Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.26.0 · метрики 1.13.0 · 2026-07-22 09:24 UTC

solvapay / solvapay-sdk

SolvaPay SDK

TypeScriptMIT★ 5 зірок⑂ 2 форкиз лист. 2025 р.Переглянути на GitHub ↗

solvapay/solvapay-sdk має індекс здоров’я 67 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (90/100), найнижчий — Sustainability & Governance (43/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

67
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

67
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

solvapayОрганізація
2 підписники6 публічних репозиторіївз трав. 2025 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
npmsolvapay1.2.01845642 дні тому
npm@solvapay/mcp0.2.81 629524 дні тому
npm@solvapay/auth1.1.07874736 днів тому
npm@solvapay/core1.2.03 309704 дні тому
npm@solvapay/init0.3.01822442 дні тому
npm@solvapay/next1.3.02 8611094 дні тому
npm@solvapay/react1.6.02 9521214 дні тому
npm@solvapay/server2.0.03 2421164 дні тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

90Відмінний · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
19.4/36Ритм комітів — 28/52 тижнів із комітами
18/18Обсяг комітів — 960 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year960
human_commit_share0,98
days_since_last_push0
active_weeks_last_year28
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 65 релізів
36/36Свіжість релізів — останній реліз 4 дн. тому
27/27Ритм релізів — реліз кожні ~1,7 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count65
latest_release_tag@solvapay/server@2.0.0
releases_from_tagsні
days_since_latest_release4
mean_days_between_releases1,7
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

54Помірний · 18% загального індексу
Як обчислюється оцінка
9.8/60Зірки — 5 зірок
0/25Форки — 2 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks2
stars5
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
18/18Настанови CONTRIBUTING
13.5/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductтак
has_pull_request_templateтак
Як обчислюється оцінка
55.7/80Щомісячні завантаження — 15 146 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagessolvapay, @solvapay/mcp, @solvapay/auth, @solvapay/core, @solvapay/init, @solvapay/next, @solvapay/react, @solvapay/server
dependents
ecosystemsnpm
total_downloads
monthly_downloads15 146
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

43У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
3.7/22.5Розподіл комітів — головний контриб’ютор — автор 84% комітів
5.4/13.5Широта контриб’юторів — 4 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled4
top_contributor_share0,835
Як обчислюється оцінка
0/46.8Вирішення issue — закрито 0% issue
26.7/38.3Прийняття PR — злито 209/299 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 1/13 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs209
open_issues2
closed_issues0
issue_closed_ratio0
closed_unmerged_prs90

Власність та опіка

42У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
3.4/25Охоплення власника — 2 підписників у solvapay
8.6/25Послужний список — 6 публічних репозиторіїв, вік облікового запису ~1 р.
Використані вхідні дані
followers2
owner_typeOrganization
is_verified
owner_loginsolvapay
public_repos6
account_age_days440

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 8 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 4 дн. тому
20/20Історія версій — 121 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagessolvapay, @solvapay/mcp, @solvapay/auth, @solvapay/core, @solvapay/init, @solvapay/next, @solvapay/react, @solvapay/server
ecosystemsnpm
any_deprecatedні
min_days_since_publish4

Інженерна якість

Чи наявні базові інженерні практики та документація?

80Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 3 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — .eslintrc.json, eslint.config.mjs
0/9.6Pre-commit-хуки
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 14 out of 14 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigтак
has_linter_configтак
has_precommit_configні

Документація

65Помірний
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
0/10Wiki
Використані вхідні дані
topics
has_wikiні
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

67Помірний · 16% загального індексу

Стан безпеки

59Помірний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — немає даних
2.5/2.5CI-Tests — 14 out of 14 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/13 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
6/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 61 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5,9
Виключено з оцінювання (немає даних або не застосовно): branch_protection, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
25/25Непрямі залежності без відомих сповіщень — жодна непряма залежність не має відомих сповіщень
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages14
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено з runtime-замиканням залежностей npm:solvapay@1.2.0 — тим, що тягне за собою встановлення опублікованого пакета, — 14 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

77Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — .cursor/rules/clean-code.mdc, .cursor/rules/mcp-apps-sdk.mdc, .cursor/rules/monorepo-versioning.mdc, .cursor/rules/tdd.mdc, .cursor/rules/typescript.mdc
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 91 з 98 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,929
agent_instruction_files.cursor/rules/clean-code.mdc, .cursor/rules/mcp-apps-sdk.mdc, .cursor/rules/monorepo-versioning.mdc, .cursor/rules/tdd.mdc, .cursor/rules/typescript.mdc
agent_instruction_max_bytes8 960
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — .eslintrc.json, eslint.config.mjs
11/11Статична перевірка типів — examples/chat-checkout-demo/tsconfig.json, examples/checkout-demo/tsconfig.json, examples/cloudflare-workers-mcp/tsconfig.json, examples/express-basic/tsconfig.json, examples/express-provider-linkage/tsconfig.json, examples/hosted-checkout-demo/tsconfig.json, examples/mcp-checkout-app/tsconfig.json, examples/mcp-oauth-bridge/tsconfig.json, examples/mcp-time-app/tsconfig.json, examples/nextjs-auth0/tsconfig.json, examples/shadcn-checkout/tsconfig.json, examples/shared/tsconfig.json, examples/supabase-edge-mcp-proxy/tsconfig.json, examples/supabase-edge-mcp/tsconfig.json, examples/tailwind-checkout/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/create-solvapay/templates/mcp/_base/tsconfig.json, packages/create-solvapay/templates/next-auth0/tsconfig.json, packages/create-solvapay/tsconfig.json, packages/demo-services/tsconfig.json, packages/init/tsconfig.json, packages/mcp-core/tsconfig.json, packages/mcp/tsconfig.json, packages/next/tsconfig.json, packages/react-supabase/tsconfig.json, packages/react/tsconfig.json, packages/server/tsconfig.json, packages/test-utils/tsconfig.json, tsconfig.json
10/10Відтворюване середовище — Dockerfile, lockfile
10/10Підтверджена практика роботи з агентами — 60 з останніх 100 комітів створено агентом або з його зазначенням
5/8Автоматизоване супроводження — автоматизацію залежностей налаштовано, але у вибірці комітів її не видно
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfilespackage-lock.json, pnpm-lock.yaml
has_dockerfileтак
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configsexamples/chat-checkout-demo/tsconfig.json, examples/checkout-demo/tsconfig.json, examples/cloudflare-workers-mcp/tsconfig.json, examples/express-basic/tsconfig.json, examples/express-provider-linkage/tsconfig.json, examples/hosted-checkout-demo/tsconfig.json, examples/mcp-checkout-app/tsconfig.json, examples/mcp-oauth-bridge/tsconfig.json, examples/mcp-time-app/tsconfig.json, examples/nextjs-auth0/tsconfig.json, examples/shadcn-checkout/tsconfig.json, examples/shared/tsconfig.json, examples/supabase-edge-mcp-proxy/tsconfig.json, examples/supabase-edge-mcp/tsconfig.json, examples/tailwind-checkout/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/create-solvapay/templates/mcp/_base/tsconfig.json, packages/create-solvapay/templates/next-auth0/tsconfig.json, packages/create-solvapay/tsconfig.json, packages/demo-services/tsconfig.json, packages/init/tsconfig.json, packages/mcp-core/tsconfig.json, packages/mcp/tsconfig.json, packages/next/tsconfig.json, packages/react-supabase/tsconfig.json, packages/react/tsconfig.json, packages/server/tsconfig.json, packages/test-utils/tsconfig.json, tsconfig.json
agent_commit_share0,6
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
54.9/55Керовані розміри файлів — 1/752 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes113 017
source_files_sampled752
oversized_source_files1
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalтак
api_schema_files

Ключові факти

5зірок GitHub
4контриб'юторів
960комітів за останні 12 місяців
0днів від останнього пушу
65релізів
1бас-фактор
2відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

Історія зірок і форків 5 ★ / 2 ⇿
5Зірки
2Форки
45Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

0123455222025-112026-022026-06
Мажорні 0Мінорні 0Патчі 0
OpenSSF Scorecard 5.9 / 10
5.9сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-22 09:24 UTC

10Binary-Artifactsno binaries found in the repo
н/дBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests14 out of 14 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/13 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
8Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities61 existing vulnerabilities detected
Прямі залежності 14
РеєстрПакетОбмеження версіїМаніфест
npm@solvapay/initworkspace:^packages/cli/package.json
npmzod^4.3.6packages/core/package.json
npm@solvapay/initworkspace:^packages/create-solvapay/package.json
npm@solvapay/coreworkspace:*packages/demo-services/package.json
npmchalk^5.6.2packages/init/package.json
npmopen^11.0.0packages/init/package.json
npm@solvapay/coreworkspace:*packages/mcp-core/package.json
npm@solvapay/authworkspace:*packages/next/package.json
npm@solvapay/coreworkspace:*packages/next/package.json
npm@solvapay/serverworkspace:*packages/next/package.json
npm@solvapay/coreworkspace:*packages/react/package.json
npm@stripe/react-stripe-js^6.0.0packages/react/package.json
npm@stripe/stripe-js^9.0.0packages/react/package.json
npm@solvapay/coreworkspace:*packages/server/package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Сповіщення про залежності 0

Встановлення npm:solvapay@1.2.0 тягне 14 пакетів, прямих і транзитивних: 0 мають відомі сповіщення, з них 0 — прямі залежності.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 8740,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "CSS": 85338,
        "HTML": 8887,
        "Shell": 18228,
        "JavaScript": 199861,
        "TypeScript": 3297297
      },
      "pushed_at": "2026-07-21T18:09:08Z",
      "created_at": "2025-11-01T09:48:15Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T12:49:41Z",
      "description": "SolvaPay SDK",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "www.solvapay.com",
      "name": "solvapay",
      "type": "Organization",
      "login": "solvapay",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/210835045?v=4",
      "created_at": "2025-05-08T09:22:09Z",
      "is_verified": null,
      "public_repos": 6,
      "account_age_days": 440
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "@solvapay/server@2.0.0",
          "kind": "other",
          "published_at": "2026-07-17T10:30:45Z"
        },
        {
          "tag": "@solvapay/next@1.3.0",
          "kind": "other",
          "published_at": "2026-07-17T10:30:42Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.8",
          "kind": "other",
          "published_at": "2026-07-17T10:30:39Z"
        },
        {
          "tag": "@solvapay/react@1.6.0",
          "kind": "other",
          "published_at": "2026-07-17T10:30:36Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.8",
          "kind": "other",
          "published_at": "2026-07-17T10:30:33Z"
        },
        {
          "tag": "@solvapay/core@1.2.0",
          "kind": "other",
          "published_at": "2026-07-17T10:30:30Z"
        },
        {
          "tag": "@solvapay/server@1.3.0",
          "kind": "other",
          "published_at": "2026-07-01T17:12:22Z"
        },
        {
          "tag": "@solvapay/core@1.1.1",
          "kind": "other",
          "published_at": "2026-07-01T17:12:19Z"
        },
        {
          "tag": "@solvapay/react@1.4.0",
          "kind": "other",
          "published_at": "2026-07-01T17:12:16Z"
        },
        {
          "tag": "@solvapay/next@1.2.1",
          "kind": "other",
          "published_at": "2026-07-01T17:12:13Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.7",
          "kind": "other",
          "published_at": "2026-07-01T17:12:10Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.7",
          "kind": "other",
          "published_at": "2026-06-15T12:21:22Z"
        },
        {
          "tag": "create-solvapay@0.5.0",
          "kind": "other",
          "published_at": "2026-06-15T12:21:19Z"
        },
        {
          "tag": "@solvapay/next@1.2.0",
          "kind": "other",
          "published_at": "2026-06-15T12:21:16Z"
        },
        {
          "tag": "@solvapay/react@1.3.0",
          "kind": "other",
          "published_at": "2026-06-15T12:21:13Z"
        },
        {
          "tag": "@solvapay/auth@1.1.0",
          "kind": "other",
          "published_at": "2026-06-15T12:21:10Z"
        },
        {
          "tag": "@solvapay/react-supabase@1.0.10",
          "kind": "other",
          "published_at": "2026-06-15T12:21:07Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.6",
          "kind": "other",
          "published_at": "2026-06-15T12:21:04Z"
        },
        {
          "tag": "@solvapay/server@1.2.1",
          "kind": "other",
          "published_at": "2026-06-15T12:21:01Z"
        },
        {
          "tag": "@solvapay/core@1.1.0",
          "kind": "other",
          "published_at": "2026-06-15T12:20:58Z"
        },
        {
          "tag": "@solvapay/next@1.1.0",
          "kind": "other",
          "published_at": "2026-06-09T13:12:21Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.5",
          "kind": "other",
          "published_at": "2026-06-09T13:12:18Z"
        },
        {
          "tag": "solvapay@1.2.0",
          "kind": "other",
          "published_at": "2026-06-09T13:12:15Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.6",
          "kind": "other",
          "published_at": "2026-06-09T13:12:12Z"
        },
        {
          "tag": "@solvapay/react@1.2.1",
          "kind": "other",
          "published_at": "2026-06-09T13:12:09Z"
        },
        {
          "tag": "@solvapay/init@0.3.0",
          "kind": "other",
          "published_at": "2026-06-09T13:12:06Z"
        },
        {
          "tag": "create-solvapay@0.4.0",
          "kind": "other",
          "published_at": "2026-06-09T13:12:03Z"
        },
        {
          "tag": "@solvapay/server@1.2.0",
          "kind": "other",
          "published_at": "2026-06-09T13:12:00Z"
        },
        {
          "tag": "create-solvapay@0.3.0",
          "kind": "other",
          "published_at": "2026-06-03T10:40:39Z"
        },
        {
          "tag": "@solvapay/server@1.1.1",
          "kind": "other",
          "published_at": "2026-05-27T16:10:49Z"
        },
        {
          "tag": "@solvapay/next@1.0.13",
          "kind": "other",
          "published_at": "2026-05-27T16:10:46Z"
        },
        {
          "tag": "@solvapay/init@0.2.0",
          "kind": "other",
          "published_at": "2026-05-27T14:00:22Z"
        },
        {
          "tag": "create-solvapay@0.2.0",
          "kind": "other",
          "published_at": "2026-05-27T14:00:19Z"
        },
        {
          "tag": "solvapay@1.1.0",
          "kind": "other",
          "published_at": "2026-05-27T14:00:16Z"
        },
        {
          "tag": "@solvapay/next@1.0.12",
          "kind": "other",
          "published_at": "2026-05-13T15:51:56Z"
        },
        {
          "tag": "@solvapay/server@1.1.0",
          "kind": "other",
          "published_at": "2026-05-13T15:51:53Z"
        },
        {
          "tag": "@solvapay/react@1.2.0",
          "kind": "other",
          "published_at": "2026-05-13T15:51:50Z"
        },
        {
          "tag": "@solvapay/react@1.1.4",
          "kind": "other",
          "published_at": "2026-05-05T09:04:40Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.5",
          "kind": "other",
          "published_at": "2026-05-05T09:04:37Z"
        },
        {
          "tag": "@solvapay/server@1.0.12",
          "kind": "other",
          "published_at": "2026-05-05T09:04:34Z"
        },
        {
          "tag": "solvapay@1.0.9",
          "kind": "other",
          "published_at": "2026-05-05T09:04:31Z"
        },
        {
          "tag": "@solvapay/next@1.0.11",
          "kind": "other",
          "published_at": "2026-05-05T09:04:29Z"
        },
        {
          "tag": "@solvapay/react@1.1.3",
          "kind": "other",
          "published_at": "2026-05-05T05:16:04Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.4",
          "kind": "other",
          "published_at": "2026-05-05T05:16:01Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.4",
          "kind": "other",
          "published_at": "2026-05-05T05:15:58Z"
        },
        {
          "tag": "@solvapay/next@1.0.10",
          "kind": "other",
          "published_at": "2026-04-29T06:44:41Z"
        },
        {
          "tag": "@solvapay/react@1.1.2",
          "kind": "other",
          "published_at": "2026-04-29T06:44:38Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.3",
          "kind": "other",
          "published_at": "2026-04-29T06:44:35Z"
        },
        {
          "tag": "@solvapay/core@1.0.9",
          "kind": "other",
          "published_at": "2026-04-29T06:44:32Z"
        },
        {
          "tag": "@solvapay/server@1.0.11",
          "kind": "other",
          "published_at": "2026-04-29T06:44:29Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.3",
          "kind": "other",
          "published_at": "2026-04-29T06:44:26Z"
        },
        {
          "tag": "@solvapay/react-supabase@1.0.9",
          "kind": "other",
          "published_at": "2026-04-28T22:51:12Z"
        },
        {
          "tag": "@solvapay/server@1.0.10",
          "kind": "other",
          "published_at": "2026-04-28T22:19:47Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.2",
          "kind": "other",
          "published_at": "2026-04-28T22:19:44Z"
        },
        {
          "tag": "solvapay@1.0.8",
          "kind": "other",
          "published_at": "2026-04-28T22:19:42Z"
        },
        {
          "tag": "@solvapay/auth@1.0.8",
          "kind": "other",
          "published_at": "2026-04-28T22:19:38Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.2",
          "kind": "other",
          "published_at": "2026-04-28T22:19:35Z"
        },
        {
          "tag": "@solvapay/next@1.0.9",
          "kind": "other",
          "published_at": "2026-04-28T22:19:33Z"
        },
        {
          "tag": "@solvapay/core@1.0.8",
          "kind": "other",
          "published_at": "2026-04-28T22:19:29Z"
        },
        {
          "tag": "@solvapay/react@1.1.1",
          "kind": "other",
          "published_at": "2026-04-28T22:19:27Z"
        },
        {
          "tag": "@solvapay/server@1.0.9",
          "kind": "other",
          "published_at": "2026-04-27T13:01:30Z"
        },
        {
          "tag": "@solvapay/next@1.0.8",
          "kind": "other",
          "published_at": "2026-04-27T13:01:27Z"
        },
        {
          "tag": "@solvapay/mcp-core@0.2.1",
          "kind": "other",
          "published_at": "2026-04-27T13:01:24Z"
        },
        {
          "tag": "@solvapay/react@1.1.0",
          "kind": "other",
          "published_at": "2026-04-27T13:01:21Z"
        },
        {
          "tag": "@solvapay/mcp@0.2.1",
          "kind": "other",
          "published_at": "2026-04-27T13:01:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2587031197e523bf5d20b114e2b5e9b648b82921",
          "body": "Dev",
          "is_bot": false,
          "headline": "Merge pull request #318 from solvapay/dev",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T12:48:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31338437ed01ee73511774b8ad82d767a9f0b476",
          "body": "docs: back-sync SDK guides from docs repo for the July 2026 release",
          "is_bot": false,
          "headline": "Merge pull request #317 from solvapay/docs/july-2026-back-sync",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T12:29:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9ccfa198557ea07ecfb27ac354df531735f205a",
          "body": "Brings docs/ in line with the published copies in the docs repo so\nscripts/sync-typescript-sdk-docs.ts doesn't clobber the newer content:\nadds the auto-recharge and business-checkout guides (lost in a branch\nswitch), the new @solvapay/next route helper sections in the Next.js\nguide, the customer.credit.auto_topup_failed webhook, the topup-first\nPAYG activation description, and a broken /oauth link fix.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: back-sync SDK guides from docs repo for the July 2026 release",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T12:21:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "17c1a59f32c9d2ce418afb543a3e551cf9f58314",
          "body": "Dev",
          "is_bot": false,
          "headline": "Merge pull request #315 from solvapay/dev",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:46:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40011996096d7d5c163700ebb4bd1d8b4eda2c39",
          "body": "chore: sync main into dev after version packages",
          "is_bot": false,
          "headline": "Merge pull request #316 from solvapay/jack/sync-main-into-dev",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:40:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5b0db3e37eabc350ea185de971b45b0eb20f05f",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync main into dev after version packages release",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:35:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b6db4d48b56eb83d1800e4b4c80d780ce3c86eb",
          "body": "…file\n\nfix: refresh lockfile after changeset version bumps",
          "is_bot": false,
          "headline": "Merge pull request #314 from solvapay/jack/fix-changeset-version-lock…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:28:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a76a925ff0f8bbed2887cf7e6b3fc17b3cd8a877",
          "body": "chore: version packages",
          "is_bot": false,
          "headline": "Merge pull request #313 from solvapay/changeset-release/main",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:27:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a80fe0d27d9dfa0e92378104d49fe57976ddabef",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: refresh lockfile after changeset version bumps",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:21:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1ad08c67090fc7db0d1639087cc4d4df0b7a27ab",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: refresh pnpm-lock.yaml after changeset version bumps",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:21:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "415c9a6d57c649a382d66990d5f69719a86317f3",
          "body": null,
          "is_bot": true,
          "headline": "chore: version packages",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T10:14:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d69fa6f97f71e4215986e24a38605d591c639d5f",
          "body": "Release: merge dev to main",
          "is_bot": false,
          "headline": "Merge pull request #303 from solvapay/dev",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T10:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4445804b005e141d43208a543c0fb025ae28081",
          "body": "fix(release): avoid false-major cascade from server 2.0.0 (widen mcp/mcp-core server peer)",
          "is_bot": false,
          "headline": "Merge pull request #311 from solvapay/jack/fix-server-peer-major-cascade",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T09:28:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8490d839df4fbe5165d8eb0c454cae3530509f3",
          "body": "…or cascade\n\n@solvapay/server takes a genuine major (2.0.0, auto-recharge break). @solvapay/mcp\nand @solvapay/mcp-core peer-depend on server via `workspace:^`, which publishes as\n`^1.4.0` and trips `onlyUpdatePeerDependentsWhenOutOfRange`, forcing false-major\nbumps onto mcp/mcp-core — and cascading \n[…]\nependency,\nand the lockfile does not track peer specifiers (no lockfile change).\n\nAlso documents this narrow exception in the versioning rules.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): widen mcp/mcp-core server peer range to avoid false-maj…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-17T09:20:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c722a7c85b1cbb661c8d02e81740de67cb12368",
          "body": "…ed-status\n\nchore(auto-recharge): drop completed status from generated types",
          "is_bot": false,
          "headline": "Merge pull request #310 from solvapay/jack/auto-recharge-drop-complet…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-15T13:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd0c354f8c003674e8572fee61e67458f4208b47",
          "body": "Align SDK types with the monthly spend cap model, which no longer uses a\nlifetime completed state. Also remove the unused root typecheck alias.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(auto-recharge): drop completed status from generated types",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-15T13:07:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ba2208727854fa95c84cf568453fb043f41597a5",
          "body": "…ace-maxrecharges-count-cap-with-monthly\n\nfeat(auto-recharge): replace maxRecharges with monthly spend cap (DEV-635)",
          "is_bot": false,
          "headline": "Merge pull request #309 from solvapay/jack/dev-635-auto-recharge-repl…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T20:50:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddb484d0522db0fd9e93e3d6470ebaf09a61973f",
          "body": "Remove the Advanced toggle so the max monthly spend field is visible whenever auto-recharge is enabled.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(react): always show monthly spend cap in auto-recharge form",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T20:45:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "384ea3d5e129fdb53e7de28be802eb1f262e81f4",
          "body": "Make the auto-recharge cache subscribable and invalidate it after balance\nreconciliation confirms a recharge so mounted hooks and MonthlySpend stay in sync.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(react): refresh monthly spend when auto-recharge lands server-side",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T13:25:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9c80ba2e542de2604d386380dab728d51c2ac75b",
          "body": "…es-count-cap-with-monthly\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-635-auto-recharge-replace-maxrecharg…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T10:14:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e6034f04061158157bb71db61329393ce6ed318f",
          "body": "Bring unified seller identity display resolver into July release review.\nResolve test conflicts by keeping July checkout assertions and the shared\nmockBalanceStatus helper defaults.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge branch 'dev' into feature/july-release-review",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T09:17:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "38f49297843a8fa559c0e6c3773c1c138b5ff649",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'dev' into feat/unify-seller-identity-display",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T09:08:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d29c7958f4a199c151076abff3f2e2f443c5bbf4",
          "body": "Make business name and tax ID optional in the shared schema, add an\neditable optional name field to embedded PaymentForm, and forward\ncustomerName through business-details attach.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(checkout): optional customer name and country-only business details",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T08:51:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2f0da5c3d7929b66cb006ecf59997362932cda2",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(examples): update checkout-demo next-env.d.ts route types path",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-14T07:21:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6195f3a97ff67755976d428b783b21222d49c1e6",
          "body": "Align checkout primitives with hosted frontend changes, fix tsconfig.build\nreferences across packages, and add scripts/typecheck-packages.ts.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(checkout): add stripe locale helper and package typecheck script",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-13T10:23:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1750fffce3f134042fa54158d6f7339f8f156e9f",
          "body": "Hide VAT/tax breakdown for non-business checkouts, update auto-recharge copy, and align section label typography with the July release review.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(checkout): hide tax summary for consumers and polish checkout UI",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-13T09:44:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b4c6a12efb74c7c0a41b7ef92cf7d49d05babccb",
          "body": "…635)\n\nExpose maxMonthlySpendMajor form helpers, i18n, init product picker support, and docs updates.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(react): add monthly spend cap UI to AutoRecharge primitive (DEV-…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-13T05:51:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5bb1081562f1b721265d11760bc427a1d0977d73",
          "body": "fix(react): re-activate PAYG plans after top-up (topup-first)",
          "is_bot": false,
          "headline": "Merge pull request #305 from solvapay/fix/payg-topup-first-activation",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-12T19:55:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee154547755df227f1e87d0af8f619df34af577f",
          "body": "Restore topup-first semantics: plan-step activatePlan returns topup_required\nat zero balance, and the active purchase materializes only after a successful\ntop-up. Updates docs, examples, and generated API types.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(react): re-activate PAYG plans after top-up (topup-first)",
          "author_name": "Tommy Berglind",
          "author_login": "tomber",
          "committed_at": "2026-07-12T19:48:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bce51e8fd57d2364798f1c44904f4d30268d7bb6",
          "body": "…cade\n\nfix(release): keep @solvapay/mcp-core on 0.2.x to avoid react/mcp major cascade",
          "is_bot": false,
          "headline": "Merge pull request #304 from solvapay/fix/mcp-core-patch-no-major-cas…",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-12T13:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "589d3ef2371307f819245c903549713c90fc5ee5",
          "body": "…or cascade\n\nShip the additive attach_business_details change as a patch (0.2.8) instead\nof a minor. On a 0.x peer, workspace:^ publishes as ^0.2.x, so a mcp-core\nminor (0.3.0) falls out of range and forces a major bump on @solvapay/react\nand @solvapay/mcp. A patch stays in range and cascades nothin\n[…]\n patch-only discipline for pre-1.0 peers in the\nmonorepo-versioning rule (keep workspace:^; take a minor/major only as a\ndeliberate 1.0 stabilization).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(release): keep @solvapay/mcp-core on 0.2.x to avoid react/mcp maj…",
          "author_name": "Tommy Berglind",
          "author_login": "tomber",
          "committed_at": "2026-07-12T13:39:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e23dcc00ddff28db665500ae902293d222441e70",
          "body": "Assert useAutoRecharge forwards the monthly cap and reloads spend fields, and\nalign test fixtures with monthlySpendMinor on auto-recharge configs.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(auto-recharge): cover maxMonthlySpendMajor save path for DEV-635",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-10T10:17:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0cbccce8bf294ad60563b48bae46a4339e310b4c",
          "body": "Align test fixtures with product status removal and discriminated union\nchecks after unify seller identity display work.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(tests): tighten business-details narrowing and balance mocks",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-09T20:32:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dc46d8e66750434cd3fcc19d9b246afa8289b063",
          "body": "…cap (DEV-635)\n\nUpdate client types, regenerate OpenAPI types, and document monthly spend cap\nsemantics with a major changeset for the breaking maxRecharges removal.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(server)!: replace auto-recharge maxRecharges with monthly spend …",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-09T19:35:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "985acd157bf830cd2748f80c3ab59210a455be17",
          "body": "…isplay\n\nIntroduce a canonical country-aware seller identity resolver in @solvapay/core\nand switch McpSellerDetailsCard to use it, replacing the internal react resolver.\nDisplay labels are now consistent: VAT number, EIN, Company number.\n\nPaired frontend PR: solvapay/solvapay-frontend (feat/unify-seller-identity-display)\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(core): add resolveSellerIdentityDisplay for unified seller tax d…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-09T16:03:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5049c22b30b401caad8495da6dc410e5543722db",
          "body": "…us-types\n\nchore(types): regenerate SDK types after product status removal (DEV-633)",
          "is_bot": false,
          "headline": "Merge pull request #300 from solvapay/fix/dev-633-remove-product-stat…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-09T07:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01fbb5cf8b32fe487853640dfcc3f8476b799979",
          "body": "…633)\n\nRegenerated generated.ts from the backend OpenAPI (product no longer exposes\nstatus; ?status= filter narrowed to active|inactive) and drop the stale\nstatus field from the listProducts client projection in client.ts.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate SDK types after product status removal (DEV-…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-09T06:55:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ac39e12aa0b824879df8f93b506bb7d321b700c8",
          "body": "…-in-seller-details-and-receipts-for\n\nfeat(dev-607): surface seller tax identity in MCP seller details card",
          "is_bot": false,
          "headline": "Merge pull request #299 from solvapay/jack/dev-607-display-vat-number…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T14:36:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6de3d97032329948f7aa6a50e433ab11ba3b0794",
          "body": "Extends the merchant contract with optional companyNumber, taxId, and\nvatNumber, renders country-smart tax rows in McpSellerDetailsCard with\nsemantic dl/dt/dd markup, and adds typed test fixtures.\n\nLinear: DEV-607\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(dev-607): surface seller tax identity in MCP seller card",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T14:30:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "535fb679e0956030d93de2953b4c776365e23bbb",
          "body": "Keep payment-confirmation gating and processTopupPayment reconciliation\nalongside business-details attach and tax summary from dev. Split\nbusiness-details PaymentForm tests into a dedicated file.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "merge: bring dev into dev-602-payment-confirmation-gating",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T12:23:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2dc24aa721c642fb210b71a5b0548e44ac14f7e7",
          "body": "…t-working-console-sdk\n\nfix: PAYG plan display in SDK components (DEV-545)",
          "is_bot": false,
          "headline": "Merge pull request #292 from solvapay/jack/dev-545-plan-activation-no…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T12:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd34734c82623cd298ceed8393aaa0211be1617b",
          "body": "Activation and MCP checkout integration tests exceed the default 5s\nbudget when turbo runs the full react suite in parallel.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(react): raise vitest timeout for parallel CI stability",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T12:05:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "02ff0c22f6886eb3c0b601f035ae90d41aaf8e51",
          "body": "…ole-sdk\n\nResolve conflicts from DEV-483 business checkout landing on dev:\nkeep Request-based route handlers, typed readServerResource bootstrap\nshape, and plan_pro stub amount (2900).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-545-plan-activation-not-working-cons…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T11:40:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e2cd9bda9dee33e68f6bba7098f7d683e6f1b742",
          "body": "…urchases-in-stripe-credit-checkout\n\nfeat(core): business details validation for credit checkout (DEV-483)",
          "is_bot": false,
          "headline": "Merge pull request #273 from solvapay/jack/dev-483-support-business-p…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T11:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "542d127a5b821a5d8acb14daec696b0dfffa61c6",
          "body": "Keep deprecated StripePaymentFormWrapper, PaymentForm.CardElement, and\nconfirmPayment card-element mode so DEV-602 ships without a breaking major.\nVersion packages to @solvapay/react@1.5.0 and @solvapay/server@1.4.0.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(DEV-602): restore Card Element shims and ship react 1.5.0 as minor",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-08T08:15:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0c54556e306feb1d61a7714672d03477a4311772",
          "body": "…ripe-credit-checkout",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-483-support-business-purchases-in-st…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-07T12:41:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5515d3e1f90741c321e332858ff8586349ee11d",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: add changeset for PAYG plan display fix (DEV-545)",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-07T12:37:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5cfc92e6751f9a343a497f911a822e9725c5c83e",
          "body": "That changeset targeted solvapay-backend and solvapay-frontend, which are\nnot packages in this workspace and broke `pnpm changeset status`.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: remove invalid credit-purchase-vat changeset from SDK",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-07T12:37:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a0c3259f1350c6ff9eacaaffc9419d4e0818e53d",
          "body": "Add shared test helpers and migrate stale balance/provider stubs so\ntest:types passes after the payment-confirmation gating changes.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(DEV-602): align react test mocks with BalanceStatus types",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-07T11:20:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "853e13f3c9636f520735ed52762de6f63d72a567",
          "body": "Remove legacy Card Element surface, treat processing as pending, resume\n3DS/redirect returns via paymentIntentReturn, and wire /process processing\nstatus through confirm and reconcile paths.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(DEV-602): gate payment success on real confirmation in SDK",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-07T11:07:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "362c19a38202b51e2305f36ae9be22de30d38fe3",
          "body": "Aligns example stub plans with the generated ListPlansResponse type required by tailwind-checkout builds.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add hidden field to stub plan fixtures after dev merge.",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-06T11:44:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f52588d45a732cd79f85dbccc2b1b20edb090bf5",
          "body": "…ole-sdk\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-545-plan-activation-not-working-cons…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-06T11:26:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0dfdeacfb977e941273b5a54f864d4ee750a92a5",
          "body": "…r-auto-recharge-top-ups-july-1-release\n\nDocument auto-recharge and credit top-ups in SDK guides (DEV-606)",
          "is_bot": false,
          "headline": "Merge pull request #294 from solvapay/jack/dev-606-update-sdk-docs-fo…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-06T10:11:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267449a8d5cad7bc17337dee5fdd5530da6ab827",
          "body": "…e-top-ups-july-1-release",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-606-update-sdk-docs-for-auto-recharg…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-06T10:04:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbede63d6d66466e396e9080b6af4d984525db4b",
          "body": "…pe-credit-checkout.\n\nKeep 483 OpenAPI-generated types (business-details endpoint and taxBehavior plan\nfields) while taking dev auto-merges elsewhere.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge origin/dev into jack/dev-483-support-business-purchases-in-stri…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-06T08:18:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c05ac8444b986bc37d77ed2061eb10662f894777",
          "body": "…plans\n\nchore(DEV-561): regenerate SDK types with plan hidden flag",
          "is_bot": false,
          "headline": "Merge pull request #296 from solvapay/feat/dev-561-hidden-enterprise-…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-05T19:36:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31ab2ac93bc8009702e2e03d696f431dd297c110",
          "body": "Regenerate generated.ts from the updated OpenAPI spec: plan `selectable`\nwas renamed to `hidden` on the SDK plan/product schemas.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate SDK types with plan `hidden` (DEV-561)",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-05T19:30:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "af1fd14d6fad98ddfacb71dc171a2906b4702c65",
          "body": "Adds the `selectable` field to the generated plan/product response and request\ntypes, reflecting the hidden enterprise-plans work in the backend.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate SDK types with plan `selectable` (DEV-561)",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-05T18:08:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "743af96a5cd3b94fffbe60a9fe37a96aaba4ae2c",
          "body": "…-latest\n\nchore(types): regenerate server SDK types from updated OpenAPI (DEV-610)",
          "is_bot": false,
          "headline": "Merge pull request #295 from solvapay/chore/dev-610-update-openapi-to…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-04T11:55:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8c64232d62631ac6c171d683f3c78136d23d467",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate types after includeFree param fix (DEV-610)",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-04T11:48:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f81ccd8eba9de0ecc8b26770456c533de659b042",
          "body": "…penapi-to-latest\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n# Conflicts:\n#\tpackages/server/src/types/generated.ts",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/dev' into chore/dev-610-update-o…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-04T11:42:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "96a33574e0ae75277d7b079cf3490c401e0b2618",
          "body": "…DEV-610)\n\nRegenerated src/types/generated.ts against the corrected /v1/sdk/* spec.\nAdds newly-typed request/response schemas (unknown payloads 15→11, typed\n50→58, component schemas 45→48). Build + DTS generation pass.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate server SDK types from updated OpenAPI spec (…",
          "author_name": "Ingemar Svensson",
          "author_login": "ingemar-svensson",
          "committed_at": "2026-07-04T11:39:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "421e9a4faff124b05ace54d5f13d9fec9bfa5bfd",
          "body": "Drop legacy CardElement border CSS and use semantic markup in StyledTopupForm.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(checkout-demo): remove duplicate Stripe frame on top-up form",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T15:18:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4750fac1b8017120bfc57fb61dfbf87eed704595",
          "body": "…ripe-credit-checkout",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-483-support-business-purchases-in-st…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T14:10:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "357e39d91c5e2f77254b8bd97e202c98cf35be97",
          "body": "Add TopupForm, AutoRecharge, useTopup, and useAutoRecharge to the React guide and wire topup_required to the new helpers in purchase management.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Document auto-recharge and credit top-ups in SDK guides (DEV-606).",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T14:07:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "126067ca88fe08a8c46bc91401da58ac0acea894",
          "body": "…-change-the-top-up-amount-on-the-hosted\n\nDEV-604: Preserve top-up amount on Change amount (MCP)",
          "is_bot": false,
          "headline": "Merge pull request #293 from solvapay/jack/dev-604-add-a-back-link-to…",
          "author_name": "Jack Smith Insulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T13:23:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6efed7c75589c11f3976109ccccdf4056dcd69e1",
          "body": "Lift useTopupAmountSelector state out of AmountPicker so the MCP top-up\nflow keeps the entered amount after Change amount. Also update checkout-demo\nto match the current configToAutoRechargeInput API.\n\nDEV-604\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(mcp-topup): preserve amount when returning via Change amount",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T13:18:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e39d077b00c78d8b424e232eab2253e925fb8506",
          "body": "…(DEV-545)\n\nRegression tests assert zero-amount usage-based active purchases flow through\ncheckPurchase into activePurchase, useUsage, and CurrentPlanCard.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test: guard PAYG activation parity in SDK provider and display hooks …",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T12:29:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "01d81218912e2ee97373c356c4f2f5503196c8ea",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: remove stale tsconfig project references (DEV-545)",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-03T07:56:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b37ecc112dfc6919e246cf6dd49b2f8fdf943605",
          "body": "Widen McpAppBootstrapLike.readServerResource so ext-apps App is assignable at\n<McpApp app={app} /> mount sites, pin next@16.2.7 via pnpm overrides to dedupe\npatch-version type conflicts in shared example route handlers, and align stub\ncheckout demo types with current @solvapay/server contracts.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: restore full monorepo build after ext-apps and Next.js type drift",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-02T12:22:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8227da1ebb7a5c7c4ad6d21dd0ab65af4642d595",
          "body": "Update CurrentPlanCard, useUsage, and UsageMeter so credit-based usage plans render the real plan name and balance rather than an unlimited label.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: show PAYG plan name and credit usage instead of unlimited (DEV-545)",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-02T11:59:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "96338f083bf74cced6e2ca10fb6d942844520b26",
          "body": "Align shared demo stub with server client type after dev merge.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(examples): include amount in stub createPaymentIntent response",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-02T07:55:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1bfafc7cd50a69c7d615128cc535cdd73cf787d1",
          "body": null,
          "is_bot": false,
          "headline": "chore: merge main into dev for release PR sync",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-02T07:53:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79d642e90d007cd91e818e16e802774eef65b940",
          "body": "…ripe-credit-checkout\n\nResolve package.json conflict: keep business-details build entrypoints and dev test scripts.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Merge branch 'dev' into jack/dev-483-support-business-purchases-in-st…",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-02T07:50:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "215d045f4eca57154a5f2ebf821a8612be8f7bff",
          "body": "Share business-details and tax-summary compound parts across PaymentForm,\nTopupForm, and MCP checkout views; attach business details on submit with\nVAT breakdown. Add BUSINESS_COUNTRY_OPTIONS in core so country selects show\nfull English names while submitting ISO codes.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(react): add B2B checkout fields, tax summary, and country labels",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-01T21:34:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "99e291f65fb1dfb5c9880232f6ce3c5577df8542",
          "body": "chore: version packages",
          "is_bot": false,
          "headline": "Merge pull request #289 from solvapay/changeset-release/main",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T17:08:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e4d6a4b38f4bf22b5893260e9b3cf0424042256",
          "body": null,
          "is_bot": true,
          "headline": "chore: version packages",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T17:03:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a6fda7fee6eb6635d6a1b9499e9d765b7800e99",
          "body": "…elease\n\nchore: sync dev with main after release merge",
          "is_bot": false,
          "headline": "Merge pull request #288 from solvapay/chore/sync-dev-with-main-post-r…",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:57:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5329244b3c9d310ea4da42d713aa939b0d1f35bb",
          "body": "fix(ci): install Deno from GitHub releases in publish workflows",
          "is_bot": false,
          "headline": "Merge pull request #287 from solvapay/fix/deno-github-release-install",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:56:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79d7def652d0bb513002301c555d9b84ca507b95",
          "body": "setup-deno intermittently fails with TypeError: fetch failed when\ndownloading from dl.deno.land. Install v2.7.4 directly from GitHub\nreleases instead, which stays reachable from GitHub Actions runners.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(ci): install Deno from GitHub releases in publish workflows",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:51:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f8fa54da332bac57ef626bed6904a8a4256e621f",
          "body": "fix(ci): pin Deno 2.7.4 and enable cache in publish workflows",
          "is_bot": false,
          "headline": "Merge pull request #286 from solvapay/fix/deno-ci-setup",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:49:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89eb993ed9b4c24cda25a5779a2e1afb379d4120",
          "body": "setup-deno with v2.x intermittently fails to fetch the latest binary\n(TypeError: fetch failed), blocking both preview and stable publishes.\nPin a known version and cache the install for reliable CI.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(ci): pin Deno 2.7.4 and enable cache in publish workflows",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:43:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "71a63103ac05962af97e35ff33c974007aba914b",
          "body": "Release: dev → main",
          "is_bot": false,
          "headline": "Merge pull request #274 from solvapay/dev",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:42:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85ea9ce9fbd8a783398e0ef06a96c85ac6f90346",
          "body": "chore: sync dev with main",
          "is_bot": false,
          "headline": "Merge pull request #285 from solvapay/chore/sync-dev-with-main",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:33:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba963e8d67d1a67c996489b79ef0cdda6dc74f08",
          "body": null,
          "is_bot": false,
          "headline": "chore: merge main into dev for release PR sync",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:28:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d78f4fce7873b08c7e716b3d87dfdb40b354660d",
          "body": "…-test\n\nfix(core): resolve @solvapay/core from source in conversion-contract tests",
          "is_bot": false,
          "headline": "Merge pull request #284 from solvapay/bugfix/core-conversion-contract…",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:24:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdf3b93892971f5a251795a45b277a4c7390cd1b",
          "body": "…vapay/solvapay-sdk into bugfix/core-conversion-contract-test",
          "is_bot": false,
          "headline": "Merge branch 'bugfix/core-conversion-contract-test' of github.com:sol…",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:19:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43651fe9e56b86ff701774a88237de0355ae0bea",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(workflows): list build before test in publish-preview steps",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:13:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fb8aa4c11a68fd383d8035e6060a74c453d7e839",
          "body": "…tests\n\nThe e2e test imports react credit-estimation helpers that depend on\n@solvapay/core dist exports. Add a vitest alias to ./src, stop masking\ntest failures with exit 0, and align publish workflows to build before\ntest like CI.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(core): resolve @solvapay/core from source in conversion-contract …",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:13:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c901dc0c2b2eb3baf0d24c8847265a5ce716703b",
          "body": "chore(plans): remove implemented and stale SDK cursor plans",
          "is_bot": false,
          "headline": "Merge pull request #283 from solvapay/chore/remove-stale-cursor-plans",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:09:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca020d170ac3fb4d9df793c7a0551ae3558931f1",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(workflows): list build before test in publish-preview steps",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:07:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b30c8061aedb2a63a5908aa6b4ef095303d55b59",
          "body": "…tests\n\nThe e2e test imports react credit-estimation helpers that depend on\n@solvapay/core dist exports. Add a vitest alias to ./src, stop masking\ntest failures with exit 0, and align publish workflows to build before\ntest like CI.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(core): resolve @solvapay/core from source in conversion-contract …",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:07:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "49d1b9fae7a850ef0a50927c6a9750e922957e6d",
          "body": "Drop completed or superseded plan files so .cursor/plans/ only tracks\nactive work.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(plans): remove implemented and stale SDK cursor plans",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T16:01:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9d56d96960a66eb52cda327298559234cbca4278",
          "body": "fix(supabase-edge-mcp): disable Deno dependency age gate for @preview CI",
          "is_bot": false,
          "headline": "Merge pull request #282 from solvapay/bugfix/deno-preview-gate",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T15:59:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a00795dafbc5874efd47d1a63c67162ad56f5402",
          "body": "Deno 2.9+ rejects npm packages published within 24h by default, which\nblocked the publish-preview workflow when resolving mutable @preview tags.\nSet minimumDependencyAge to 0, disable lockfile on the validate import map,\nand remove stale lockfiles before deno check.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(supabase-edge-mcp): disable Deno dependency age gate for @preview CI",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T15:53:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5177c2c2a8f51a1118c7a79dfaf44f206667a28d",
          "body": "fix(server): align multi-currency integration tests with payment intent contract",
          "is_bot": false,
          "headline": "Merge pull request #281 from solvapay/bugfix/integration-test-fixes",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T14:47:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de0f1acb8c05f5602aef1cd3bbadf0d24b7b2516",
          "body": "…nt contract\n\nAssert presentment charges via originalAmount and expose amount, currency,\nand exchangeRate on createPaymentIntent responses to match backend FX behavior.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(server): align multi-currency integration tests with payment inte…",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T14:41:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "29f744cc8f1aa2a13850f20ebf323325bba0f14a",
          "body": "Delete four plans whose work has fully landed in the codebase:\n- unify_checkout_primitive: useCheckoutFlow hook + CheckoutSteps parts shipped.\n- first_class_chatbot_sdk: payable.gate, createAnonymousAuthAdapter,\n  buildPaywallGate all present.\n- fix_topup_confirmation_dismiss: usePaywallResolver payment_required\n  balance branch shipped.\n- amount-pills-rounded-rect: 8px radius applied to both stylesheets.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(plans): remove implemented SDK cursor plans",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T13:37:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "046877f427688cd44f3d9e63930718c34a11c6ba",
          "body": "Delete three plans that no longer match the codebase:\n- extend-payment-confirmation-timeouts: PaymentForm confirmation logic\n  was refactored into reconcilePayment; the CONFIRMATION_TIMEOUT_MS\n  target no longer exists.\n- mcp_multi-product_investigation: deferred investigation referencing\n  sibling \n[…]\niscontinued MCP Pay surface.\n- mcp-agent-sdk-review: never started; points at a building-mcp-app\n  skill dir that was consolidated into create-mcp-app.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(plans): remove drifted SDK cursor plans",
          "author_name": "Tommy",
          "author_login": "tomber",
          "committed_at": "2026-07-01T13:36:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c2aa8a5fae1aee0923462c180ee48da3b771e5f",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(core): extend business details types for B2B checkout tax flows",
          "author_name": "jacksmithinsulander",
          "author_login": "jacksmithinsulander",
          "committed_at": "2026-07-01T05:50:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 65,
      "commits_last_year": 960,
      "latest_release_at": "2026-07-17T10:30:45Z",
      "latest_release_tag": "@solvapay/server@2.0.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 28,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 1.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "solvapay",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/solvapay",
          "is_deprecated": false,
          "latest_version": "1.2.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 56,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 184,
          "first_published_at": "2026-03-28T18:03:23.034000Z",
          "latest_published_at": "2026-06-09T13:11:58.405000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 42
        },
        {
          "name": "@solvapay/mcp",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/mcp",
          "is_deprecated": false,
          "latest_version": "0.2.8",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 52,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1629,
          "first_published_at": "2026-04-24T22:28:56.139000Z",
          "latest_published_at": "2026-07-17T10:30:27.767000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@solvapay/auth",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/auth",
          "is_deprecated": false,
          "latest_version": "1.1.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 47,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 787,
          "first_published_at": "2025-11-02T21:40:36.568000Z",
          "latest_published_at": "2026-06-15T12:20:55.864000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 36
        },
        {
          "name": "@solvapay/core",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/core",
          "is_deprecated": false,
          "latest_version": "1.2.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 70,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3309,
          "first_published_at": "2025-10-29T11:41:15.855000Z",
          "latest_published_at": "2026-07-17T10:30:28.056000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@solvapay/init",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/init",
          "is_deprecated": false,
          "latest_version": "0.3.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 24,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 182,
          "first_published_at": "2026-05-24T07:28:35.851000Z",
          "latest_published_at": "2026-06-09T13:11:57.608000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 42
        },
        {
          "name": "@solvapay/next",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/next",
          "is_deprecated": false,
          "latest_version": "1.3.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 109,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2861,
          "first_published_at": "2025-11-02T21:40:43.898000Z",
          "latest_published_at": "2026-07-17T10:30:28.020000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@solvapay/react",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/react",
          "is_deprecated": false,
          "latest_version": "1.6.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 121,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2952,
          "first_published_at": "2025-10-29T11:41:18.073000Z",
          "latest_published_at": "2026-07-17T10:30:28.510000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@solvapay/server",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@solvapay/server",
          "is_deprecated": false,
          "latest_version": "2.0.0",
          "repository_url": "https://github.com/solvapay/solvapay-sdk",
          "versions_count": 116,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3242,
          "first_published_at": "2025-10-29T11:41:20.681000Z",
          "latest_published_at": "2026-07-17T10:30:28.305000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 5,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-05-03",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": {
        "days": [
          {
            "date": "2025-11-09",
            "count": 1
          },
          {
            "date": "2025-11-18",
            "count": 1
          },
          {
            "date": "2026-04-27",
            "count": 2
          },
          {
            "date": "2026-05-09",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 5,
        "total_stars": 5
      },
      "open_issues_and_prs": 19
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/chat-checkout-demo/tsconfig.json",
        "examples/checkout-demo/tsconfig.json",
        "examples/cloudflare-workers-mcp/tsconfig.json",
        "examples/express-basic/tsconfig.json",
        "examples/express-provider-linkage/tsconfig.json",
        "examples/hosted-checkout-demo/tsconfig.json",
        "examples/mcp-checkout-app/tsconfig.json",
        "examples/mcp-oauth-bridge/tsconfig.json",
        "examples/mcp-time-app/tsconfig.json",
        "examples/nextjs-auth0/tsconfig.json",
        "examples/shadcn-checkout/tsconfig.json",
        "examples/shared/tsconfig.json",
        "examples/supabase-edge-mcp-proxy/tsconfig.json",
        "examples/supabase-edge-mcp/tsconfig.json",
        "examples/tailwind-checkout/tsconfig.json",
        "packages/auth/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/create-solvapay/templates/mcp/_base/tsconfig.json",
        "packages/create-solvapay/templates/next-auth0/tsconfig.json",
        "packages/create-solvapay/tsconfig.json",
        "packages/demo-services/tsconfig.json",
        "packages/init/tsconfig.json",
        "packages/mcp-core/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/next/tsconfig.json",
        "packages/react-supabase/tsconfig.json",
        "packages/react/tsconfig.json",
        "packages/server/tsconfig.json",
        "packages/test-utils/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 113017,
      "source_files_sampled": 752,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        ".cursor/rules/clean-code.mdc",
        ".cursor/rules/mcp-apps-sdk.mdc",
        ".cursor/rules/monorepo-versioning.mdc",
        ".cursor/rules/tdd.mdc",
        ".cursor/rules/typescript.mdc"
      ],
      "agent_instruction_max_bytes": 8960
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 14,
        "malicious_count": 0,
        "assessed_package": "npm:solvapay@1.2.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@solvapay/init",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "zod",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@solvapay/init",
          "manifest": "packages/create-solvapay/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@solvapay/core",
          "manifest": "packages/demo-services/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "chalk",
          "manifest": "packages/init/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.6.2"
        },
        {
          "name": "open",
          "manifest": "packages/init/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.0.0"
        },
        {
          "name": "@solvapay/core",
          "manifest": "packages/mcp-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@solvapay/auth",
          "manifest": "packages/next/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@solvapay/core",
          "manifest": "packages/next/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@solvapay/server",
          "manifest": "packages/next/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@solvapay/core",
          "manifest": "packages/react/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@stripe/react-stripe-js",
          "manifest": "packages/react/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "@stripe/stripe-js",
          "manifest": "packages/react/package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "@solvapay/core",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 17,
        "merged_prs": 209,
        "open_issues": 2,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 90
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "tomber",
          "commits": 771,
          "avatar_url": "https://avatars.githubusercontent.com/u/3495976?v=4"
        },
        {
          "type": "User",
          "login": "jacksmithinsulander",
          "commits": 119,
          "avatar_url": "https://avatars.githubusercontent.com/u/106760392?v=4"
        },
        {
          "type": "User",
          "login": "ingemar-svensson",
          "commits": 29,
          "avatar_url": "https://avatars.githubusercontent.com/u/62596262?v=4"
        },
        {
          "type": "User",
          "login": "dhruv-sanan",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/162488342?v=4"
        }
      ],
      "contributors_sampled": 4,
      "top_contributor_share": 0.835
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish-preview.yml",
        "publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".eslintrc.json",
        "eslint.config.mjs"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "14 out of 14 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/13 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 8,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "61 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2587031197e523bf5d20b114e2b5e9b648b82921",
        "ran_at": "2026-07-22T09:24:01Z",
        "aggregate_score": 5.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T12:51:53Z",
      "oldest_open_prs": [
        {
          "number": 102,
          "created_at": "2026-04-16T16:29:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 186,
          "created_at": "2026-05-10T12:30:33Z",
          "last_comment_at": "2026-06-01T18:07:20Z",
          "last_comment_author": "tomber"
        },
        {
          "number": 193,
          "created_at": "2026-05-11T12:35:53Z",
          "last_comment_at": "2026-05-11T12:35:54Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 207,
          "created_at": "2026-05-23T20:13:38Z",
          "last_comment_at": "2026-05-23T20:13:39Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 213,
          "created_at": "2026-05-25T13:35:26Z",
          "last_comment_at": "2026-05-25T13:35:27Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 214,
          "created_at": "2026-05-25T13:35:55Z",
          "last_comment_at": "2026-05-25T13:35:56Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 258,
          "created_at": "2026-06-10T21:59:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 272,
          "created_at": "2026-06-22T15:26:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 276,
          "created_at": "2026-06-29T09:25:14Z",
          "last_comment_at": "2026-07-08T12:45:54Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 277,
          "created_at": "2026-06-29T09:29:39Z",
          "last_comment_at": "2026-07-08T12:46:05Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 278,
          "created_at": "2026-06-29T09:34:39Z",
          "last_comment_at": "2026-07-08T12:45:50Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 279,
          "created_at": "2026-06-29T09:35:16Z",
          "last_comment_at": "2026-07-08T12:45:53Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 280,
          "created_at": "2026-06-29T09:35:52Z",
          "last_comment_at": "2026-07-08T12:46:02Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 290,
          "created_at": "2026-07-01T22:45:39Z",
          "last_comment_at": "2026-07-01T22:45:39Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 291,
          "created_at": "2026-07-01T22:45:43Z",
          "last_comment_at": "2026-07-01T22:45:45Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 301,
          "created_at": "2026-07-09T07:32:40Z",
          "last_comment_at": "2026-07-09T07:48:05Z",
          "last_comment_author": "cursor"
        },
        {
          "number": 312,
          "created_at": "2026-07-17T09:44:30Z",
          "last_comment_at": "2026-07-17T09:44:31Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-07-17T12:48:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 167,
          "created_at": "2026-05-03T22:03:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 187,
          "created_at": "2026-05-10T20:09:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/solvapay/solvapay-sdk",
    "host": "github.com",
    "name": "solvapay-sdk",
    "owner": "solvapay"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 67,
        "vitality": 90,
        "community": 54,
        "governance": 43,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 90,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "commits_last_year": 960,
              "human_commit_share": 0.98,
              "days_since_last_push": 0,
              "active_weeks_last_year": 28
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "28/52 weeks with commits",
                "points": 19.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 28
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "960 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 960
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 65,
              "latest_release_tag": "@solvapay/server@2.0.0",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 1.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "65 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 65
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 4,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 4 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 54,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 2,
              "stars": 5,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 70,
            "inputs": {
              "packages": [
                "solvapay",
                "@solvapay/mcp",
                "@solvapay/auth",
                "@solvapay/core",
                "@solvapay/init",
                "@solvapay/next",
                "@solvapay/react",
                "@solvapay/server"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 15146
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "15,146 downloads/month across npm",
                "points": 55.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 15146,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 4,
              "top_contributor_share": 0.835
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 84% of commits",
                "points": 3.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 84
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "4 contributors",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 27,
            "inputs": {
              "merged_prs": 209,
              "open_issues": 2,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 90
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "209/299 decided PRs merged",
                "points": 26.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 209,
                      "decided": 299
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "solvapay",
              "public_repos": 6,
              "account_age_days": 440
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of solvapay",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "solvapay"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "6 public repos, account ~1 yr old",
                "points": 8.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 6
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "solvapay",
                "@solvapay/mcp",
                "@solvapay/auth",
                "@solvapay/core",
                "@solvapay/init",
                "@solvapay/next",
                "@solvapay/react",
                "@solvapay/server"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "121 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 121
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc.json, eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.json, eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "14 out of 14 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 67,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "14 out of 14 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "61 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:solvapay@1.2.0 runtime dependency closure — what installing the published package pulls in — 14 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:solvapay@1.2.0",
                  "assessed": 14
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 14,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 14,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 77,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.929,
              "agent_instruction_files": [
                ".cursor/rules/clean-code.mdc",
                ".cursor/rules/mcp-apps-sdk.mdc",
                ".cursor/rules/monorepo-versioning.mdc",
                ".cursor/rules/tdd.mdc",
                ".cursor/rules/typescript.mdc"
              ],
              "agent_instruction_max_bytes": 8960
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursor/rules/clean-code.mdc, .cursor/rules/mcp-apps-sdk.mdc, .cursor/rules/monorepo-versioning.mdc, .cursor/rules/tdd.mdc, .cursor/rules/typescript.mdc",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursor/rules/clean-code.mdc, .cursor/rules/mcp-apps-sdk.mdc, .cursor/rules/monorepo-versioning.mdc, .cursor/rules/tdd.mdc, .cursor/rules/typescript.mdc"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "91 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 91,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "examples/chat-checkout-demo/tsconfig.json",
                "examples/checkout-demo/tsconfig.json",
                "examples/cloudflare-workers-mcp/tsconfig.json",
                "examples/express-basic/tsconfig.json",
                "examples/express-provider-linkage/tsconfig.json",
                "examples/hosted-checkout-demo/tsconfig.json",
                "examples/mcp-checkout-app/tsconfig.json",
                "examples/mcp-oauth-bridge/tsconfig.json",
                "examples/mcp-time-app/tsconfig.json",
                "examples/nextjs-auth0/tsconfig.json",
                "examples/shadcn-checkout/tsconfig.json",
                "examples/shared/tsconfig.json",
                "examples/supabase-edge-mcp-proxy/tsconfig.json",
                "examples/supabase-edge-mcp/tsconfig.json",
                "examples/tailwind-checkout/tsconfig.json",
                "packages/auth/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/create-solvapay/templates/mcp/_base/tsconfig.json",
                "packages/create-solvapay/templates/next-auth0/tsconfig.json",
                "packages/create-solvapay/tsconfig.json",
                "packages/demo-services/tsconfig.json",
                "packages/init/tsconfig.json",
                "packages/mcp-core/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/next/tsconfig.json",
                "packages/react-supabase/tsconfig.json",
                "packages/react/tsconfig.json",
                "packages/server/tsconfig.json",
                "packages/test-utils/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.6,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc.json, eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.json, eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/chat-checkout-demo/tsconfig.json, examples/checkout-demo/tsconfig.json, examples/cloudflare-workers-mcp/tsconfig.json, examples/express-basic/tsconfig.json, examples/express-provider-linkage/tsconfig.json, examples/hosted-checkout-demo/tsconfig.json, examples/mcp-checkout-app/tsconfig.json, examples/mcp-oauth-bridge/tsconfig.json, examples/mcp-time-app/tsconfig.json, examples/nextjs-auth0/tsconfig.json, examples/shadcn-checkout/tsconfig.json, examples/shared/tsconfig.json, examples/supabase-edge-mcp-proxy/tsconfig.json, examples/supabase-edge-mcp/tsconfig.json, examples/tailwind-checkout/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/create-solvapay/templates/mcp/_base/tsconfig.json, packages/create-solvapay/templates/next-auth0/tsconfig.json, packages/create-solvapay/tsconfig.json, packages/demo-services/tsconfig.json, packages/init/tsconfig.json, packages/mcp-core/tsconfig.json, packages/mcp/tsconfig.json, packages/next/tsconfig.json, packages/react-supabase/tsconfig.json, packages/react/tsconfig.json, packages/server/tsconfig.json, packages/test-utils/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/chat-checkout-demo/tsconfig.json, examples/checkout-demo/tsconfig.json, examples/cloudflare-workers-mcp/tsconfig.json, examples/express-basic/tsconfig.json, examples/express-provider-linkage/tsconfig.json, examples/hosted-checkout-demo/tsconfig.json, examples/mcp-checkout-app/tsconfig.json, examples/mcp-oauth-bridge/tsconfig.json, examples/mcp-time-app/tsconfig.json, examples/nextjs-auth0/tsconfig.json, examples/shadcn-checkout/tsconfig.json, examples/shared/tsconfig.json, examples/supabase-edge-mcp-proxy/tsconfig.json, examples/supabase-edge-mcp/tsconfig.json, examples/tailwind-checkout/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/create-solvapay/templates/mcp/_base/tsconfig.json, packages/create-solvapay/templates/next-auth0/tsconfig.json, packages/create-solvapay/tsconfig.json, packages/demo-services/tsconfig.json, packages/init/tsconfig.json, packages/mcp-core/tsconfig.json, packages/mcp/tsconfig.json, packages/next/tsconfig.json, packages/react-supabase/tsconfig.json, packages/react/tsconfig.json, packages/server/tsconfig.json, packages/test-utils/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "60 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 60,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 113017,
              "source_files_sampled": 752,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/752 source files over 60KB",
                "points": 54.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 752,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T09:24:20.855665Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/solvapay/solvapay-sdk.svg",
  "full_name": "solvapay/solvapay-sdk",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.26.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.