Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-27 03:49 UTC

quantakrypto / pqc-tools

Open-source post-quantum readiness tooling by quantakrypto

TypeScriptApache-2.0★ 9 зірок⑂ 0 форківз черв. 2026 р.Переглянути на GitHub ↗

quantakrypto/pqc-tools має індекс здоров’я 67 зі 100, що відповідає смузі «Помірний». Найвищий показник — Engineering Quality (90/100), найнижчий — Sustainability & Governance (43/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

67
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

67
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

@QuantaKryptoОрганізація
1 підписник4 публічні репозиторіїз черв. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
npm@quantakrypto/mcp0.5.22 087134 дні тому
npm@quantakrypto/core0.5.02 041116 днів тому
npm@quantakrypto/agent0.5.072566 днів тому
npm@quantakrypto/qscan0.5.01 597116 днів тому
npm@quantakrypto/sieve0.5.01 714116 днів тому
npm@quantakrypto/qprobe0.5.031226 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

75Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
4.2/36Ритм комітів — 6/52 тижнів із комітами
18/18Обсяг комітів — 254 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year254
human_commit_share0,98
days_since_last_push0
active_weeks_last_year6
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 4 релізів
36/36Свіжість релізів — останній реліз 3 дн. тому
27/27Ритм релізів — реліз кожні ~2,5 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count4
latest_release_tagv1
releases_from_tagsні
days_since_latest_release3
mean_days_between_releases2,5
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

55Помірний · 18% загального індексу
Як обчислюється оцінка
14.6/60Зірки — 9 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars9
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
18/18Настанови CONTRIBUTING
13.5/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductтак
has_pull_request_templateтак
Як обчислюється оцінка
52.4/80Щомісячні завантаження — 8 476 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
dependents
ecosystemsnpm
total_downloads
monthly_downloads8 476
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

43У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
21/38.3Прийняття PR — злито 17/31 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs17
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs14
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue. Залишкові ваги перенормовано.

Власність та опіка

38У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
2.2/25Охоплення власника — 1 підписників у quantakrypto
5.3/25Послужний список — 4 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers1
owner_typeOrganization
is_verified
owner_loginquantakrypto
public_repos4
account_age_days34

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 6 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 4 дн. тому
20/20Історія версій — 13 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
ecosystemsnpm
any_deprecatedні
min_days_since_publish4

Інженерна якість

Чи наявні базові інженерні практики та документація?

90Відмінний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 7 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — eslint.config.js
0/9.6Pre-commit-хуки
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigтак
has_linter_configтак
has_precommit_configні

Документація

90Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://quantakrypto.com/tools
10/10Опис репозиторію
10/10Теми — 20 тем
0/10Wiki
Використані вхідні дані
topicscrypto-agility, cryptography, harvest-now-decrypt-later, infosec, post-quantum, pqc, pqc-migration, pqc-readiness, pqcrypto, q-day, quantum, quantum-readiness, security-training, encryption-strategy, pqc-certification, cbom, mcp, post-quantum-cryptography, sbom, nist
has_wikiні
homepagehttps://quantakrypto.com/tools
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

77Добрий · 16% загального індексу
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — немає даних
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
1.2/2.5CII-Best-Practices — badge detected: Passing
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
4.5/5SAST — SAST tool detected but not run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 52 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate7,1
Виключено з оцінювання (немає даних або не застосовно): branch_protection, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
25/25Непрямі залежності без відомих сповіщень — жодна непряма залежність не має відомих сповіщень
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages2
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено з runtime-замиканням залежностей npm:@quantakrypto/mcp@0.5.2 — тим, що тягне за собою встановлення опублікованого пакета, — 2 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

70Добрий · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 90 з 98 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,918
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
12.6/18Розгортання однією командою — packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (домовленість інструментарію, без раннера задач)
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — eslint.config.js
11/11Статична перевірка типів — packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
10/10Відтворюване середовище — Dockerfile, lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
8/8Автоматизоване супроводження — 2 з останніх 100 комітів — автоматичні оновлення залежностей
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Використані вхідні дані
has_nixні
has_testsтак
lockfilespackage-lock.json
has_dockerfileтак
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configspackages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifestspackages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml, packages/core/test/benchmark/recall/rust/Cargo.toml
dependency_bot_commit_share0,02
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
55/55Керовані розміри файлів — 0/454 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes59 062
source_files_sampled454
oversized_source_files0
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalтак
api_schema_files

Ключові факти

9зірок GitHub
1контриб'юторів
254комітів за останні 12 місяців
0днів від останнього пушу
4релізів
1бас-фактор
0відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

OpenSSF Scorecard 7.1 / 10
7.1сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-27 03:49 UTC

10Binary-Artifactsno binaries found in the repo
н/дBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
5CII-Best-Practicesbadge detected: Passing
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
9SASTSAST tool detected but not run on all commits
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities52 existing vulnerabilities detected
Прямі залежності 9
РеєстрПакетОбмеження версіїМаніфест
npm@quantakrypto/core0.5.0packages/action/package.json
npm@quantakrypto/qscan0.5.0packages/action/package.json
npm@quantakrypto/core0.5.0packages/agent/package.json
npm@quantakrypto/core0.5.0packages/mcp/package.json
npm@quantakrypto/qprobe0.5.0packages/mcp/package.json
npm@quantakrypto/core0.5.0packages/qprobe/package.json
npm@quantakrypto/agent0.5.0packages/qscan/package.json
npm@quantakrypto/core0.5.0packages/qscan/package.json
npm@noble/post-quantum^0.4.0validation/sieve-real-sut/package.json
Усі залежності 214

Повний розв'язаний набір залежностей із графа залежностей GitHub: 6 прямих і 208 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
npm@noble/post-quantum0.4.1пряма
npm@noble/post-quantum0.6.1пряма
npm@quantakrypto/agent0.5.0пряма
npm@quantakrypto/core0.5.0пряма
npm@quantakrypto/qprobe0.5.0пряма
npm@quantakrypto/qscan0.5.0пряма
crates.ioanyhowнепряма
crates.ioed25519-dalekнепряма
crates.iohexнепряма
crates.ioopensslнепряма
crates.iorsaнепряма
crates.ioserdeнепряма
crates.ioserde_jsonнепряма
crates.iotokioнепряма
crates.iotracingнепряма
crates.iox25519-dalekнепряма
Gogithub.com/cloudflare/circlv1.3.9непряма
Gogithub.com/decred/dcrd/dcrec/secp256k1/v4v4.3.0непряма
Gogithub.com/golang-jwt/jwt/v5v5.2.1непряма
Gogolang.org/x/cryptov0.24.0непряма
Gogolang.org/x/sysv0.21.0непряма
Gogolang.org/x/termv0.21.0непряма
Mavencom.fasterxml.jackson.core:jackson-databind2.17.1непряма
Mavenio.jsonwebtoken:jjwt-api0.11.5непряма
Mavenorg.bouncycastle:bcpkix-jdk18on1.78.1непряма
Mavenorg.bouncycastle:bcprov-jdk18on1.78.1непряма
npm@esbuild/aix-ppc640.28.1непряма
npm@esbuild/android-arm0.28.1непряма
npm@esbuild/android-arm640.28.1непряма
npm@esbuild/android-x640.28.1непряма
npm@esbuild/darwin-arm640.28.1непряма
npm@esbuild/darwin-x640.28.1непряма
npm@esbuild/freebsd-arm640.28.1непряма
npm@esbuild/freebsd-x640.28.1непряма
npm@esbuild/linux-arm0.28.1непряма
npm@esbuild/linux-arm640.28.1непряма
npm@esbuild/linux-ia320.28.1непряма
npm@esbuild/linux-loong640.28.1непряма
npm@esbuild/linux-mips64el0.28.1непряма
npm@esbuild/linux-ppc640.28.1непряма
npm@esbuild/linux-riscv640.28.1непряма
npm@esbuild/linux-s390x0.28.1непряма
npm@esbuild/linux-x640.28.1непряма
npm@esbuild/netbsd-arm640.28.1непряма
npm@esbuild/netbsd-x640.28.1непряма
npm@esbuild/openbsd-arm640.28.1непряма
npm@esbuild/openbsd-x640.28.1непряма
npm@esbuild/openharmony-arm640.28.1непряма
npm@esbuild/sunos-x640.28.1непряма
npm@esbuild/win32-arm640.28.1непряма
npm@esbuild/win32-ia320.28.1непряма
npm@esbuild/win32-x640.28.1непряма
npm@eslint-community/eslint-utils4.9.1непряма
npm@eslint-community/regexpp4.12.2непряма
npm@eslint/config-array0.21.2непряма
npm@eslint/config-helpers0.4.2непряма
npm@eslint/core0.17.0непряма
npm@eslint/eslintrc3.3.5непряма
npm@eslint/js9.39.4непряма
npm@eslint/object-schema2.1.7непряма
npm@eslint/plugin-kit0.4.1непряма
npm@humanfs/core0.19.2непряма
npm@humanfs/node0.16.8непряма
npm@humanfs/types0.15.0непряма
npm@humanwhocodes/module-importer1.0.1непряма
npm@humanwhocodes/retry0.4.3непряма
npm@noble/ciphers2.2.0непряма
npm@noble/curves2.2.0непряма
npm@noble/hashes1.8.0непряма
npm@noble/hashes2.2.0непряма
npm@quantakrypto/action0.5.0непряма
npm@quantakrypto/mcp0.5.2непряма
npm@quantakrypto/observatory0.0.0непряма
npm@quantakrypto/sieve0.5.0непряма
npm@types/estree1.0.9непряма
npm@types/json-schema7.0.15непряма
npm@types/node26.1.1непряма
npm@types/node^20.12.0непряма
npm@typescript-eslint/eslint-plugin8.61.0непряма
npm@typescript-eslint/parser8.61.0непряма
npm@typescript-eslint/project-service8.61.0непряма
npm@typescript-eslint/scope-manager8.61.0непряма
npm@typescript-eslint/tsconfig-utils8.61.0непряма
npm@typescript-eslint/type-utils8.61.0непряма
npm@typescript-eslint/types8.61.0непряма
npm@typescript-eslint/typescript-estree8.61.0непряма
npm@typescript-eslint/utils8.61.0непряма
npm@typescript-eslint/visitor-keys8.61.0непряма
npmacorn8.16.0непряма
npmacorn-jsx5.3.2непряма
npmajv6.15.0непряма
npmansi-styles4.3.0непряма
npmargparse2.0.1непряма
npmbalanced-match1.0.2непряма
npmbalanced-match4.0.4непряма
npmbrace-expansion1.1.16непряма
npmbrace-expansion5.0.7непряма
npmcallsites3.1.0непряма
npmchalk4.1.2непряма
npmcolor-convert2.0.1непряма
npmcolor-name1.1.4непряма
npmconcat-map0.0.1непряма
npmcross-spawn7.0.6непряма
npmdebug4.4.3непряма
npmdeep-is0.1.4непряма
npmelliptic^6.5.4непряма
npmelliptic^6.5.5непряма
npmesbuild0.28.1непряма
npmescape-string-regexp4.0.0непряма
npmeslint9.39.4непряма
npmeslint-scope8.4.0непряма
npmeslint-visitor-keys3.4.3непряма
npmeslint-visitor-keys4.2.1непряма
npmeslint-visitor-keys5.0.1непряма
npmespree10.4.0непряма
npmesquery1.7.0непряма
npmesrecurse4.3.0непряма
npmestraverse5.3.0непряма
npmesutils2.0.3непряма
npmexpress^4.18.0непряма
npmexpress^4.19.2непряма
npmfast-check4.9.0непряма
npmfast-deep-equal3.1.3непряма
npmfast-json-stable-stringify2.1.0непряма
npmfast-levenshtein2.0.6непряма
npmfdir6.5.0непряма
npmfile-entry-cache8.0.0непряма
npmfind-up5.0.0непряма
npmflat-cache4.0.1непряма
npmflatted3.4.2непряма
npmfsevents2.3.3непряма
npmglob-parent6.0.2непряма
npmglobals14.0.0непряма
npmhas-flag4.0.0непряма
npmignore5.3.2непряма
npmignore7.0.5непряма
npmimport-fresh3.3.1непряма
npmimurmurhash0.1.4непряма
npmis-extglob2.1.1непряма
npmis-glob4.0.3непряма
npmisexe2.0.0непряма
npmjs-yaml4.3.0непряма
npmjson-buffer3.0.1непряма
npmjson-schema-traverse0.4.1непряма
npmjson-stable-stringify-without-jsonify1.0.1непряма
npmjsonwebtoken^9.0.0непряма
npmjsonwebtoken^9.0.2непряма
npmkeyv4.5.4непряма
npmlevn0.4.1непряма
npmlocate-path6.0.0непряма
npmlodash^4.17.21непряма
npmlodash.merge4.6.2непряма
npmminimatch10.2.5непряма
npmminimatch3.1.5непряма
npmms2.1.3непряма
npmnatural-compare1.4.0непряма
npmnode-forge^1.3.1непряма
npmoptionator0.9.4непряма
npmp-limit3.1.0непряма
npmp-locate5.0.0непряма
npmparent-module1.0.1непряма
npmpath-exists4.0.0непряма
npmpath-key3.1.1непряма
npmpicomatch4.0.4непряма
npmpino^9.2.0непряма
npmprelude-ls1.2.1непряма
npmprettier3.8.3непряма
npmpunycode2.3.1непряма
npmpure-rand8.4.2непряма
npmresolve-from4.0.0непряма
npmsemver7.8.3непряма
npmshebang-command2.0.0непряма
npmshebang-regex3.0.0непряма
npmstrip-json-comments3.1.1непряма
npmsupports-color7.2.0непряма
npmtinyglobby0.2.17непряма
npmts-api-utils2.5.0непряма
npmtsx4.23.1непряма
npmtype-check0.4.0непряма
npmtypescript5.9.3непряма
npmtypescript^5.4.5непряма
npmtypescript-eslint8.61.0непряма
npmundici-types8.3.0непряма
npmuri-js4.4.1непряма
npmwhich2.0.2непряма
npmword-wrap1.2.5непряма
npmyocto-queue0.1.0непряма
NuGetBouncyCastle.Cryptography2.4.0непряма
NuGetNewtonsoft.Json13.0.3непряма
NuGetSystem.IdentityModel.Tokens.Jwt7.5.1непряма
PyPIcryptographyнепряма
PyPIcryptography49.0.0непряма
PyPIfastapi0.110.1непряма
PyPIparamikoнепряма
PyPIprometheus-client0.20.0непряма
PyPIpycryptodome3.20.0непряма
PyPIpycryptodome3.23.0непряма
PyPIpydantic-settings2.2.1непряма
PyPIpyjwtнепряма
PyPIpyopensslнепряма
PyPIpython-dotenv1.0.1непряма
PyPIrequestsнепряма
PyPIrequests2.34.2непряма
PyPIstructlog24.1.0непряма
PyPIuvicorn0.29.0непряма
RubyGemsed25519непряма
RubyGemsjwtнепряма
RubyGemsnet-sshнепряма
RubyGemspgнепряма
RubyGemspumaнепряма
RubyGemsrailsнепряма
RubyGemsrbnaclнепряма
RubyGemsrspec-railsнепряма
RubyGemsrubocopнепряма
Сповіщення про залежності 0

Встановлення npm:@quantakrypto/mcp@0.5.2 тягне 2 пакетів, прямих і транзитивних: 0 мають відомі сповіщення, з них 0 — прямі залежності.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "crypto-agility",
        "cryptography",
        "harvest-now-decrypt-later",
        "infosec",
        "post-quantum",
        "pqc",
        "pqc-migration",
        "pqc-readiness",
        "pqcrypto",
        "q-day",
        "quantum",
        "quantum-readiness",
        "security-training",
        "encryption-strategy",
        "pqc-certification",
        "cbom",
        "mcp",
        "post-quantum-cryptography",
        "sbom",
        "nist"
      ],
      "is_fork": false,
      "size_kb": 2378,
      "has_wiki": false,
      "homepage": "https://quantakrypto.com/tools",
      "languages": {
        "C": 11808,
        "C#": 13339,
        "Go": 13560,
        "HCL": 448,
        "PHP": 259,
        "Java": 9201,
        "Ruby": 9206,
        "Rust": 11638,
        "Bicep": 214,
        "Shell": 1100,
        "Swift": 110,
        "Kotlin": 2093,
        "Python": 18432,
        "Dockerfile": 1319,
        "JavaScript": 146066,
        "TypeScript": 1911224
      },
      "pushed_at": "2026-07-26T17:47:28Z",
      "created_at": "2026-06-09T04:17:00Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T17:47:47Z",
      "description": "Open-source post-quantum readiness tooling by quantakrypto",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://quantakrypto.com",
      "name": "@QuantaKrypto",
      "type": "Organization",
      "login": "quantakrypto",
      "company": null,
      "location": "Switzerland",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/295786989?v=4",
      "created_at": "2026-06-22T08:34:25Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 34
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1",
          "kind": "other",
          "published_at": "2026-07-23T05:57:13Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-20T15:46:31Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-07-19T08:10:54Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-15T18:46:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "409726240647384572233737a78f2a66bd9854d1",
          "body": "…lockfile depth, parallel double-stat) (#38)\n\nFour post-1.0-roadmap detection items on the benchmark-guarded surface.\nThe F1 = 1.000 precision/recall benchmark is unchanged (zero FP, zero FN).\n\n- PHP composer.json / composer.lock dependency scanning: add `composer` to\n  DependencyEcosystem, a curate\n[…]\nrf; file set and detection output are byte-identical.\n\nRebuilds the action bundle. Full gate green (test, typecheck, lint, api:check,\nformat:check).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(core): detection quick-wins (PHP composer, JS recall edges, npm …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:47:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a8b0e6f5f620a4aebcc1a18e1766355189b0802",
          "body": "…(#37)\n\nQuantify harvest-now-decrypt-later exposure so the migration backlog ranks by\nreal risk instead of finding counts. Exposure per finding =\ncrypto-vulnerability x data-sensitivity x Mosca-factor (retention + secrecy\nlifetime vs the quantum-threat horizon; Mosca's inequality made concrete).\n\nco\n[…]\nrprintFinding().\n\nSemVer: minor (additive API + CLI). Tests: parser, glob, binding, Mosca math,\nsummary, scaffold, CLI wiring. api:docs regenerated.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(hndl): data-risk quantifier (hndl.yml, qscan --hndl, hndl init) …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcaf36631a8664ef3ad03fd1b6e542a46b9d6bdf",
          "body": "Every finding in the qScan --format json output now carries a top-level\nfingerprint field, and each SARIF result mirrors it in properties.fingerprint\nalongside the existing partialFingerprints. The value reuses the baseline\nidentity fingerprintFinding: sha256(ruleId | normalized POSIX repo-relative\n\n[…]\ntinctness across rule/path/\ncontext, the rule+path fallback, cross-format equality (JSON = SARIF =\nbaseline), and stability under snippet redaction.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "core: stable finding fingerprints in JSON and SARIF output (#36)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:22:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e73eb43a2fafd1922746309b664a5d0afdd5277",
          "body": "…m the scan\n\nmanifests were exempt from the file-size cap entirely; a hostile or broken\nlockfile could be read unbounded. give them a generous 16 MiB ceiling instead\n(real monorepo lockfiles are well under it). pure size logic, no detection change.",
          "is_bot": false,
          "headline": "fix(core): cap manifest read size so a pathological lockfile can't oo…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c4dc93b0637a2f9d252c6e318863bcd976ed230",
          "body": "everything the backlogs tracked as P0/P1 has shipped (0.5.x: 52 detectors,\n14 languages, qprobe, openvex, standards profiles, frozen api). what's left is\naccuracy nice-to-haves, the declarative detector factory, perf, and a golden-file\ncorpus. reconciled against the code 2026-07-26.",
          "is_bot": false,
          "headline": "docs: reconciled post-1.0 roadmap (supersedes the old audit backlogs)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c68538aad98554ccd772906da533063ed2e14162",
          "body": null,
          "is_bot": false,
          "headline": "docs: version-support policy for the 0.5.x packages + the v1 action tag",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b5f48fa7eabd291dfac2cdeb054188184eb7ad",
          "body": "…ity vs cryptodeps\n\nadds tink across com.google.crypto.tink (maven), tink-crypto/tink-go +\ngoogle/tink/go (go), and pypi tink. flagged as rsa/ecdsa/eddsa signatures\nplus ecies hybrid, so hndl-exposed. catalog now 81 entries.\n\ncrypto-js stays out on purpose: it is symmetric/hash/hmac/pbkdf2 only, no\nasymmetric public-key surface, same scope boundary as the password kdfs.\ncomparison doc updated to reflect full parity on the pubkey packages\ncryptodeps documents. re-bundled the action dist.",
          "is_bot": false,
          "headline": "feat(core): catalog google tink (maven/go/pypi); note full pubkey par…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bd18cb4d42fb129aa3dd8f3f37a0dbf7da9712d",
          "body": "two head-to-head comparisons with verified coverage: algorithm matrix,\necosystem/package parity, extras and honest gaps vs cryptodeps, plus the\nfips 203/204/205, sp 800-208, cnsa 2.0 and ir 8547 mapping vs nist.\ncounts verified against the built registry and dep catalog, not prose.",
          "is_bot": false,
          "headline": "docs: add comparison vs qramm/cryptodeps and vs nist",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a0aac3fc77fcf9520a27e4f7c51f5f9f0640655",
          "body": "* docs: fix dead links, stale versioning note, and API-reference doc extraction\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numb\n[…]\nlve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\n* docs: fix unfinished 'See and' phrase in ADR 0005",
          "is_bot": false,
          "headline": "docs: fix unfinished 'See and' phrase in ADR 0005 (#35)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:42:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27ad3e3f10f339545be148d4244a7a8e84d9cf44",
          "body": "…traction (#34)\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numbers (pre-1.0, 0.x range)\n- gen-api-reference.mjs: anchor doc sum\n[…]\nolve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "docs: fix dead links, stale versioning note, and API-reference doc ex…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:37:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a921a52c6e6a8d6cb9382a711b6573156ef33068",
          "body": "chore: move the observatory worker to its own repository",
          "is_bot": false,
          "headline": "Merge pull request #33 from quantakrypto/chore/remove-observatory",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74cec18da463e58ed805258009103b469c8f57fd",
          "body": "The PQC observatory worker now lives at github.com/quantakrypto/pqc-observatory,\na self-contained repo that probes public hosts via openssl (it must not depend on\nqProbe, which is ownership-gated for endpoints you control). Removed from here:\npackages/observatory, ADR 0007, the root observatory script, and the pg devDep.",
          "is_bot": false,
          "headline": "chore: move the observatory worker to its own repository",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:15:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d35f4f5b15252f45e217a05eb15fbd6da50a0e",
          "body": "Observatory: internal PQC-readiness probe worker (ADR 0007)",
          "is_bot": false,
          "headline": "Merge pull request #32 from quantakrypto/feat/observatory-worker",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba8063706e85acc49fdb268b81af3d18fe21976d",
          "body": null,
          "is_bot": false,
          "headline": "docs: OpenSSF Best Practices pre-filled answers",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0f88aeeae962a56770bc0420d02cc1eccb7224c",
          "body": "Adds packages/observatory (private, unpublished): a monthly worker that probes a\nfixed panel of public hosts for PQC-hybrid key exchange (X25519MLKEM768) and\ncertificate posture, writing idempotent per-month results and a rollup to\nPostgres for the site's public /observatory page.\n\nReuses qProbe's u\n[…]\n. See docs/adr/0007.\n\nThe published packages are untouched: qprobe unchanged, zero-runtime-dependency\nand offline-boundary invariants still hold. pg is a devDependency of the\nobservatory package only.",
          "is_bot": false,
          "headline": "feat(observatory): internal PQC-readiness probe worker + ADR 0007",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "008333afb319a993c8b0f9d16c2277ae1b8da3dd",
          "body": null,
          "is_bot": false,
          "headline": "docs: add OpenSSF Best Practices passing badge (#31)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-24T02:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e68ab13934111dfc9c7fa5ee8ee5669979103093",
          "body": "- qprobe/mlkem768: replace biased modulo sampling with unbiased rejection\n  sampling for the throwaway probe key (js/biased-cryptographic-random)\n- sieve/protocol fromB64: replace the /=+$/ trailing-trim (O(n^2) on the\n  untrusted SUT response) with a linear scan (js/polynomial-redos)\n- mcp/http: di\n[…]\nests pass, including the property-based fuzz tests on the patched\nparsers. Trailing-slash trims on trusted config input (walk globs, agent\nbaseURL) are dismissed separately as not attacker-controlled.",
          "is_bot": false,
          "headline": "fix(security): resolve CodeQL findings in untrusted-input paths (#30)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:44:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e2991cc568d1225ae134a323a5dd68b8f731841",
          "body": "Add fast-check (dev-only) property tests that fuzz the parsers that consume\nattacker-controlled bytes: qProbe's TLS ServerHello / record / SSH KEXINIT /\nX.509 OID decoders, and Sieve's SUT response decoder. Each runs thousands of\nrandom inputs asserting the robustness contract (safe wrappers never t\n[…]\nhrow only their typed error, never a raw crash). All green,\nso the parsers hold; the tests stand as a regression guard and satisfy the\nOpenSSF Scorecard fuzzing criterion. No runtime dependency added.",
          "is_bot": false,
          "headline": "test: property-based fuzzing of the untrusted-input parsers (#29)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:17:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e769591f56bef2b4bb30401d7c29836b9b7cd7a5",
          "body": "* ci: add CodeQL SAST workflow (pinned)\n\n* ci: move packages:write to job scope (least-privilege top level)",
          "is_bot": false,
          "headline": "ci: add CodeQL SAST workflow (#28)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T08:51:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b346991abc40eef0fa3d13f84e5ba1b7d714bec4",
          "body": "Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.15 to 1.1.16.\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.16)\n\n---\nupdated-dependencies:\n- dependency-n\n[…]\non\n  dependency-version: 1.1.16\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump brace-expansion from 1.1.15 to 1.1.16 (#26)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6822434ebae7fcb5f96a416d96b3b5ae93e89f0",
          "body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.0.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n  dependency-version: 4.3.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump js-yaml from 4.2.0 to 4.3.0 (#20)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7918654d8e3073d5c90fbd44a22e06f2533ffe67",
          "body": "…thub.com)",
          "is_bot": false,
          "headline": "mirror container + npm packages to github packages (ghcr + npm.pkg.gi…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f18694debd4960bfb23da4bc2d37aebed4c52ff",
          "body": null,
          "is_bot": false,
          "headline": "bump docker image to @quantakrypto/mcp 0.5.2",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:12:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e67f89ca3f6145968b281c9e5c0b61ec4b97bf6",
          "body": null,
          "is_bot": false,
          "headline": "make mcp-registry publish idempotent (skip already-published version)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:01:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c6acc5d7ad2adc95434585c352818ec915af533",
          "body": "… em dash",
          "is_bot": false,
          "headline": "shorten root action description under 125 chars for marketplace, drop…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:31:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ac2632582f46ef0bd7e7bd118d7dbdc3632c178",
          "body": null,
          "is_bot": false,
          "headline": "add root action.yml so the action can list on the github marketplace",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:18:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc6f17d4e5de400c2534d595886273c850eedcf8",
          "body": null,
          "is_bot": false,
          "headline": "add 400x400 logo for marketplace/directory listings",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:15:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "192dd4c4153d21e79929d234b246198b855e62ce",
          "body": "…rver",
          "is_bot": false,
          "headline": "add root .mcp.json so cursor / open-plugins clients can import the se…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:58:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6264359813afcda7eb217ceca17e10130cba0414",
          "body": null,
          "is_bot": false,
          "headline": "shorten server.json description to fit the registry 100-char limit",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:38:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f134a0efdc802e5d96cce9717c9e86b2fc4bde1a",
          "body": "runs mcp-publisher with github-oidc auth, so the io.github.quantakrypto namespace\nis authorized by the org's own actions token. no keys, no interactive login.",
          "is_bot": false,
          "headline": "add workflow to publish server.json to the mcp registry via oidc",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6147d56bb6432648d494e1243ccad09bbe765c56",
          "body": "the mcp registry verifies npm ownership by reading an mcpName field from the\nPUBLISHED package.json, so we ship a tiny 0.5.2 that adds it plus a server.json\n(namespace io.github.quantakrypto/pqc-tools, npm stdio package + the hosted\nstreamable-http remote). metadata only, no code change. after this publishes,\nlisting on the registry is just: mcp-publisher login github && mcp-publisher publish.",
          "is_bot": false,
          "headline": "mcp 0.5.2: add mcpName + server.json for the official mcp registry",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dbf1446a1f4afaf6f8183cffebb8a9736899a5d",
          "body": "- tool input schemas: every array field (findings/verdicts, score_delta\n  before/after) now has an 'items' object schema instead of a bare type:array.\n  mcp inspectors flag the bare form ('missing items definition') and it drags\n  the tool-definition-quality score.\n- bump @quantakrypto/mcp to 0.5.1 + changelog. pairs with the already-landed\n  resources/templates/list fix (ed6ecfd). package-only patch — core/qscan/etc\n  stay 0.5.0 (unreleased work still parked under [Unreleased]).",
          "is_bot": false,
          "headline": "mcp 0.5.1: describe tool array items, cut patch release",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T02:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6ecfdf3452c0563624a260f2dd42ad784f851a",
          "body": "the server advertises the 'resources' capability, so spec-compliant clients\n(and mcp directory health checks like glama's inspector) call\nresources/templates/list during discovery. we only expose fixed-uri resources,\nno uri templates — but we were falling through to -32601 method-not-found, which\ntrips those clients. return an empty { resourceTemplates: [] } instead.\n\nadded a test asserting it succeeds empty rather than erroring.",
          "is_bot": false,
          "headline": "handle resources/templates/list instead of 404ing discovery",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T01:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c58bc376dd6bd3ac7bf54d9f04018b428b3863c",
          "body": "the recall/corpus benchmark ships fake dependency manifests (pom.xml, go.mod,\ncargo.toml, requirements.txt, csproj, gemfile, package.json...) with pinned deps\non purpose — thats the test data for crypto-dependency detection. when one of\nthose pinned versions gets a security advisory (jackson-databin\n[…]\ncore).\n\nscope each fixture ecosystem under packages/core/test/benchmark/** with\nlimit 0 + ignore '*' so dependabot leaves the test corpus alone. real dev deps\n(npm at /) and action SHAs are untouched.",
          "is_bot": false,
          "headline": "stop dependabot from failing on scanner test fixtures",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T00:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33b823beb2e8dbdce12efe3eef7f17de3f9ce252",
          "body": "glama (and other mcp hosts) sandbox the server: they run initialize +\ntools/list over stdio and expect a valid reply. this image installs the\npublished @quantakrypto/mcp and starts the stdio transport, so that check\npasses. base image + package are both pinned; glama.json claims the listing.\nbump both pins on release.",
          "is_bot": false,
          "headline": "add dockerfile + glama.json for mcp directory listing",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T17:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6cca652a7e4f929c7d81b31501bcf3a72690295",
          "body": "the hosted MCP gateway described as future work in HOSTING.md now exists and runs in\nproduction (quantakrypto/mcp-gateway, live at mcp.quantakrypto.com). add:\n- HOSTING.md: a reference-implementation callout up top + note on §3 that oauth 2.1 is\n  what the gateway implements (better-auth, 30-day tok\n[…]\nant to use it?\" callout with the `claude mcp add --transport http` command,\n  the content-only tool surface (fs/network tools withheld), and the gateway repo link.\ndocs only; no code/behaviour change.",
          "is_bot": false,
          "headline": "docs(mcp): point HOSTING + README at the now-live hosted gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T04:12:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a895f0a8b4e125f8df672a3d9e5e22b58d8ca612",
          "body": "…e dir as a module\n\n`node --test scripts/test/` (a directory arg) runs the tests on node 20, but on node\n21+ the runner resolves the path as a module and fails with \"Cannot find module\n.../scripts/test\", reddening build+test on the node 22 matrix leg. use\n`scripts/test/*.test.mjs` — shell-expanded to the literal file, exactly like the\nper-workspace `test/*.test.ts` scripts already do — which both node versions run.",
          "is_bot": false,
          "headline": "fix(test): explicit glob for test:scripts so node 22 doesn't treat th…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb3eecc23f4e8bba6916fbe8f29e843e28acb2ac",
          "body": "… EPIPE\n\nthe evidence signer (--sign/--timestamp) shells out via spawnSync with the payload on\nstdin. a command that exits before draining stdin (e.g. `false`) makes spawnSync\nsurface an EPIPE in res.error on linux — not macos — even though the child ran and\nreturned an exit status. the old code che\n[…]\nt a non-zero exit status (or terminating signal) FIRST; only fall back to\nres.error for a genuine spawn failure (e.g. ENOENT). deterministic across platforms.\naction dist re-bundled (it embeds qscan).",
          "is_bot": false,
          "headline": "fix(sign): report a signer's non-zero exit before an incidental stdin…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:38:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e397c9e6f06f7c6e190bcbd5857fea0e18907880",
          "body": null,
          "is_bot": false,
          "headline": "chore(action): re-bundle dist for the 0.5.0 release",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T15:46:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7917f17c20ee7287a9427f03eaf3a30e449e11b",
          "body": null,
          "is_bot": false,
          "headline": "docs: design for hosted OAuth-gated multi-tenant MCP gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T14:27:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ede29ffa0abc3c385a2ff18b246875433e7a9775",
          "body": "Per the cleanup request: remove point-in-time audit process artifacts and\nplanning docs, keep the enduring standards/reference/decision documentation, and\nadd a clear statement of what each library is for and what we're building toward.\n\nRemoved (in the previous commit): docs/audits/, docs/AUDIT.md,\n[…]\nMODEL (§8 controls table + the agent-line note refreshed to\nthe completed/fixed status), COMPLIANCE, CONFIG, SECURITY, CONTRIBUTING, and the\nGitHub templates — no broken links to removed files remain.",
          "is_bot": false,
          "headline": "docs: prune audit logs & plans; add OBJECTIVES; fix cross-references",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:54:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2d28b1b7a8290bf8271ff5e7074949e5f75bd0d",
          "body": "…leanup\n\nDetector fixes (each with a regression test; suite 1118 -> 1123):\n- proxy (H1/H2/L1/L2): the global marker gate was too narrow, silently dropping\n  canonical HAProxy (bind ssl crt, no crt-store) and Traefik (certFile/keyFile,\n  no certResolver) configs. Replaced with per-rule self-gating; E\n[…]\n, plans, and 0.4 runbook (docs/audits/,\nAUDIT.md, ROADMAP.md, how-to-test-0.4.md, superpowers/) — the enduring 'why' is\nin the ADRs; the new OBJECTIVES.md + index rewrite land in the follow-up commit.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in the 5 new detectors + begin docs c…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:48:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a36bd28b8537e7f6a5970afb5ef52124d4e5faf3",
          "body": "…/gRPC TLS, code-signing, weak-hash\n\nFresh coverage-gap research (3 Fable agents: assess + 2 web-research passes)\nidentified high-value PQC surfaces the scanner missed. Adds 5 detectors\n(47->52 detectors, 277->297 rules), scope kept to PQC + quantum-adjacent:\n\n- solidity: 14th source language pack (\n[…]\nassword hashing.\n\nEach with self-contained tests; benchmark F1=1.000, zero FP held. Wired into\nregistry + coverage constants + comment table; docs/README/ROADMAP/CHANGELOG\nupdated. Suite 1065 -> 1118.",
          "is_bot": false,
          "headline": "feat: 5 new detection surfaces — Solidity/blockchain, WebAuthn, proxy…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:33:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a17925014e030608025c7c20cabd453b0f736f65",
          "body": "…ant test\n\nAssessment (Fable) found two of my new packs under-reported HNDL, re-introducing\naudit bug P0-4: objc-seckey-ec and Dart ECKeyGenerator classified ambiguous EC\nkeygen as signature/ECDSA/hndl:false, while the whole fleet (java/python/c/swift/\ncloud-kms/ruby EC keygen) uses the HNDL-safe ke\n[…]\ns JWT coverage (added to JWT_HOST_EXTENSIONS); cloud-kms\nmasks comments so a commented-out YAML/JSON KeySpec can't fire; fixed the stale\n'JS/TS, Python, Go, Java' analyzable-languages doc in types.ts.",
          "is_bot": false,
          "headline": "fix: restore fleet HNDL convention for EC keygen + add catalog invari…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:22:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a1912474845689e60b42fe989db0b697d630c08",
          "body": "…n barrel\n\nstandardsReviewStatus is exported by standards.ts but NOT re-exported by the\npublic index.js barrel, so standards-check.mjs crashed on import ('does not\nprovide an export'). Because the standards-currency step is advisory\n(continue-on-error), the crash went unnoticed in CI. Import both symbols from\nthe standards.js subpath. Add a build-aware smoke test to the guard suite so an\nimport regression can't silently break this advisory gate again.",
          "is_bot": false,
          "headline": "fix(standards-check): import from standards.js subpath, not the froze…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:28:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f029ee1b20c3aa7ceb39ed62417f634b5d4076d",
          "body": "… + counts\n\n- ADR-0005 + THREAT-MODEL: F1 (blast-radius gate), F2 (system-role instruction/\n  data separation), F3 (--max-findings spend cap) are fixed in code — mark them\n  resolved instead of open, consistent with ROADMAP §1 (verified in loop.ts,\n  remediate-pipeline.ts, triage-run.ts).\n- COMPLIAN\n[…]\nd; 0.4.4 published) across COMPLIANCE,\n  VERSIONING, AUDIT, SUPPLY-CHAIN; test-count and 'supported vs benchmark-corpus\n  languages' wording refreshed; CHANGELOG Fixed section for the audit hardening.",
          "is_bot": false,
          "headline": "docs: reconcile ADR-0005/THREAT-MODEL (F1-F3 fixed), refresh versions…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:26:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adaaa20f803d3dbc7544f867636a133723cc2cf4",
          "body": "Detectors:\n- ssh-ca: add ssh-ca-config rule for TrustedUserCAKeys/HostCertificate/ssh-keygen\n  -s — the canonical CA deployment previously yielded ZERO findings (H6); stop\n  firing on program SOURCE files, so a vendored SSH lib's cert-type constant is\n  not flagged as live config (M4).\n- spire: matc\n[…]\n (file:src/a.ts#L3) (M7); the @id digest\n  includes triage status_notes so triaged/untriaged exports get distinct ids (L1).\n\nAll with regression tests. Suite 1052 -> 1063; benchmark F1=1.000, zero FP.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in detectors, CBOM, and VEX",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:21:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dc164c054073ff4e842c9c0b662a87cb8afd244",
          "body": "…3, M6)\n\nThe line-by-line + sequential-regex guard was bypassable by ORDINARY code, so\nADR-0005's 'enforced by CI' claim was false. Rewrite with a single-pass lexer\n(code/string/comment classification, recursing into template ${…} as code) and\nwhole-file scanning with index->line mapping:\n- C1: Pret\n[…]\n: auto-merge runs on comment-stripped text, so a // gh pr merge note no\n  longer false-positives; real exec('gh pr merge') strings still fire.\nRegression tests pin every bypass. Real repo stays clean.",
          "is_bot": false,
          "headline": "fix(guard): make offline-boundary bypass-resistant (audit C1-C3, H1-H…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f550df96e8091c3cfc0e60aad84039f8991ad156",
          "body": "ADR-0005's no-auto-merge rule covers workflows, not just package source. Extend\nthe guard to scan .github/workflows/*.yml for gh-pr-merge/--admin, with a\nknown-bad-fixture test. Workflows are currently clean.",
          "is_bot": false,
          "headline": "test: offline-boundary guard also scans workflows for auto-merge",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f206c81f351977ad552485b798cc645c743a7c7",
          "body": "Closes the post-1.0 coverage gaps:\n- objc-crypto (.m/.mm): Apple Security-framework SecKey* RSA/EC keygen, RSA/ECDSA\n  signing, RSA encryption, ECDH — gated off .h to avoid C/C++ overlap.\n- dart-crypto (.dart): pointycastle + package:cryptography RSA/ECDSA/ECDH/Ed25519/X25519.\n- dkim-crypto: classic\n[…]\n1.000, zero FP). Repointed the coverage-honesty tests\noff .m/.dart (now supported) to genuinely-unsupported Lua/Perl. Docs updated\n(core README language table, ROADMAP, CHANGELOG). Suite 1002 -> 1052.",
          "is_bot": false,
          "headline": "feat: coverage packs — Objective-C, Dart, DKIM, SSH-CA, SPIFFE/SPIRE",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a660c018f4ca964b0479c7b57cc04abedfece4",
          "body": "Adds scripts/check-offline-boundary.mjs — the gate ADR-0005 called for but that\n'did not exist yet'. It enforces the two-plane split by masked source scan:\ncore/mcp/sieve import no @quantakrypto/agent, make no outbound fetch/WebSocket/XHR\ncall, and read no LLM API key; qscan reaches the agent ONLY v\n[…]\n\n(e.g. core's redaction patterns). Wired into ci.yml + supply-chain-audit.yml;\nreject logic covered by known-bad fixtures in guards.test.mjs. ADR-0005 +\nROADMAP updated to reflect the gate now exists.",
          "is_bot": false,
          "headline": "feat: CI-enforce the ADR-0005 offline/agent boundary",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:38:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6511bcba849a3680b5720293ed71ecd9e612c59c",
          "body": "The CycloneDX CBOM labelled every asset 'algorithm'. Now each finding is\nclassified into its proper CycloneDX 1.6 assetType: X.509 findings ->\ncertificate; private/public key material -> related-crypto-material (typed\nprivate-key/public-key); TLS -> protocol (protocolProperties.type tls);\neverything\n[…]\nhanged algorithmProperties. Every asset\nstill carries quantumVulnerable/harvestNowDecryptLater. Completes the refinement\nthe CBOM audit deferred. Grouping is now (assetType, algorithm, discriminator).",
          "is_bot": false,
          "headline": "feat: refine CBOM assetType (certificate / key-material / protocol)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:32:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "691d02c5e8123ca734cf582d1b679e26dbcb50c2",
          "body": "Emit the quantum-readiness posture as an OpenVEX 0.2.0 document so it flows into\nthe same supply-chain pipeline that already ingests CVE-based VEX. One statement\nper rule (synthetic QK-<ruleId> vulnerability, since PQC findings have no CVE),\nevery affected file:line product, status 'affected', the r\n[…]\nnly an operator can attest a mitigation). Deterministic output.\n\nNew core API toOpenVex + OpenVex* types; qScan --format vex / renderVex; help,\nqscan README, and CHANGELOG updated. Surface 326 -> 331.",
          "is_bot": false,
          "headline": "feat: OpenVEX 0.2.0 export (--format vex)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:28:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c03731db39cbb43d8a91dc0b7ec1fcade55f747",
          "body": "Records the toolkit-export decision the audit flagged: the frozen external\nplugin point is the public Detector interface + scan({detectors}) / RuleMeta /\nFinding types; the lexical helpers (findingFromRule, eachMatch, comment maskers)\nstay INTERNAL so their signatures aren't frozen at 1.0 (exporting later is\nadditive). Clarifies the 'Adding a detector' guide is for in-repo contributors,\nresolving the read that external authors should import findingFromRule.",
          "is_bot": false,
          "headline": "docs: settle the detector plugin surface for the 1.0 freeze",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:13:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dc5241fdc20fdbb701c7939dce7b90e5f9dde79",
          "body": "… A.8.24\n\nROADMAP current-status count ~930 -> ~985 (historical audit figures left as-is).\nAdds a note to the A.8.24 evidence doc that verifyReadinessReport recomputes the\nintegrity hash to detect body tampering independently of the external signature.",
          "is_bot": false,
          "headline": "docs: refresh current test count + document verifyReadinessReport for…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:12:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0143fc1c1d9aa17d93a1eb66fa146aa91320db67",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): note verifyReadinessReport API + test-hardening pass",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4b541845dbed7653698d6405588f6744e1ad32e",
          "body": "The anthropic/openai adapters had happy-path + one HTTP-error test but nothing\nfor the transport failure modes a BYOK integration actually hits. Add, to both:\na timeout that aborts a hung request via the AbortSignal, a propagated network\n(fetch-rejection) error, and — the load-bearing BYOK security \n[…]\n that\nthe API key travels ONLY in its auth header (x-api-key / Bearer) and never\nleaks into the request URL or body. Also gives the openai adapter the HTTP-error\ntest it was missing. Suite 979 -> 986.",
          "is_bot": false,
          "headline": "test: agent BYOK adapter error paths + API-key-only-in-header invariant",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60d7d6a188b1244701529bc2d1d8b6c5b2d5020d",
          "body": "The supply-chain / output guards (check-zero-deps, check-action-pins,\nvalidate-sarif) run as standalone CI steps, so nothing proved their FAILURE\npath still works — a guard whose reject logic silently broke would leave CI\ngreen while the invariant eroded. Add scripts/test/guards.test.mjs with\nknown-\n[…]\nd it\nto match check-action-pins.mjs; the CLI behaviour is unchanged.\n\nWired via a new root `test:scripts` (node --test), chained into `npm test` so\nCI's existing test step covers it. Suite 951 -> 979.",
          "is_bot": false,
          "headline": "test: cover the CI guard scripts + fix validate-sarif import side effect",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:01:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d1e160d62558fc9b7f83a8e510e9c36c7eabb37",
          "body": "stateful-hbs was the only built-in detector with no dedicated unit test. Add\none covering each distinctive token (LMS/HSS/pyhsslms/XMSS/XMSSMT/xmss_keypair),\nthe SP 800-208 SHAKE256 + 192-bit parameter variants, the XMSS-vs-XMSSMT\nno-double-count boundary, the bare-word negative cases, and the load-bearing\ninvariant that these approved-but-stateful schemes are signature/medium and\nNEVER hndl:true (they are a state-management hazard, not broken crypto).",
          "is_bot": false,
          "headline": "test: unit-test the stateful-HBS detector (SP 800-208)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:56:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efc2dbdcef08ad212358bec2fc05ff285cda93fe",
          "body": "…eport\n\nSieve runner: add tests for the failure paths that had none — a SUT that never\nanswers rejects with TimeoutError (carrying request + timeoutMs); a SUT that\nexits mid-request, or fails to spawn, rejects the in-flight send with a\nSutCrashError that attaches the exit reason and captured stderr;\n[…]\nlicy verdicts, subject/tool metadata)\nwhile ignoring the excluded scan time / CBOM envelope / attestation block. Tests\ncover the classic 'edit the evidence' downgrade. Additive API surface (324->326).",
          "is_bot": false,
          "headline": "test: sieve runner crash/timeout coverage + evidence verifyReadinessR…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c69941bd3474c5d6a8ae4051fbbf2328128bbd5",
          "body": "The qscan CLI and MCP tool tests were written when core.scan was a stub and\ntolerated every exit code (`[OK, FINDINGS, ERROR].includes(code)`) or both\nbranches of an if/else. core is fully implemented and main()/scan_path drive\nthe genuine detector pipeline, so these now assert deterministic outcome\n[…]\nl temp fixtures: clean dir -> 0, RSA keygen -> 1/real finding,\nbaseline written, explain_finding returns real PQC remediation.\n\nAlso drops a stray U+200B from the maskBlockComments doc comment (lint).",
          "is_bot": false,
          "headline": "test: de-stub tautological CLI/MCP tests against the real scanner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:51:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0850f29d8420de99e0162e38d235792aad984ea",
          "body": "…/Azure KMS\n\nFrom the pre-1.0 audit's detection-gap list:\n\n- New xmldsig detector: classical XML-DSig / XML-Enc algorithm URIs (SAML SSO,\n  WS-Security) — rsa-sha*/dsa-sha*/ecdsa-sha* signatures and rsa-oaep key transport.\n- New pkcs11 detector: classical keys behind a PKCS#11 HSM/token — pkcs11-too\n[…]\ns. Messages/ids made cloud-generic.\n\nTwo new detectors registered (35 total). Regression tests (positives, negatives,\ndoc-suppression) throughout. Suite: 951 passing; all gates clean; benchmark 1.000.",
          "is_bot": false,
          "headline": "detectors: close coverage gaps — SAML/XML-DSig, PKCS#11, TDE, CDK/GCP…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:18:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f08bd446459fec5fadc1b66a23326be4f116bd5",
          "body": "The detector matched only the quoted-value SDK/JSON form (`KeySpec: \"RSA_2048\"`), so\nAWS CDK's enum-member form (`kms.KeySpec.RSA_2048`, `acm.KeyAlgorithm.EC_prime256v1`)\nand Pulumi's camelCase props (`customerMasterKeySpec: \"RSA_2048\"`) produced ZERO\nfindings — the dominant IaC idioms at AWS-heavy \n[…]\nth cases; also cover ACM `KeyAlgorithm`. The fast-reject\ngate is now case-insensitive. Terraform's snake_case spec still never double-counts\n(the regex has no underscore form). Regression tests added.",
          "is_bot": false,
          "headline": "cloud-kms: cover AWS CDK enum forms + Pulumi/camelCase key specs",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:08:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "204e89b43d5601bcb36688e258b5c7a4527ea816",
          "body": "…NCSC\n\nCloses the audit's #1 gap: the tool was hardcoded to a NIST/CNSA worldview, and its\n\"hybrids optional\" guidance was regime-WRONG for ANSSI/BSI (where hybridization is\nrequired), with no way to choose otherwise.\n\n- New core `StandardsProfile` layer (standards-profiles.ts): five cited, dated\n  \n[…]\ntionForProfile, formatProfileGuidance (frozen in the surface). A drift test\n  keeps profile params aligned with PQC_STANDARDS.\n\nDocs: CHANGELOG, ROADMAP, CLI help. Suite: 936 passing; all gates clean.",
          "is_bot": false,
          "headline": "feat: selectable standards regimes (--profile) — NIST/CNSA/BSI/ANSSI/…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:01:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cd17e3e04536d9daac70069d441a52e5826da8b",
          "body": "…E, ROADMAP)\n\n- CONFIG.md §5 was materially wrong: it implied the Action and MCP honor a\n  discovered config. Neither does (verified) — and that's deliberate: both run over\n  operator-uncontrolled trees, so a discovered config there would be a scan-integrity\n  bypass. Documented the trusted-local-op\n[…]\n/ 593 tests / 9 langs / 5\n  packages). Updated to v0.5.0 / ~930 tests / 11 langs / 7 packages, added qprobe,\n  and led with both benchmark numbers (curated 1.000 + real-world recall 0.84).\n\nDocs only.",
          "is_bot": false,
          "headline": "docs: correct drift the audit flagged (CONFIG security posture, READM…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:43:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe7869d5f84ab86a16113d399c66fa7520203d36",
          "body": "Nine symbols with zero cross-package consumers were being SemVer-frozen by accident\n— un-export them from @quantakrypto/core's index (they stay exported from their own\nmodules, so core's own tests still import them via ../src/): the parallel-scan\nchunk/merge helpers (mergeChunkResults, chunkByBytes)\n[…]\niewStatus, and isGeneratedPath. Public surface 324 → 315 symbols\n(core 139 → 130). Also refreshed the stale builtinDetectors doc comment (it\ndescribed ~10 detectors; there are 33). No behavior change.",
          "is_bot": false,
          "headline": "freeze-safety: trim internal plumbing from the public API surface",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:42:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26f4c7d57ff97958659fca364cf04db12e51c3c3",
          "body": "Two better-before-the-1.0-API-freeze items from the audit.\n\n- Block comments now mask correctly. `maskCommentLines` is line-only, so an\n  HCL/Bicep resource wrapped in `/* … */` had its inner lines left live (verified\n  FP: bicep-keyvault-rsa / tf-rsa-key fired inside a block comment). New\n  offset-\n[…]\nderReport` into async `runQscan`; the sync `commandSigner` still satisfies the\n  wider type. Added an async-signer test.\n\nRegression tests added. Suite: 928 passing; all gates clean (incl. api-check).",
          "is_bot": false,
          "headline": "freeze-safety: block-comment masking + async-capable EvidenceSigner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:55:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f10745a5ceb62aa36fd94b73fc39a4a12cf0ca84",
          "body": "…rity drift\n\nConfirmed, low-risk findings from the pre-1.0 four-lens audit.\n\nSecurity:\n- An AUTO-DISCOVERED quantakrypto.config.json can come from the scanned tree, so a\n  hostile repo could silently WEAKEN its own scan (disable rules, raise the\n  severity-threshold, exclude files → flip exit 1→0). \n[…]\n9/X448 low→medium (aligns with node/rust/go) — the same\n  primitive must not flip CI exit codes based on which surface uses it.\n\nRegression tests added throughout. Suite: 925 passing; all gates clean.",
          "is_bot": false,
          "headline": "audit fixes: config-trust warning, verified FPs, Swift coverage, seve…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:32:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc942ea12abfb232859dc81d3a782d2bde8e1a59",
          "body": "… were missing\n\nThe generator's declaration regexes didn't allow an `async` modifier, so\n`export async function` was skipped: runQscan, runSieve, runProbe (the main public\nentry points of qscan/sieve/qprobe) were absent from the frozen surface\n(docs/api-surface.json + API.md), and since `--check` sh\n[…]\nmplete freeze. Widen the modifier prefix to\n`(?:(?:declare|async|abstract)\\s+)*` in both collectExports regexes and docFor, and\nregenerate: 318 → 324 symbols.\n\nFound by the pre-1.0 test-quality audit.",
          "is_bot": false,
          "headline": "fix(api-gen): capture `export async function` — flagship entry points…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:20:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ac14568839a1dd17270a7472371ed2729127cde",
          "body": "Completes the A.8.24 evidence chain per ADR-0004: the tool orchestrates a signer,\nit implements no cryptography.\n\n- `qscan --format evidence --sign <cmd>` / `--timestamp <cmd>` pipe the report's\n  deterministic contentHash to an operator-provided external signer (openssl /\n  cosign / an RFC-3161 TSA\n[…]\ney.\n\nDocs: A.8.24 evidence doc §3.1 (interface + examples + verify recipe), ROADMAP,\nCHANGELOG. New public exports frozen in the API surface. Suite: 922 passing;\nlint/format/zero-deps/api-check clean.",
          "is_bot": false,
          "headline": "qscan: orchestrate external evidence signing (--sign / --timestamp)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:58:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b26eeed47f8420b8197ed0dfd91f4757f0a39d7",
          "body": "Promote the roadmap's i18n YAGNI note to a load-bearing Architecture Decision\nRecord: the human-facing report ships no message catalogs or locale machinery, and\nthe structured JSON/SARIF/CBOM output is the locale-neutral integration surface for\nany consumer that needs localized presentation. Framed as a YAGNI deferral, not a\npermanent refusal — reopening requires a new ADR with a concrete localized-consumer\nneed. Indexed in docs/adr/README.md and cross-linked from ROADMAP.md.",
          "is_bot": false,
          "headline": "docs: record report-is-English-only (no i18n) as ADR-0006",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:48:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2241e0ce3c675f512409caa3beb4563f916b8de8",
          "body": "…gate)\n\nCloses the VERSIONING.md 1.0 requirement of \"a documented, frozen public API\nsurface + a generated API reference\".\n\n- scripts/gen-api-reference.mjs (zero-dep) reads each package's public entry point\n  (following a single `export * from` hop) and emits docs/API.md (human reference)\n  and docs\n[…]\ngate bites: exit 1 on a dropped/added symbol, 0 when clean.\n- Documented the closed gate in VERSIONING.md, ROADMAP.md §1, and CHANGELOG.\n\nSuite: 916 passing; lint/format/zero-deps/api-check all clean.",
          "is_bot": false,
          "headline": "docs: freeze the public API surface + generate an API reference (1.0 …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:42:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32f90adc35068db7f330c1dbc27f061ad4aa962a",
          "body": "Bump every @quantakrypto/* package 0.4.4 → 0.5.0 (and the cross-package core/\nqprobe/qscan/agent pins + the two version.ts constants), and date the CHANGELOG\n[Unreleased] → [0.5.0].\n\nMinor bump under 0.x: this line adds new backward-compatible detector surfaces\n(Azure Bicep, Swift/CryptoKit, Pulumi)\n[…]\ntop of the round 3/4/5 detection-accuracy\nand engine-correctness fixes and the dead-code/API-surface cleanup. Suite at 916\npassing; precision/recall gates and the zero-FP negative set held throughout.",
          "is_bot": false,
          "headline": "release: v0.5.0",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:35:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a84af29921dea8a22a4d2a9ea292d6e861e3cab",
          "body": "Document the detector-precision hardening (comment/prose masking, cross-detector\ndouble-count deferrals, per-language FP/FN fixes), the engine correctness fixes\n(triage cap, CBOM merge/serial, readiness ordering, CLI ENOENT/--merge, sieve KAT\nskips), the dead-code removal and API-surface narrowing, the three new detector\nsurfaces (Azure Bicep, Swift/CryptoKit, Pulumi), and the real-repo validation +\ncorpus expansion. No previously-documented entries changed.",
          "is_bot": false,
          "headline": "docs: bring CHANGELOG [Unreleased] current through rounds 3–5",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89dc0598aa850fc1abdc0faade4e74c7d1d997c1",
          "body": "Three new detector surfaces (#5), each registered, unit-tested, and pinned by the\nbenchmark corpus:\n\n- bicep: Azure-native IaC (.bicep) — Microsoft.KeyVault `kty: 'RSA'/'EC'` keys\n  (gated to the Key Vault marker) and legacy `minimumTlsVersion: 'TLS1_0'/'TLS1_1'`.\n  Complements the existing ARM/Clou\n[…]\nhe `algorithm` value (RSA/ECDSA/ED25519).\n\nValidated against real OSS repos (gin, mux, flask, terraform-aws-eks, express,\nhelm/charts): zero false positives from the new detectors. Suite: 916 passing.",
          "is_bot": false,
          "headline": "detectors: add Azure Bicep, Swift/CryptoKit, and Pulumi coverage",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:27:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "877319c024ada9a572206b21d631e7e735e5a6db",
          "body": "Add 7 labeled corpus cases so the new coverage is pinned by the precision/recall\ngates (was invisible to the benchmark before):\n\nPositives:\n- GCP service-account JSON with a single-line \\n-escaped PKCS#8 key\n  (pem-pkcs8-private-key)\n- Terraform tls_private_key ED25519 (tf-ed25519-key)\n- Ansible com\n[…]\nide a Terraform description string\n- a PEM parser's paired header/footer string constants\n- commented-out PHP openssl crypto\n\nBenchmark: recall perfect, negative set strict (0 FP). Suite: 899 passing.",
          "is_bot": false,
          "headline": "benchmark: expand corpus for the round 3/4/5 detector surfaces",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:18:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "173d388feb0909804020bd84b4cfc5e14fa16bf5",
          "body": "Empirical validation (scanning real OSS repos — gin, flask, terraform-aws-eks,\nhelm/charts, express, gorilla/mux) surfaced one false-positive class: the\nssh-kex-classical / tls-classical-kex token rules fired on classical algorithm\nnames LISTED inside a Terraform/Packer `description = \"…\"` string (\"\n[…]\n is unaffected.\n\nThe rest of the sweep (~82 findings across 6 repos) was legitimate: real embedded\ntest certs/keys, real InsecureSkipVerify, and intentional classical-crypto deps.\n\nSuite: 899 passing.",
          "is_bot": false,
          "headline": "source: don't fire transport-KEX rules on algorithm names in a doc field",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:15:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5560caa06ce10bd7549191f63e322e85da7b595c",
          "body": null,
          "is_bot": false,
          "headline": "test: cover cosign sign-blob subcommand",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:44:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd2d584af6bebd42d5c95c1dfd1aba61db40b80a",
          "body": "Un-export 71 symbols across the workspace that are referenced only within their\nown declaring file — helpers, config/option interfaces, and protocol member types\nthat are not part of any package's public API (none re-exported by an index, none\nimported by another module or test). The build (declarat\n[…]\nrms nothing outside each file used them. Also delete mcp's JsonValue type,\nwhich turned out to be unused in-file once un-exported.\n\nNo behavior change. Suite: 894 passing; lint/format/zero-deps clean.",
          "is_bot": false,
          "headline": "narrow visibility of internal-only symbols; drop dead JsonValue type",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:43:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee573f43af9d63f682362c952fb06c4ce6c008df",
          "body": "- Delete three symbols with zero references anywhere: mcp `ToolInputSchema` (and\n  the now-unused JsonSchema import it existed to reference), sieve `SuccessResponse`,\n  and mcp `writeLine` (a redundant helper — runStdioServer writes inline).\n- cicd: reorder the cosign subcommand alternation so `sign\n[…]\nhortening its matchLength).\n- cloud-kms: drop the redundant `CustomerMasterKeySpec` fast-reject conjunct — the\n  string contains `KeySpec`, so the earlier check already covers it.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "remove dead code: unused exports, redundant helper, unreachable branches",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88e41c5b8c2bcf3b1229272ac8638c5592b610b8",
          "body": "- ansible: an openssl_privatekey `type: X448` now reports algorithm X448 instead\n  of the shared XDH rule's default X25519 label.\n- database: the sslmode prefilter now also admits the `ssl_mode` (underscore) form\n  the RE_WEAK_SSLMODE regex already matches — previously the gate silently blocked\n  every underscore-only file, making that regex branch dead.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "ansible/database: correct X448 label and align the sslmode prefilter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e97bc430284bbee36af0972ac10e55788f7a3487",
          "body": "An adversarial verification pass over the round 3 diff surfaced six regressions —\ninputs the test suite didn't cover. All fixed and pinned with tests.\n\n- pem: a long single-line, `\\n`-escaped key body (GCP service-account JSON,\n  `PRIVATE_KEY=\"…\\n…\"`) pushed the -----END marker past the 800-char win\n[…]\ny checked the immediate preceding\n  char, so a hardened full-suite exclusion (`HIGH:!ECDHE-RSA-RC4-SHA`) false-\n  positived. The lookbehind now walks back to the element boundary.\n\nSuite: 893 passing.",
          "is_bot": false,
          "headline": "fix regressions from the round 3 detector changes (verification pass)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:18:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ea64d43ce303938ecc04944562b4cbb461c0bb0",
          "body": "…m ids\n\n- c: the TLS-version rule now also matches TLSv1_1_method, the _client/_server\n  method variants, and SSLv2_method (previously only TLSv1_method/SSLv3_method).\n- openpgp: map the RFC 9580 (crypto-refresh) v6 public-key algorithm ids —\n  25 X25519, 26 X448 (key agreement, HNDL), 27 Ed25519, 28 Ed448 (signatures) —\n  so v6 keys classify precisely instead of falling back to a generic finding.\n\nSuite: 887 passing.",
          "is_bot": false,
          "headline": "c/openpgp: widen legacy TLS method forms and map RFC 9580 v6 algorith…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:59:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd436ab7aa4747d339a1378f1a837b8d78d3a3c6",
          "body": "…AT skips\n\nRound 3 audit follow-up on the non-detector engine (crashes, misleading output,\nsilent data loss).\n\n- triage: when capping to --max-findings, select the TOP by SEVERITY, not by\n  file-path order — a critical in a late-sorting file was dropped from triage and\n  sunk to the bottom of the re\n[…]\nT: an unverifiable vector (no seed/coins) is a SKIP, not a match — it no\n  longer inflates the \"N/N matched\" count into a false conformance pass.\n\nAdds regression tests throughout. Suite: 887 passing.",
          "is_bot": false,
          "headline": "engine: fix triage cap, CBOM merge crashes/serial, readiness order, K…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:57:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1384375b74d6a4cf3b88bccc48f95be282a877b9",
          "body": "Round 3 audit follow-up on the language packs.\n\nDouble-counts (deferrals added to jwtDetector, mirroring jose.ts):\n- A JWK object inlined in JS/TS/Py source no longer fires BOTH jwk-* and\n  jwt-classical-alg: jwtDetector skips alg tokens whose enclosing object has a\n  `\"kty\"` (jwk owns it).\n- A quot\n[…]\nx448::Secret`.\n- elixir: `:crypto.compute_key` (the (EC)DH agreement op); JOSE OKP X25519/X448 is\n  key agreement (HNDL), not an EdDSA signature.\n\nAdds regression tests throughout. Suite: 881 passing.",
          "is_bot": false,
          "headline": "source/language detectors: dedup double-counts and close FP/FN gaps",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:48:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a06ef9988a41ad4fd1d160e61d0270dbc3490bb",
          "body": "Round 3 audit follow-up on the infrastructure/config detectors. Root cause of the\nfalse positives: commentStyleForFile covers no config extension, so any config\ndetector that skipped maskCommentLines had zero comment protection.\n\nFalse positives (comment masking added; offsets preserved):\n- mesh, dn\n[…]\nno `\"` between the markers. This closes a self-regression where a PEM\nparser's paired header/footer string constants were accepted as a real key.\n\nAdds regression tests throughout. Suite: 870 passing.",
          "is_bot": false,
          "headline": "config detectors: comment masking for config formats, plus FN/FP fixes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:35:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99bdda97910f2a88d165573caf6d42cafc3cc709",
          "body": "… scoping\n\nRound 3 correctness pass. Fixes three P0 false-positive classes plus two\nregressions from the Round 2 JWK/JOSE work, and makes the shared object-scoping\nhelper string-aware.\n\n- comments: add PHP/.phtml/Scala (`.scala`/`.sc`) to the C-style comment table\n  and Ruby/Elixir (`.rb`/`.ex`/`.ex\n[…]\nlt marker.\n- keystore: accept BER indefinite-length PKCS#12 (0x80), emitted by NSS/Firefox\n  .p12 exports, alongside the long-form DER lengths.\n\nAdds regression tests for each fix. Suite: 862 passing.",
          "is_bot": false,
          "headline": "core: eliminate P0 false-positive classes and harden per-key JWK/JOSE…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:19:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4894d5ec21b5754b9fef379e7d2a6f167ec4d0d5",
          "body": "Binary pipeline (from the binary-audit): detect PKCS#12-format keystores named\n.jks/.keystore (keytool default since Java 9) and the 30 81 / 30 83 DER length\nforms; count latin1 keystore bytes at on-disk size (serial/parallel budget parity);\nisKeystorePath uses endsWith so bare dotfiles agree with t\n[…]\nssaging keeps only static-RSA\n(ECDHE owned by source); secrets defers PGP MESSAGE to pem; cfn ARM kty requires a\nMicrosoft.KeyVault marker. qprobe upgrade drops stale net listeners. Regression-tested.",
          "is_bot": false,
          "headline": "audit round 1 fixes: binary keystore/openpgp + detector precision",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:43:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "787b69f4e235f2268d6f2372e4915cd7d9781a51",
          "body": "…y_share\n\nThe TLS probe now sends a valid X25519MLKEM768 key_share (real X25519 public from\nnode:crypto + a valid-range ML-KEM-768 encapsulation key, ek||x25519 per\ndraft-ietf-tls-ecdhe-mlkem), so a supporting server selects 0x11EC directly in its\nServerHello — catching support-but-don't-prefer serv\n[…]\ntes the handshake): a ByteEncode12\nof in-range coefficients passes the encaps modulus check; the throwaway secret is\nnever computed. New mlkem768.ts, pure + unit-tested; fallback to x25519/HRR intact.",
          "is_bot": false,
          "headline": "qprobe: definitive hybrid negotiation via a well-formed ML-KEM-768 ke…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:19:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b0489d303f601b19ae20e3ca43b656825d09cc",
          "body": "Extend qprobe beyond TLS/SSH/SMTP to the other 'communication between things'\nendpoints, auto-selected by well-known port:\n- imap (:143) / pop3 (:110): line-based STARTTLS/STLS upgrade (generic\n  probeLineStartTls helper), then the same negotiated-parameter inspection.\n- postgres (:5432): send the 8\n[…]\n853) and IMAPS (:993) already work as direct-TLS probes.\nAll reuse the clean-close hang guard and cert/KEX classification. Pure builders +\nmock-server dance tested; postgres upgrade path e2e-verified.",
          "is_bot": false,
          "headline": "qprobe: add IMAP/POP3 STARTTLS and PostgreSQL SSLRequest probes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:12:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eab2897929c9c017cac4fc0bcad02bab6e79eabd",
          "body": "Single-source ownership for overlapping surfaces (audit precision findings):\n- source.ts owns SSH KexAlgorithms + ECDHE cipher tokens; removed the redundant\n  vpn net-sshd-classical-kex and mesh mesh-istio-classical-cipher rules.\n- cloudformation.ts owns crypto inside CFN/ARM templates: jwk + cloud-\n[…]\ntensions; usage-aware — a signing RSA/EC JWK is a signature\n  (hndl:false), encryption keys stay hndl:true.\n- jose: defer to jwk when the alg is inside a JWK object.\nRegression-tested; 837 tests pass.",
          "is_bot": false,
          "headline": "detectors: fix cross-detector double-counts + jwk sig/enc classification",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:05:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "caddec1ebc12b0afb5d24e180b86eb9fdf9912c2",
          "body": "Building on the byte-preserving binary read (keystore pipeline), extend it to\nOpenPGP keyrings (.gpg/.pgp/.kbx) and add an openpgp detector that parses packet\ntags: committed SECRET keys (sensitive; the sharp finding — a private key in a\nrepo), public keys, binary PGP-encrypted messages (PKESK → HND\n[…]\nPG\nkeyboxes. The public-key algorithm (RSA/DSA/ElGamal/ECDSA/EdDSA/ECDH) is read from\nthe packet body. Bounds-checked, fuzz-tested, pipeline-tested. Armored blocks stay\nwith the PEM/secrets detectors.",
          "is_bot": false,
          "headline": "detect binary OpenPGP key material and GnuPG keyboxes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:46:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d78c7dc8da074ebbed1e048fa318dc293b7a19c",
          "body": "Previously the networked probe_endpoint tool was refused unconditionally on the\nHTTP transport. Mirror the allowFs pattern instead: it is OFF by default on HTTP\nbut a trusted operator can enable it via QUANTAKRYPTO_MCP_ALLOW_NETWORK=1 (or the\nallowNetwork option). Threaded through HttpServerOptions/\n[…]\nlowFs, allowNetwork); startup banner shows probe:on/off.\nThe per-call ownership attestation and range refusal still apply on every transport.\nstdio (local, trusted) is unchanged. Docs + tests updated.",
          "is_bot": false,
          "headline": "mcp: make HTTP exposure of probe_endpoint an opt-in parameter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:19:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3f4017158dde01b2ba766b8f4d68809fc8b2be3",
          "body": "The scan pipeline hard-skipped binary files, so keystores (private key material)\nwere invisible. Add a keystore extension set (walk.ts isKeystorePath); the serial\nand parallel scan paths now read those extensions byte-preserving (latin1) and\nexempt them from the minified skip, so a new keystore dete\n[…]\nppet dropped). Other binaries stay skipped.\nPipeline-tested end to end. Also records this session's platform work (qscan\n--cbom --merge, MCP probe_endpoint, infra Action recipe, detector-audit fixes).",
          "is_bot": false,
          "headline": "detect committed cryptographic keystores (JKS/JCEKS/PKCS12/BKS)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:13:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a8f882d02dcd2c65f7d7d2672fb603411d5b78b0",
          "body": "Exposes qProbe's live-endpoint probing to AI agents. The qprobe plane is loaded via\ndynamic import so the server stays offline until the tool is invoked, and the\nownership attestation is enforced: probe_endpoint refuses unless i_own_this=true and\nrefuses CIDR/ranges (helpful message). Errored/unreac\n[…]\nRefused UNCONDITIONALLY on the HTTP\ntransport (new NETWORK_TOOL_NAMES) — a hosted MCP must not be an arbitrary-host\nprobing oracle. mcp now depends on @quantakrypto/qprobe (internal, zero-dep intact).",
          "is_bot": false,
          "headline": "mcp: add gated probe_endpoint tool (the only networked MCP tool)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "033ef7175b340a5f9d04ffdc0eb7dcfc7d8e2321",
          "body": "…+ combined CBOM)\n\nNew example workflow showing the infra line end to end: qScan gates code + IaC on\nevery change, a weekly scheduled job probes owned TLS/SSH endpoints with qProbe\n(behind a committed ownership manifest), and 'qscan --cbom --merge' fuses the scan\nand endpoint CBOMs into one combined code + infrastructure + wire bill of materials.\nAdds an owned-hosts.example.txt manifest template.",
          "is_bot": false,
          "headline": "action: infrastructure readiness recipe (IaC scan + scheduled qprobe …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7547aaa27f7d9b0bf665a3ae9e4028c9267a379",
          "body": "… CBOM\n\nThe mergeCboms engine (core/cbom-merge.ts) existed but was unwired. Add a\nrepeatable --merge <cbom.json> flag: with --cbom it reads external CBOMs (e.g. a\nqprobe endpoint CBOM) and merges them with the scan CBOM via CycloneDX, producing\none combined code + infrastructure bill of materials. Errors (missing file, non-\nJSON, non-CycloneDX) exit 2 with a clear message. Unit + e2e tested.",
          "is_bot": false,
          "headline": "qscan: wire mergeCboms — qscan --cbom --merge for combined code+infra…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b54926228119bb179b99de832497e133fb68e28",
          "body": "…(audit)\n\nAddresses infra config-detector audit findings (my detectors):\n- ReDoS: bound the unbounded [^\\n]* / [^\\n&|;]*? spans in messaging (ssl.protocol,\n  ssl.cipher.suites) and cicd (gpg, codesign) — they blew the repo's 2s budget on\n  adversarial input. Add config-detector inputs to redos.test.\n[…]\n(the cipher rule reports the KEX harvest).\n\n(vpn sshd double-count and the cross-detector / other-agent-owned findings are left\nfor coordination — the other agent is actively remediating those files.)",
          "is_bot": false,
          "headline": "detectors: fix ReDoS, comment-masking FPs, and cipher classification …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "febabf20e71da5450bee9ea810081ee43a7c23da",
          "body": "Two new config-scope detectors closing audited gaps:\n- supply-chain: Docker Content Trust (Notary v1), CNCF Notation, in-toto signing\n  (signature-side, gated to CI/Dockerfile/shell, comment-masked)\n- vault: native HashiCorp Vault HCL transit key types (rsa-*/ecdsa-p*/ed25519) and\n  pki role key_type; gated to .hcl + a transit/pki marker so it never overlaps the\n  terraform detector (.tf)\n\nAlso records the ansible/age detectors and the qprobe hang fix in CHANGELOG.",
          "is_bot": false,
          "headline": "detect supply-chain signing and native vault hcl crypto",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T14:03:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b4012b750a45f42998065c8852ac112d00198",
          "body": "Two new config-scope detectors closing audited gaps:\n- ansible: community.crypto openssl_privatekey/csr type RSA/ECC (comment-masked, gated)\n- age: committed AGE-SECRET-KEY-1 identity (X25519 private key) — worse than a\n  recipient; sensitive so the snippet is dropped. Closes the secrets-detector FN.",
          "is_bot": false,
          "headline": "detect ansible community.crypto keys and committed age identity keys",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T13:58:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 4,
      "commits_last_year": 254,
      "latest_release_at": "2026-07-23T05:57:13Z",
      "latest_release_tag": "v1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 2.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@quantakrypto/mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/mcp",
          "is_deprecated": false,
          "latest_version": "0.5.2",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2087,
          "first_published_at": "2026-06-22T13:45:51.286000Z",
          "latest_published_at": "2026-07-23T03:34:07.172000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@quantakrypto/core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/core",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2041,
          "first_published_at": "2026-06-22T13:45:42.443000Z",
          "latest_published_at": "2026-07-20T15:48:15.033000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/agent",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/agent",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 725,
          "first_published_at": "2026-07-03T12:32:08.324000Z",
          "latest_published_at": "2026-07-20T15:48:11.055000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qscan",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qscan",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1597,
          "first_published_at": "2026-06-22T13:45:48.337000Z",
          "latest_published_at": "2026-07-20T15:48:26.187000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/sieve",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/sieve",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1714,
          "first_published_at": "2026-06-22T13:45:45.289000Z",
          "latest_published_at": "2026-07-20T15:48:29.507000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qprobe",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qprobe",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 312,
          "first_published_at": "2026-07-19T08:12:24.768000Z",
          "latest_published_at": "2026-07-20T15:48:22.571000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 9,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/action/tsconfig.json",
        "packages/agent/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/qprobe/tsconfig.json",
        "packages/qscan/tsconfig.json",
        "packages/sieve/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
        "packages/core/test/benchmark/recall/go/go.mod",
        "packages/core/test/benchmark/recall/java/pom.xml",
        "packages/core/test/benchmark/recall/rust/Cargo.toml"
      ],
      "largest_source_bytes": 59062,
      "source_files_sampled": 454,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 2,
        "malicious_count": 0,
        "assessed_package": "npm:@quantakrypto/mcp@0.5.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qscan",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qprobe",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qprobe/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/agent",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@noble/post-quantum",
          "manifest": "validation/sieve-real-sut/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/agent",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/core",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qprobe",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qscan",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "anyhow",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ed25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "openssl",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rsa",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "x25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.3.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.2.1",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": false,
            "version": "2.17.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.jsonwebtoken:jjwt-api",
            "direct": false,
            "version": "0.11.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcpkix-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcprov-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.21.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "2.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/ciphers",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/curves",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/action",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/mcp",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/observatory",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/sieve",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^20.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.16",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "8.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash",
            "direct": false,
            "version": "^4.17.21",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-forge",
            "direct": false,
            "version": "^1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": false,
            "version": "^9.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "BouncyCastle.Cryptography",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "nuget"
          },
          {
            "name": "Newtonsoft.Json",
            "direct": false,
            "version": "13.0.3",
            "ecosystem": "nuget"
          },
          {
            "name": "System.IdentityModel.Tokens.Jwt",
            "direct": false,
            "version": "7.5.1",
            "ecosystem": "nuget"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "49.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fastapi",
            "direct": false,
            "version": "0.110.1",
            "ecosystem": "pypi"
          },
          {
            "name": "paramiko",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-client",
            "direct": false,
            "version": "0.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-settings",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyopenssl",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "structlog",
            "direct": false,
            "version": "24.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uvicorn",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ed25519",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "jwt",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "net-ssh",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "pg",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "puma",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rbnacl",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rspec-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rubocop",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 214,
        "direct_count": 6,
        "indirect_count": 208
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 17,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "leonacostaok",
          "commits": 248,
          "avatar_url": "https://avatars.githubusercontent.com/u/7293791?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "github-packages.yml",
        "mcp-registry.yml",
        "release.yml",
        "scorecard.yml",
        "supply-chain-audit.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 5,
            "reason": "badge detected: Passing",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool detected but not run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "52 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "409726240647384572233737a78f2a66bd9854d1",
        "ran_at": "2026-07-27T03:49:10Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T17:49:06Z",
      "oldest_open_prs": [
        {
          "number": 6,
          "created_at": "2026-07-15T07:31:01Z",
          "last_comment_at": "2026-07-23T10:16:56Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 7,
          "created_at": "2026-07-15T07:31:03Z",
          "last_comment_at": "2026-07-23T10:16:58Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 22,
          "created_at": "2026-07-21T13:54:49Z",
          "last_comment_at": "2026-07-23T10:17:00Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 23,
          "created_at": "2026-07-21T13:54:51Z",
          "last_comment_at": "2026-07-23T10:17:01Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 24,
          "created_at": "2026-07-21T13:54:52Z",
          "last_comment_at": "2026-07-23T10:17:03Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 25,
          "created_at": "2026-07-21T13:55:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 27,
          "created_at": "2026-07-23T00:48:07Z",
          "last_comment_at": "2026-07-23T10:17:05Z",
          "last_comment_author": "leonacostaok"
        }
      ],
      "last_merged_pr_at": "2026-07-26T17:47:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/quantakrypto/pqc-tools",
    "host": "github.com",
    "name": "pqc-tools",
    "owner": "quantakrypto"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 77,
        "vitality": 75,
        "community": 55,
        "governance": 43,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 254,
              "human_commit_share": 0.98,
              "days_since_last_push": 0,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "254 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 254
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 4,
              "latest_release_tag": "v1",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 2.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "4 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "forks": 0,
              "stars": 9,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "9 stars",
                "points": 14.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 8476
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "8,476 downloads/month across npm",
                "points": 52.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 8476,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "merged_prs": 17,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "17/31 decided PRs merged",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 17,
                      "decided": 31
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "quantakrypto",
              "public_repos": 4,
              "account_age_days": 34
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of quantakrypto",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "quantakrypto"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "13 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "crypto-agility",
                "cryptography",
                "harvest-now-decrypt-later",
                "infosec",
                "post-quantum",
                "pqc",
                "pqc-migration",
                "pqc-readiness",
                "pqcrypto",
                "q-day",
                "quantum",
                "quantum-readiness",
                "security-training",
                "encryption-strategy",
                "pqc-certification",
                "cbom",
                "mcp",
                "post-quantum-cryptography",
                "sbom",
                "nist"
              ],
              "has_wiki": false,
              "homepage": "https://quantakrypto.com/tools",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://quantakrypto.com/tools",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: Passing",
                "points": 1.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected but not run on all commits",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "52 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@quantakrypto/mcp@0.5.2 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@quantakrypto/mcp@0.5.2",
                  "assessed": 2
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 2,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 2,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.918,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/action/tsconfig.json",
                "packages/agent/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/qprobe/tsconfig.json",
                "packages/qscan/tsconfig.json",
                "packages/sieve/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
                "packages/core/test/benchmark/recall/go/go.mod",
                "packages/core/test/benchmark/recall/java/pom.xml",
                "packages/core/test/benchmark/recall/rust/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 59062,
              "source_files_sampled": 454,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/454 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 454,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T03:49:20.509862Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/quantakrypto/pqc-tools.svg",
  "full_name": "quantakrypto/pqc-tools",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.