commit_share0
toolchain_manifestsCargo.toml
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Rust (статично типізована)
55/55Керовані розміри файлів — 0/85 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageRust
largest_source_bytes41 394
source_files_sampled85
oversized_source_files0

Ключові факти

117зірок GitHub
2контриб'юторів
409комітів за останні 12 місяців
5днів від останнього пушу
30релізів
1бас-фактор
2відкритих issue
crates.io, npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

Історія зірок і форків 0 ★ / 7 ⇿
0Зірки
7Форки
26Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

234567722026-032026-052026-07
Мажорні 2Мінорні 18Патчі 6
OpenSSF Scorecard 4.9 / 10
4.9сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-24 02:33 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/13 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
1Vulnerabilities9 existing vulnerabilities detected
Прямі залежності 24
РеєстрПакетОбмеження версіїМаніфест
crates.ioclap4Cargo.toml
crates.ioclap_complete4Cargo.toml
crates.ioflate21Cargo.toml
crates.iomimalloc0.1Cargo.toml
crates.iorayon1Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioserde_yaml0.9Cargo.toml
crates.iosha20.10Cargo.toml
crates.ioshlex1Cargo.toml
crates.iotar0.4Cargo.toml
crates.iotoml0.8Cargo.toml
crates.iounicode-width0.2Cargo.toml
npm@vercel/analytics^1.6.1site/package.json
npm@vercel/speed-insights^1.3.1site/package.json
npmfumadocs-core^14.7.7site/package.json
npmfumadocs-mdx^11.10.1site/package.json
npmfumadocs-ui^14.7.7site/package.json
npmmermaid^11.16.0site/package.json
npmnext^15.5.20site/package.json
npmreact^19.2.7site/package.json
npmreact-dom^19.2.7site/package.json
npmreact-icons^5.7.0site/package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "skills",
        "claude-code",
        "copilot",
        "cursor",
        "mcp",
        "codex",
        "openclaw",
        "opencode",
        "mcps",
        "ai-agent",
        "ai-skills-manager",
        "antigravity",
        "claude",
        "claude-skills",
        "developer-tool",
        "gemini",
        "kiro",
        "pi",
        "ai-commands"
      ],
      "is_fork": false,
      "size_kb": 1473,
      "has_wiki": false,
      "homepage": "https://www.kasetto.dev",
      "languages": {
        "CSS": 36467,
        "MDX": 104208,
        "Just": 1326,
        "Ruby": 656,
        "Rust": 669391,
        "Shell": 11290,
        "JavaScript": 5611,
        "PowerShell": 4078,
        "TypeScript": 63258
      },
      "pushed_at": "2026-07-18T13:34:55Z",
      "created_at": "2026-03-17T19:27:54Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T14:14:55Z",
      "description": "📼 A declarative AI agent environment manager, written in Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust",
        "MDX"
      ]
    },
    "owner": {
      "blog": "https://www.pivoshenko.dev",
      "name": "Volodymyr Pivoshenko",
      "type": "User",
      "login": "pivoshenko",
      "company": "Bally's Interactive",
      "location": "London",
      "followers": 49,
      "avatar_url": "https://avatars.githubusercontent.com/u/40499728?v=4",
      "created_at": "2018-06-22T17:16:57Z",
      "is_verified": null,
      "public_repos": 25,
      "account_age_days": 2953
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-07-17T13:03:55Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-06-28T09:47:03Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-06-21T20:56:13Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-06-18T20:24:57Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-06-18T20:13:38Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-12T17:09:12Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-06-04T10:03:47Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-06-01T08:53:44Z"
        },
        {
          "tag": "v2.12.0",
          "kind": "minor",
          "published_at": "2026-05-25T13:52:14Z"
        },
        {
          "tag": "v2.11.0",
          "kind": "minor",
          "published_at": "2026-05-19T07:03:34Z"
        },
        {
          "tag": "v2.10.0",
          "kind": "minor",
          "published_at": "2026-05-18T19:56:29Z"
        },
        {
          "tag": "v2.9.1",
          "kind": "patch",
          "published_at": "2026-05-12T20:53:28Z"
        },
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-05-10T20:19:08Z"
        },
        {
          "tag": "v2.8.1",
          "kind": "patch",
          "published_at": "2026-05-10T16:47:13Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-05-10T16:27:08Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-05-09T18:44:45Z"
        },
        {
          "tag": "v2.6.1",
          "kind": "patch",
          "published_at": "2026-05-07T20:41:37Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-05-04T11:41:25Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2026-05-04T10:00:14Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-05-03T20:08:00Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-04-26T15:01:00Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-04-23T07:59:03Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-04-21T19:18:20Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-04-19T19:05:58Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-04-06T13:14:48Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-04-06T12:55:03Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-03-20T16:59:36Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-03-20T16:28:32Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-03-20T15:59:58Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-03-19T07:45:28Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "b4cc4d023685478eed1e1b89c185e672bf93658c",
          "body": null,
          "is_bot": false,
          "headline": "chore: add editorconfig",
          "author_name": "Volodymyr Pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-18T13:34:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a9e6e311465a6523344844145f44c1b5687b319",
          "body": "Biome's noSvgWithoutTitle a11y rule fails on the icon, favicon, and\nlogo because they render visible text without an accessible name.\nGive each svg a title matching its visible content so screen readers\nannounce it and just lint passes.",
          "is_bot": false,
          "headline": "fix(site): add titles to svg assets for accessibility",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T17:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd8d7d6747015920d75191a052c990c5dd75f2e5",
          "body": null,
          "is_bot": false,
          "headline": "build(deps): update dependencies",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T17:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f0c813808cce04e6906fc95e923fc146aa7af03",
          "body": "The header hardcoded \"21 PRESETS, BUILT IN\" and went stale when the\nzcode preset joined the grid. Render AGENTS.length instead so the count\ntracks the list.",
          "is_bot": false,
          "headline": "fix(site): derive agents-grid preset count from list length",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T13:14:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d4039818900f904f6b7342dc1eb4ea5bbcaf607",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.6.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T12:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3752c4dd65d5df97228fcc5079bef50f7937eea6",
          "body": null,
          "is_bot": false,
          "headline": "build: bump crossbeam-epoch to 0.9.20 for RUSTSEC-2026-0204",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T12:56:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53d68a718f5e0896326a7c007246422017e95ba4",
          "body": "Add ZCode (https://zcode.z.ai) as the 22nd agent preset, covering all\nfour asset kinds:\n\n- skills: ~/.zcode/skills (global), .zcode/skills (project)\n- commands: ~/.zcode/commands + .zcode/commands, Markdown + frontmatter\n- MCP servers: new McpSettingsFormat::ZCode writing the nested\n  mcp.servers ob\n[…]\nregate AGENTS.md (workspace) + ~/.zcode/AGENTS.md\n\nThe JSON merge/remove/list helpers in mcps/ are generalized from a\nsingle root key to a nested key path to support the mcp.servers shape.\n\nCloses #45",
          "is_bot": false,
          "headline": "feat: add zcode agent preset",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T12:56:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e07827d1d4505a3bfd9f90519e642a2a88ae0b4",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.5.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-28T09:43:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "146b23d806cc1595afc0bcd0fdaab0134204f4f1",
          "body": "… and CLI help",
          "is_bot": false,
          "headline": "style: normalize unicode ellipsis to ASCII ... across docs, comments,…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:37:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50737d988d59ae3051953c84df7bb9a929fda42e",
          "body": null,
          "is_bot": false,
          "headline": "style: collapse single-line use import in sync/skills",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf40cf7b7bb1838321cea8b3c0d1a811365fb08f",
          "body": "Collapse dedup_targets/dedup_command_targets/dedup_paths/dedup_instruction_targets\nonto one generic dedup_by_path(iter, key); extract json_object() for the shared\nread->parse->get-object preamble behind json_server_names/json_all_keys_present.",
          "is_bot": false,
          "headline": "refactor: dedup path-set helpers and share MCP JSON object parsing",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:24:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d04e8daa3281bee48cd2178938fd25a71e598c1",
          "body": "`doctor` now diffs every managed install path for the active scope against\nthe lock and reports untracked entries across all four asset kinds:\n\n- skills: a `SKILL.md` dir in a managed skills path but absent from the lock\n- commands / per-dir instructions: files in managed dirs not in the lock\n- inst\n[…]\nhealth flag. A config-level custom `destination` redirects the\nskill scan to that dir, matching sync. Surfaced as a Checks row plus an amber\n\"Untracked\" group, and in --json via the `unmanaged` array.",
          "is_bot": false,
          "headline": "feat(doctor): report untracked entries in managed install paths",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:22:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99ea5e2c8b4e0f74478fb67985dfaca37e3b1282",
          "body": "Present the tagged-form secret sources as a list (source -> manager +\nCLI), add a \"Secrets, never committed\" feature bullet, and reframe the\npositioning from \"skill management\" to \"AI environment management across\nprojects, machines, and agents\".",
          "is_bot": false,
          "headline": "docs(readme): list secret managers and broaden positioning",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:27:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "134a658778127b210be8cbbfd15359018f19732c",
          "body": "Clears the high-severity advisory (unbounded out-of-order stream\nreassembly) that was failing audit-rs in CI.",
          "is_bot": false,
          "headline": "fix(deps): bump quinn-proto to 0.11.15 for RUSTSEC-2026-0185",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "217947d51253f334bac8d8401a9942187d1720e0",
          "body": null,
          "is_bot": false,
          "headline": "docs(lock): note the comma-in-path limitation of the destination CSV",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0b550f55c0a64d0f1550aef1be6aa193e6feb79",
          "body": "The `kasetto lock` re-resolve path wrote only destinations[0] -- the\nlock-side twin of the multi-agent data-loss bug fixed in the previous\ncommit (#42). In a multi-agent setup `lock` / `lock --upgrade-package`\npinned a single agent dir, so later teardown orphaned the other agents'\ncopies and doctor \n[…]\ning ones.\n\nExtract fsops::join_dest_csv and route both the sync and lock write\npaths through it so the two cannot drift apart again. Adds unit tests\nfor the helper's relative and out-of-root behavior.",
          "is_bot": false,
          "headline": "fix(lock): record every skill destination in the lock rebuild",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a96600c66dd11770263b94801ed901086035e3e",
          "body": "SkillEntry recorded only the first agent dir, but skills install into all\nconfigured agent dirs. On a source retarget (URL -> local path) the skill\nkey changes, so the new entry installs into every dir and the stale-removal\npass then deletes the old entry's recorded path -- the dir just written --\nd\n[…]\noctor: verify each locked destination exists on disk; fail when missing\n- clean/list: split the multi-value destination\n\nAdds regression tests for the retarget collision and full multi-agent teardown.",
          "is_bot": false,
          "headline": "fix(sync): track every skill destination to stop multi-agent data loss",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24daafe18cdfa623ec3336279550898da5016d1e",
          "body": "Both split a payload on the first `#`. Route vault_path_field through\nsplit_field and add the mandatory-field check on top, so the delimiter\nlogic lives in one place.",
          "is_bot": false,
          "headline": "refactor(secrets): derive vault_path_field from split_field",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "734cbddf14be88f377aef1b907c941d8cdcc686a",
          "body": "Selective `kst sync --update <name>` recomputed the update flag once per\nsource and applied it to every file in that source. When a source held\nseveral secret-bearing MCP files, rotating one force-remerged (overwrite)\nthe others too, clobbering hand-edited servers from the sibling files.\n\nDerive the\n[…]\n fetch decision. Also scope the\nsecret-placeholder check to the injected `mcpServers` object so a\nplaceholder in an unrelated key no longer triggers a spurious\nworld-readable warning and rotation tip.",
          "is_bot": false,
          "headline": "fix(secrets): scope --update rotation per file, not per source",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eda21a86f7b5800c5de00fae2560e15b49e5b370",
          "body": "The tagged form documents ten providers, not four — the count was a\nleftover from before the extra managers were added. Drop the number so\nit can't go stale again.",
          "is_bot": false,
          "headline": "docs(secrets): drop stale provider count in tagged-form intro",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e227ccc6ecbe4c4b4b60a9620687ccb33a5149",
          "body": null,
          "is_bot": false,
          "headline": "docs(site): tighten feature-tab copy",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b029b3fda06a1c00e563cc3c933bc8fa1898d8e5",
          "body": null,
          "is_bot": false,
          "headline": "docs(secrets): document #json-key for gcp and az",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8007d87b05f1e7f2114d253e7e77146ca8c03517",
          "body": "GCP Secret Manager and Azure Key Vault secrets are frequently JSON documents,\nlike AWS. Give `gcp`/`az` the same optional `#<json-key>` selector aws already\nhas, reusing split_field + extract_json_field. No `#` returns the raw secret\n(unchanged behavior).",
          "is_bot": false,
          "headline": "feat(secrets): support #json-key extraction for gcp and az",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6aa501f1748e08b508404abcd1f66fc9cae5ae5",
          "body": "The track title \"SECRET SOURCES\" already labels the section, so the inner\nheader line was redundant.",
          "is_bot": false,
          "headline": "refactor(site): drop the secret-cards header bar",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67b956e606e642d9d9617e60305c5d38a79d8c90",
          "body": "…e example\n\nThe per-card CLI label duplicated the source name (e.g. \"HashiCorp Vault\" /\n\"vault\"); remove it (and its unused style) so each card is just logo + name +\n${kst:…} example. Move the SECRET SOURCES track above EXAMPLE.",
          "is_bot": false,
          "headline": "refactor(site): drop redundant CLI label from secret cards, move abov…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77e221269b15d9eb7a294250ed03efc5b102bfae",
          "body": "New \"SECRET SOURCES\" track with a card per provider — brand logo, name, the CLI\nit uses, and a copy-ready ${kst:…} usage example. Covers all ten sources (env,\ncredentials.yaml, 1Password, Vault, KeePass, AWS, GCP, Azure, pass, Keychain)\nusing monochrome react-icons glyphs tinted to the palette (no image assets).\n\nAlso closes the landing gap where the feature copy only mentioned env/credentials\n— it now names the external managers too.",
          "is_bot": false,
          "headline": "feat(site): add secret-sources cards to the homepage",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6321e315dbc982b844509463c87eea54b0944b97",
          "body": "Add a \"Pinning a source\" subsection for each new provider, refresh the\nunknown-tag list, and update the README, security page, and module map.",
          "is_bot": false,
          "headline": "docs(secrets): document aws, gcp, az, pass, and keychain sources",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11de374b57664fa9b28bb0b6535ac5d63a0b55cb",
          "body": "Five more tagged secret sources, each a thin SecretSource that shells out to the\nprovider's own CLI (so kasetto still stores no tokens):\n\n  ${kst:aws:<secret-id>#<json-key>}   aws secretsmanager get-secret-value\n  ${kst:gcp:<name>}                   gcloud secrets versions access latest\n  ${kst:az:<\n[…]\nson_field); the `#field` split is shared with keychain via split_field.\nLike op/vault/kp these are registered unconditionally but gated by `handles`, so\nthey cost nothing until a matching tag appears.",
          "is_bot": false,
          "headline": "feat(secrets): add aws, gcp, az, pass, and keychain sources",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4825acba6ee2c78e87590f8597ae33d123e7b94b",
          "body": "The per-file classification was an immediately-invoked closure inside the\nsync_mcps loop — a smell used only to get `?`-style error handling, and the\nmain reason the function ran ~320 lines. Extract it into a named\n`classify_mcp_file` that returns an `McpFileOutcome` (Unchanged / SecretError /\nInsta\n[…]\n.\n\nPreserves the status distinction: a malformed file is `broken` (exit 0) while\nan unresolved secret is `source_error` (exit 1), and the `--update`-only\nre-merge of secret-bearing packs is unchanged.",
          "is_bot": false,
          "headline": "refactor(sync): extract classify_mcp_file from sync_mcps",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c04932aed61c5cf849306dbef0b5c418d7c5414",
          "body": "`process_single_skill` took nine positional arguments and carried an\n`#[allow(clippy::too_many_arguments)]`. Group the five cohesive per-skill\ndescriptors (source, revision, name, path, label) into a `SkillJob` struct so\nthe installer takes a single descriptor, and drop the lint allow.",
          "is_bot": false,
          "headline": "refactor(sync): bundle per-skill install args into SkillJob",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba30d3b549119132a74f18322434de1ae1c08ff1",
          "body": "Add a prominent callout that a plain sync leaves the old secret in place, and\nrecord the review hardening (memo, rotation hint, has_secrets lock flag,\ndestination perms warning) in the module map.",
          "is_bot": false,
          "headline": "docs(secrets): flag that rotation requires --update",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b59dffbcd4f2ed0920912cfd48ca26f5cc6c84c3",
          "body": "Address findings from an architectural review of the secret-injection feature:\n\n- memoize resolution per run (SecretContext.cache, keyed on the placeholder)\n  so a repeated secret spawns op/vault/keepassxc once — no duplicate biometric\n  prompts\n- fix the misleading \"kp is not supported\" error to po\n[…]\nhen a destination settings file holding a resolved secret is\n  group/world-readable (reuses warn_if_world_readable, symmetric to credentials)\n- document the write-then-read constraint in run_cli_stdin",
          "is_bot": false,
          "headline": "feat(secrets): harden injection per design review",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c1d5f10036ade4133371ca603f55a45eea2ba7a",
          "body": "Add the KeePass section and config block to the secrets docs, plus README,\nsecurity page, landing/module references and the unknown-tag list.",
          "is_bot": false,
          "headline": "docs(secrets): document the KeePass (kp) secret source",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02dacf6456c5a6692fa4e9e8569863b7cd6f52d6",
          "body": "Add KeePass as a tagged secret source. `${kst:kp:<entry>#<attr>}` (attribute\ndefaults to `Password`) runs `keepassxc-cli show -s -a <attr> <db> <entry>`.\n\nThe database location comes from a new `secrets.keepass` config block\n(`database` + optional `key_file`); unlock supports both a key-file and a\nm\n[…]\ntdin`. With no password, stdin is closed and\n`--no-password` is passed so a prompting CLI fails fast instead of hanging.\nLike op/vault, a failing CLI hard-errors regardless of --allow-missing-secrets.",
          "is_bot": false,
          "headline": "feat(secrets): resolve ${kst:kp:…} via the KeePassXC CLI",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f7d6a0493d5f0506e66cd13b1137fc3396e40b9",
          "body": "Update README, docs site (secrets/security/configuration), landing copy,\nand the module map to the lowercase sentinel and the four explicit source\ntags (env, crd, op, vault).",
          "is_bot": false,
          "headline": "docs(secrets): lowercase ${kst_…} grammar and env/crd source tags",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96ba15b8a3cbb98413e65636c269858904cd4bdf",
          "body": "Switch the placeholder sentinel to lowercase `${kst…}` (matching the\nkasetto/kst brand) and add `env`/`crd` as explicit tags alongside\n`op`/`vault`, so a ref can pin exactly one source:\n\n  ${kst_vercel_token}        chain: env (as-written, then uppercased) -> credentials.yaml\n  ${kst:env:VERCEL_TOKE\n[…]\nesolves the conventional UPPER_CASE env var. Credential\nlookups go through case-insensitive lookup_key/descend helpers. An uppercase\n`${KST…}` is treated as a foreign var and passes through untouched.",
          "is_bot": false,
          "headline": "feat(secrets): lowercase sentinel and explicit env/crd source tags",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e357d1cfd28aab78d72ab10218ab692510bd568",
          "body": "Add an External Secret Managers section to /docs/secrets, update the security\nmodel and README Secrets subsection, and drop the \"not supported yet\" language\nnow that the tagged form resolves through the op/vault CLIs.",
          "is_bot": false,
          "headline": "docs(secrets): document op and vault external secret managers",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ea3627aed9c40c40b9bd451c5a26ef5347851dd",
          "body": "…t CLIs\n\nAdd 1Password and HashiCorp Vault as secret sources behind the tagged\nplaceholder form. ${KST:op:<vault>/<item>/<field>} (or a full op:// URI) shells\nout to `op read`; ${KST:vault:<kv-path>#<field>} shells out to\n`vault kv get -field`. Both inherit the user's existing CLI session — kasetto\n\n[…]\nrs. A failing\nCLI (missing binary, auth error, item not found) hard-fails the entry with the\nCLI's stderr; an unknown tag errors as unsupported. Resolved values are captured\nvia run_cli, never echoed.",
          "is_bot": false,
          "headline": "feat(secrets): resolve ${KST:op:…} and ${KST:vault:…} via the op/vaul…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1fd29b5690afce7f01cf9c7f582778fdf4bc8960",
          "body": "Add a dedicated /docs/secrets page, wire the secrets field into the\nconfiguration reference, reconcile the security model's overwrite and\ncredentials-file claims, note injection on the enterprise feature pillar, and\nadd a README Secrets subsection.",
          "is_bot": false,
          "headline": "docs(secrets): document ${KST_…} secret injection across README and site",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8257b9d9302bb3e21ea528165e764f68f8a0021a",
          "body": "…time\n\nResolve ${KST_<NAME>} placeholders (with __ nested keys) in MCP packs from\nenvironment variables and ~/.config/kasetto/credentials.yaml, so packs can ship\ntoken/password references without committing values.\n\nInjection is in-memory only: the lock hashes the placeholder source file, so\nsecrets\n[…]\nT:op://…} form is\nreserved and errors as unsupported.\n\nmerge_mcp_config now consumes the pre-injected mcpServers map with an overwrite\nflag (the rotation path) instead of reading the pack file itself.",
          "is_bot": false,
          "headline": "feat(secrets): inject ${KST_…} placeholders into MCP configs at sync …",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9bde2c26e4ce641c9b37079a789a83c06bd7be37",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.4.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-21T20:52:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "148429297ebc3dad97417f8b8a23ddf2b171e0b4",
          "body": "Same bug class as the MCP fix: command sync used `cleanup_dir` (the archive\nroot, with no `sub-dir` applied) as the search root on the staged-remote path,\nso a remote command source pinned to a branch/default ref with a `sub-dir`\ndiscovered commands under the repo root instead of the sub-dir. Resolve against\n`materialized.source_root`, which honors `sub-dir` for every source kind.",
          "is_bot": false,
          "headline": "fix(commands): resolve commands from source_root, not cleanup_dir",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4069bd81e83a7855c733cad3436d88cd6c4ae3cf",
          "body": "`store` propagated cache scratch-setup failures (no HOME, read-only\nXDG_CACHE_HOME) as errors, breaking an otherwise-valid sync since `ref:` sources\nroute through the cache. The cache is an optimization, so setup failures now\ndegrade to a miss (`None`), letting the caller extract into its stage dir. Split\nthe promote step into `store_promote` so genuine extraction/promotion errors\nstill surface. Add a regression test.",
          "is_bot": false,
          "headline": "fix(cache): fall back to direct extract when the cache dir is unwritable",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a78ef5bce2b89d8ee664870facdd32593e52d511",
          "body": "The MCP sync path used `cleanup_dir` as the search root, falling back to the\nliteral `src.source` string when it was `None`. Now that a `ref:`-pinned remote\nsource is served from the on-disk cache (no throwaway stage, so `cleanup_dir` is\n`None`), a tag/SHA-pinned `mcps:` source searched under `Path:\n[…]\nalized.source_root` instead — correct for local, freshly\nstaged, and cache-served sources alike (this mirrors what the instructions sync\npath already does). `cleanup_dir` stays a teardown-only handle.",
          "is_bot": false,
          "headline": "fix(mcps): resolve MCP files from source_root, not cleanup_dir",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1faea84863cf4eab4ea37b146326f2df764546b",
          "body": "Audited CLAUDE.md, README, and the site docs against the code:\n\n- CLAUDE.md: materialize_source calls remote::download_extract (the removed\n  fetch_remote wrapper is gone); load_config_any lives in config.rs; rewrite the\n  stale UI System section to the real 24-bit truecolor palette (ACCENT/ATTENTIO\n[…]\n-sub-dir (remove).\n- slash-commands.mdx: drop aider, which is not a kasetto agent preset.\n- configuration.mdx: MCP entry paths resolve relative to the source root only\n  (MCP sources have no sub-dir).",
          "is_bot": false,
          "headline": "docs: correct inaccuracies found in a full docs audit",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a00526c5129d1163c6c898d1c04bf329fbf48d4",
          "body": "Update CLAUDE.md (source/ + fsops/ module notes, sync data flow) for the\nimmutable-ref source cache, streaming + sparse tarball extraction, and rayon\nparallel skill-source materialization. Document the KASETTO_NO_CACHE opt-out in\nthe site configuration reference.",
          "is_bot": false,
          "headline": "docs: document source cache, sparse extraction, parallel fetch",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9333653f228e1bb1a17bd8c2ca61401f7dd206fb",
          "body": "Stream the HTTP response straight into the gzip decoder instead of buffering the\nwhole archive in memory, and sparse-extract only entries under sub-dir, skipping\nthe create/write/chmod syscalls for the rest of a monorepo.",
          "is_bot": false,
          "headline": "perf: sparse-extract sub-dir sources and stream archive bodies",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "060eebc0392f59b36cbb453ba95c277593110278",
          "body": "Add scripts/bench-sync.sh (a hyperfine harness for cold sync) and a just recipe\nto drive it.",
          "is_bot": false,
          "headline": "bench: add hyperfine cold-sync benchmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2e45a35fa4c19f214476bfcd23883dac7b47940",
          "body": "Split skill sync into three phases: plan each source locally (locked\nsatisfiability, needs_fetch), materialize every fetch-bound source in parallel\nvia rayon (downloads/extractions are independent; the source cache serializes\nsame-key races), then process results sequentially in config order so outp\n[…]\n and last-writer-wins destination semantics stay deterministic.\n\nAlso fixes a latent unchanged check that only inspected destinations[0]: it now\nverifies every destination via dest_status().all_match.",
          "is_bot": false,
          "headline": "perf: download source archives in parallel during skill sync",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1a0e67a6c20d7e9eb16eccb20d330f3e8d4007f",
          "body": "Cache extracted source trees under $XDG_CACHE_HOME/kasetto/sources/<hash>/tree/\nwith a sibling .complete marker (atomic extract-to-tmp then rename). Immutable\nrefs reuse the cached tree with zero revalidation, so repeat cold syncs skip\nthe download + extract entirely. Opt out with KASETTO_NO_CACHE.",
          "is_bot": false,
          "headline": "perf: cache extracted source trees for immutable refs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6389d41aaefe446bed3b62961773576c79b2899f",
          "body": "Add X-Content-Type-Options, X-Frame-Options, Referrer-Policy and\nPermissions-Policy to all routes via next.config.mjs headers(), matching\nthe pivoshenko brand sites. Wire @vercel/analytics + @vercel/speed-insights\nin the root layout.",
          "is_bot": false,
          "headline": "feat(site): add security headers, Analytics and Speed Insights",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T17:49:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea375303a811fa57aea00d751233ba8f11d8c13d",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.3.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-18T20:18:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1f85a90e12a92347186a866b0cabb29ac0a5b3b",
          "body": "…e extension names\n\nAddress three P2 review findings in the instructions sync path:\n\n- Discovery now uses materialized.source_root instead of\n  cleanup_dir.unwrap_or(source_root); for a remote source with sub-dir,\n  cleanup_dir is the archive root, so the configured sub-dir was ignored\n  and instruc\n[…]\nction_names strips an explicit .md/.mdc extension from\n  object entries, matching resolve_instruction_entry's stored name, so\n  the lock lookup no longer misses and forces refetches / --locked errors.",
          "is_bot": false,
          "headline": "fix(instructions): honor sub-dir, prune targetless reconfig, normaliz…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:18:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a46f1e68807e08d77b391e3d33a9bcd28a511cc",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.3.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-18T20:08:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2611bba2a429b91ad7bec19200d18c755e6e2b28",
          "body": "The 32-char instruction:multi-agent-dispatch slug overflowed the status\ngutter, breaking column alignment in both demos.\n\n- demo.svg: re-pad all sync rows so every status word starts at column 34\n- globals.css: hero terminal .t-row grid slug column minmax(24ch -> 34ch) so\n  status tails align across rows (no row exceeds the widest existing line)",
          "is_bot": false,
          "headline": "fix(site): align demo status column for longer instruction slugs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b2ab200bd7a9efe042f6f96867033483926e83",
          "body": "Instructions were under-documented after the rules->instructions rename:\nseveral surfaces still described three asset kinds (skills, commands, MCPs).\n\n- landing cards: \"SKILLS, COMMANDS & MCPS\" -> \"... & INSTRUCTIONS\", four kinds\n- commands/sync-flow/auth/configuration/cookbook docs: add/remove/list\n[…]\n README list/clean copy includes instructions\n- example config sources instructions from github.com/pivoshenko/pivoshenko.ai\n  (docs-autoupdate, multi-agent-dispatch); regenerated via just sync-config",
          "is_bot": false,
          "headline": "docs: document instructions as a first-class asset kind",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84f417b7f5cc45b64de36af70438d262f2cb084c",
          "body": "Add two instruction rows (instruction:docs-autoupdate and\ninstruction:multi-agent-dispatch) to the github.com/pivoshenko/pivoshenko.ai\nsource group in the animated README demo.svg and the site hero terminal,\nmarked \"added\" so the new instructions asset kind is visible in the sync\ndemo. Grow the SVG canvas and retime the reveal cascade for the two new\nrows; bump the demo.svg cache-buster to v6.",
          "is_bot": false,
          "headline": "docs: showcase instructions in readme demo and hero terminal",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4561e80113d54e8967775933ded10029ff9f9a7d",
          "body": "Rename the fourth asset kind from \"rules\" to \"instructions\" across the\nRust crate (types, modules, config key, lock kind), the example config,\nand all prose. Each agent's native destination is unchanged: instructions\nstill write to CLAUDE.md / .cursor/rules / AGENTS.md, etc.\n\n- src/rules -> src/inst\n[…]\n -> Instruction*\n- config key `rules:` -> `instructions:`; lock kind -> \"instructions\"\n- source discovery dir rules/ -> instructions/\n- README, docs site, example yaml, CLAUDE.md, CONTRIBUTING updated",
          "is_bot": false,
          "headline": "refactor: rename rules asset kind to instructions",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a068621ffe83e53a00bc3b4dc94656ec3556f29",
          "body": "Add a fourth asset type — rules — that syncs agent instruction files\n(CLAUDE.md, .cursor/rules/*.mdc, AGENTS.md, GEMINI.md, …) from a source's\nrules/ directory into each agent's native location.\n\n- model: RuleSourceSpec/RulesField/RuleEntry config, RuleFormat/RuleTarget,\n  per-agent rules_project_pa\n[…]\nsets with agg:/file: destination tokens\n- wire add/remove/list/doctor/clean/lock + CLI --rule flag and --type rules\n- docs: README, configuration.mdx, agents.mdx (full per-agent path table), CLAUDE.md",
          "is_bot": false,
          "headline": "feat(rules): distribute agent rules across all agents",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3fcb3283511deb2ee8f77d6f8b2f40ac51837a54",
          "body": null,
          "is_bot": false,
          "headline": "fix(site): override js-yaml and dompurify to patch transitive vulns",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T13:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18b93a8f1876a1611c8b15f264783dc6b84f81ae",
          "body": null,
          "is_bot": false,
          "headline": "docs: use brew tap/trust/install for Homebrew instructions",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T12:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec01ccaffad67e5fc57987f441a610682bac6290",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.2.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-12T17:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3d0aaf2d23588e02b77af78b579b38d68926a30",
          "body": "needs_fetch, the repair-source lookup, and the process step each\nre-walked and re-SHA256ed the same destination dirs — up to three\nfull tree hashes per skill per sync, multiplied across agent\ndestinations. A per-run HashCache memoizes per-destination hashes\nand a single dest_status pass derives both\n[…]\ny failure cannot leave a stale verdict. Sharing\none snapshot between needs_fetch and the process step also closes\nthe TOCTOU where the repair-copy guarantee could break between\nthe two hashing passes.",
          "is_bot": false,
          "headline": "perf(sync): hash each skill destination once per run",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "037b1c066166ecd6e80b54504152e7bd98a7fe6e",
          "body": "The buffered read/write loop created destination files with\ndefault permissions, so executable scripts inside skills lost\ntheir +x bit on install. fs::copy preserves permissions and uses\nkernel-level copy where available (clonefile on APFS). On Windows\nthe READONLY attribute is cleared after the copy, since a\npropagated read-only flag would make the next sync's\nremove_dir_all fail with PermissionDenied.\n\nRead-only source files now install read-only on Unix, matching\ncp/cargo/uv semantics.",
          "is_bot": false,
          "headline": "fix(fsops): preserve file permissions in copy_file",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acd4226f0e7b2e3bb3418f7607ae7f69931607b6",
          "body": "Apply the clippy perf lint set (redundant_clone,\nneedless_pass_by_value, needless_collect) plus adjacent idiom\ncleanups: merge_yaml consumes its inputs instead of cloning both\nmaps per extends level, remove_stale borrows the tracked-asset\nlist instead of cloning it into a second map, join_lines takes a\nslice, and string keys and paths stop round-tripping through\nowned Strings. Behavior is unchanged throughout.",
          "is_bot": false,
          "headline": "perf: drop redundant clones and allocations",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04ecc289ded5057ecd7ac2c36b2afc47dabb9099",
          "body": "The `<source>::<name>` lock key was hand-built with format! in\nfive places; one helper keeps the key format from drifting\nbetween the lock writer and the lookup sites.",
          "is_bot": false,
          "headline": "refactor(sync): add skill_key helper for lock keys",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3c9bd858b3c372cec879d2886fdcefa16cbbf4a",
          "body": "The function returns unix seconds as a string; the name promised\nISO 8601 it never delivered. Output format is unchanged.",
          "is_bot": false,
          "headline": "refactor(fsops): rename now_iso to now_unix_str",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69211a91ee2cdf2e3bdbf71da0826f6ba3d5fb40",
          "body": "write_cache swallowed serde_json failures via unwrap_or_default\nand silently wrote an empty cache file. Surface the error to the\ncaller instead; the background refresh thread already treats the\nwrite as best-effort.",
          "is_bot": false,
          "headline": "fix(update-notifier): propagate cache serialization errors",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0e60643f2dd026c043321e8f29f39044d6c1cae",
          "body": "String env values are handled by the arm above, and Display\noutput for numbers, bools, and null is never quote-wrapped, so\nthe trim_matches('\"') could not fire. Render via Display alone.",
          "is_bot": false,
          "headline": "refactor(mcps): drop dead quote-trim on codex env values",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cb35d155043ec1a3d4eade9283858a6331d3337",
          "body": "Wildcard targets were pushed in HashMap iteration order, so\ninstall order, spinner labels, and --json output shuffled\nbetween runs. Sort the selection so output is reproducible,\nconsistent with the deterministic lock.",
          "is_bot": false,
          "headline": "fix(fsops): make wildcard skill selection deterministic",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1240a69d07d3f0280410a1b05a2553302c3502c4",
          "body": "resolve_path replaced every `~` in the string with the home\ndirectory, so a path like `./backup~old/skills` had home spliced\ninto its middle. Only a leading `~/` (or a bare `~`) is a home\nprefix; a tilde elsewhere is an ordinary path character.",
          "is_bot": false,
          "headline": "fix(fsops): expand only a leading tilde in resolve_path",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1774f8e9a17e9507295a55331a208b66797abb34",
          "body": "Parallel test threads can observe the same nanosecond, so the\npid+nanos nonce used by the per-module temp_dir helpers let\nconcurrent tests share a scratch dir and corrupt each other's\nhash expectations (~2 in 5 full-suite runs failed). Add a\nprocess-wide atomic counter to the nonce of the existing fsops\nhelper and drop the 11 duplicated copies in favor of it.",
          "is_bot": false,
          "headline": "test: share one race-free temp_dir helper across modules",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a4cea5db410ac4238d8f8490197d10028c4a4cc",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh CLAUDE.md for current justfile + CI shape",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T13:08:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73c389444b202ea24ae21c76517bfe0b4be72266",
          "body": null,
          "is_bot": false,
          "headline": "ci: fix action versions and test recipe failures",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:15:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f39dc6564b46a4fa39d55b51d6b4f631bbd526d",
          "body": null,
          "is_bot": false,
          "headline": "ci: drop hashFiles guard; move .no-tests sentinel handling into justfile",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a9104c85d471f33d18cc871b461b2fd37ced3e2",
          "body": null,
          "is_bot": false,
          "headline": "ci: flatten to one job per language",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:02:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a5e55882fa98ca32584192cd6db289c29c3ad5",
          "body": null,
          "is_bot": false,
          "headline": "ci: bump action versions to latest major",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T10:59:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6366cc0cdf51ea6e7f30dc52b3bc00bf719cddb9",
          "body": "…-24.04-arm",
          "is_bot": false,
          "headline": "ci: standardize workflow to per-language parallel pipelines on ubuntu…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T10:56:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e02b3f9a4a4c3affbba8f844c67703fae259387e",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.1.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-04T09:59:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec8b5419482d17b4400f941481877c49f714cbed",
          "body": "`kasetto add <deep-URL>` writes source + ref/branch + sub-dir, but\n`remove` was discarding the derived ref/branch/sub-dir and matching\non the bare source alone. In a config with multiple entries from the\nsame repo (different sub-dirs or refs), `remove` either errored as\nambiguous or could only targe\n[…]\nTODO;\n  proper fix is a host branches-API probe.\n\nThree new tests cover sub-dir disambiguation, the ambiguity error\nwhen sub-dir is omitted, and matching entries without a sub-dir via\nan empty filter.",
          "is_bot": false,
          "headline": "fix(commands): match remove by sub-dir from deep browse URLs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b50ad7f744511babc60c3a79ef585b1c5ae73f7a",
          "body": "…emo screens\n\n- add: reject `--locked` without `--no-sync` up front (cargo-style \"lock\n  would need updating but --locked was passed\"). A brand-new source has\n  no lock entry yet, so the implicit sync would fail mid-flight after\n  the manifest edit; the error now points at the two valid workflows\n- \n[…]\n assets/demo.svg: fade the scene-2 add lines at 8.06s → 8.32s (just\n  before remove appears at 8.50s) and reposition remove lines back to\n  the top of the terminal; comment updated to reflect 3 scenes",
          "is_bot": false,
          "headline": "feat(commands): guard add --locked + split add/remove into separate d…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d4ce5fe672e78ba08ccbf252b533d3143d6cfe6",
          "body": "- add/remove: <source>@<ref> shorthand, --dry-run, --locked, --json,\n  -qq count plumbing, `tip:` hint after --no-sync; verb tense corrected\n  to present continuous (Adding/Removing) so the sync summary's past\n  tense (Installed N items) closes the rhythm\n- lock: --check (aliases --locked/--frozen) \n[…]\n per the cross-surface sync rule, including a new cookbook recipe for\n  cargo/uv-style editing and one for lock --check / --upgrade-package\n- justfile: drop the now-unused demo-vhs / demo-fish recipes",
          "is_bot": false,
          "headline": "feat(commands): cargo/uv-style flags on add/remove/lock + two-scene demo",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c03a1bfa2abf903905979d9be698866fc9c7cb82",
          "body": "Add three config-editing subcommands inspired by cargo/uv:\n\n- `add <source>`: append a source to the local kasetto.yaml (comments\n  preserved via line-surgical edits, never a serde round-trip) and sync\n  it in. Kind-tagged repeatable flags --skill/--mcp/--command name entries\n  and can touch several\n[…]\n CLI style\n(terse name-only-colored edit confirmations, green Locked summary verb,\ncolor gated on color_stdout_enabled).\n\nDocs updated across README, the docs site commands/index pages, and\nCLAUDE.md.",
          "is_bot": false,
          "headline": "feat(commands): add cargo/uv-style add, remove, and lock subcommands",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b1ffd2d4e142f93f0fc76dab4e2c4aa3d57b00d",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): tighten social preview centering",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T19:04:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea3a6327c72fd7adf9893837b8853f8cc8ae27c5",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): drop terminal chrome from social preview, center wordmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T19:00:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a692c4d11d1cd9ab0b6dd0aa417eeb902a5f374b",
          "body": "… mono",
          "is_bot": false,
          "headline": "docs(assets): restore ascii wordmark in social preview, use jetbrains…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73bb54df5261439cbc5ca190a3932f98b0d1b782",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): redesign social preview with clean wordmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:55:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6263e9df965f165f585d15ae7ff597d5ddc0093",
          "body": "…mo svg",
          "is_bot": false,
          "headline": "docs(readme): color inline status words (updated/added/removed) in de…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46878cf16b0a5806e1e655e1791d7ff2201c1605",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): bust camo cache for demo svg",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a420107b778a3917a7bc03df2e505729d04e9277",
          "body": null,
          "is_bot": false,
          "headline": "revert(readme): drop two-column demo layout, restore single column",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:48:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfd752e238c3e36ab8466ef00900bb2cab3bc4bf",
          "body": "… display",
          "is_bot": false,
          "headline": "docs(readme): reflow demo svg into two columns for shorter full-width…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:32:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bf59f2f376e5e65a5d8be73a359e04e4899a4ff",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): scale demo svg to 50% width, centered",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:28:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a30974d84423bb60c34dd4ff6b8ae4dd218cb669",
          "body": null,
          "is_bot": false,
          "headline": "ci: rename Deploy Site workflow to Site",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:27:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cde41936f823481afde0edaef5b4f77bf86d8968",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): shrink demo svg further (376h, 12px font, 11px rows)",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c8e4213b7528609a4bbddfeb1f005f317960c6d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): compress demo svg vertically, restore full width",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:24:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c665c03b59207ef38a247e722ad6b5b1f90cd2f",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): shrink demo svg to 720px and center",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "995b8bcfd57bf4419119601225be1f633c8a50f1",
          "body": "Promotes the bold \"About the name\" to a heading-style line on its own\nand updates the body to cover all three asset kinds (skills, MCPs,\ncommands) instead of just two.",
          "is_bot": false,
          "headline": "docs(readme): split about-the-name into its own paragraph",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67df306a1ff87eeb2f923b607b935b15390fc2f2",
          "body": "The five overlapping spinner frames read as a glitch under GitHub's\nrendering, so revert to the simpler prompt → Resolved transition.\n\nMove the etymology line under the mock and label it \"About the name\"\nso it reads as a footnote rather than the lead paragraph.",
          "is_bot": false,
          "headline": "docs(readme): drop resolving spinner, move name blurb below demo",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2824c83bfabcb84ee48bf4055eefa5517645f53e",
          "body": "Drop per-line spacing from 18 → 14 px and tighten the section gaps so\nthe 1:0.97 square aspect ratio becomes 1:0.78. At width=100% on\nGitHub's README column the terminal is now ~20% shorter without\nlosing readability or any rows.",
          "is_bot": false,
          "headline": "docs(readme): compress demo svg vertically",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0367314d9fb9c4cae430402c4e6514a3ec7a2266",
          "body": "- New phase between the prompt and the Resolved line: five braille\n  spinner frames (⠋⠙⠹⠸⠼) cycle for ~600 ms next to \"Resolving sources\"\n  before the ✓ Resolved line lands, matching the site's resolve state.\n- Rename sync-demo.svg → demo.svg now that it's the only README mock.\n- Drop the centering wrapper and set img width=\"100%\" so the terminal\n  spans the README column instead of sitting at 580 px.\n- viewBox tightened to 580×560 (was 580×580) to drop unused padding.",
          "is_bot": false,
          "headline": "docs(readme): add resolving spinner, rename to demo.svg, span full width",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 30,
      "commits_last_year": 409,
      "latest_release_at": "2026-07-17T13:03:55Z",
      "latest_release_tag": "v3.6.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 17,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 6.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "kasetto",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "cursor",
            "claude-code",
            "codex",
            "skills",
            "mcps"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/kasetto",
          "is_deprecated": false,
          "latest_version": "3.6.0",
          "repository_url": "https://github.com/pivoshenko/kasetto",
          "versions_count": 29,
          "total_downloads": 485,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 128,
          "first_published_at": "2026-03-19T07:53:56.660116Z",
          "latest_published_at": "2026-07-17T13:04:42.620240Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 7,
      "stars": 117,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-21",
            "count": 2
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 7,
        "total_forks": 7
      },
      "star_history": null,
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "site/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml"
      ],
      "largest_source_bytes": 41394,
      "source_files_sampled": 85,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 23446
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "clap_complete",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "flate2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "mimalloc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "rayon",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_yaml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "shlex",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tar",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "toml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "unicode-width",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "@vercel/speed-insights",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.1"
        },
        {
          "name": "fumadocs-core",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.7.7"
        },
        {
          "name": "fumadocs-mdx",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.10.1"
        },
        {
          "name": "fumadocs-ui",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.7.7"
        },
        {
          "name": "mermaid",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.16.0"
        },
        {
          "name": "next",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.5.20"
        },
        {
          "name": "react",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-icons",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.7.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 25,
        "open_issues": 2,
        "closed_ratio": 0.833,
        "closed_issues": 10,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "pivoshenko",
          "commits": 367,
          "avatar_url": "https://avatars.githubusercontent.com/u/40499728?v=4"
        },
        {
          "type": "User",
          "login": "aaronflorey",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/948073?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.973
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "ci.yaml",
        "labels.yaml",
        "release.yaml",
        "site.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/13 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "b4cc4d023685478eed1e1b89c185e672bf93658c",
        "ran_at": "2026-07-24T02:33:44Z",
        "aggregate_score": 4.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T13:36:33Z",
      "oldest_open_prs": [
        {
          "number": 51,
          "created_at": "2026-07-21T02:02:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-17T13:14:57Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 48,
          "created_at": "2026-07-19T15:24:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 49,
          "created_at": "2026-07-19T15:32:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/pivoshenko/kasetto",
    "host": "github.com",
    "name": "kasetto",
    "owner": "pivoshenko"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 49,
        "vitality": 82,
        "community": 55,
        "governance": 55,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 82,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 409,
              "human_commit_share": 0.93,
              "days_since_last_push": 5,
              "active_weeks_last_year": 17
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "17/52 weeks with commits",
                "points": 11.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 17
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "409 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 409
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 30,
              "latest_release_tag": "v3.6.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 6.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "30 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "forks": 7,
              "stars": 117,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "117 stars",
                "points": 33.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 117
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "7 forks",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "packages": [
                "kasetto"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 485,
              "monthly_downloads": 128
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "128 downloads/month across crates",
                "points": 28.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 128,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.973
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 25,
              "open_issues": 2,
              "closed_issues": 10,
              "issue_closed_ratio": 0.833,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "83% of issues closed",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "25/38 decided PRs merged",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 25,
                      "decided": 38
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "followers": 49,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "pivoshenko",
              "public_repos": 25,
              "account_age_days": 2953
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "49 followers of pivoshenko",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 49,
                      "login": "pivoshenko"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "25 public repos, account ~8 yr old",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 25
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "kasetto"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "29 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "ai",
                "skills",
                "claude-code",
                "copilot",
                "cursor",
                "mcp",
                "codex",
                "openclaw",
                "opencode",
                "mcps",
                "ai-agent",
                "ai-skills-manager",
                "antigravity",
                "claude",
                "claude-skills",
                "developer-tool",
                "gemini",
                "kiro",
                "pi",
                "ai-commands"
              ],
              "has_wiki": false,
              "homepage": "https://www.kasetto.dev",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.kasetto.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 4.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 71,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 23446
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "93 of 93 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 93,
                      "sampled": 93
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [
                "Cargo.lock",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "site/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "site/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "site/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 41394,
              "source_files_sampled": 85,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/85 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 85,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T02:33:57.752187Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/pivoshenko/kasetto.svg",
  "full_name": "pivoshenko/kasetto",
  "license_state": "custom",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаcrates.io.