公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-30 06:10 UTC

AlexanderMattTurner / agent-sanitizer

Strip common prompt injection surfaces.

JavaScript · PythonApache-2.0★ 2 星标⑂ 1 复刻始于 2026年6月在 GitHub 上查看 ↗

AlexanderMattTurner/agent-sanitizer 的健康指数为 100 分中的 58 分,处于「中等」区间。 其得分最高的类别是AI Readiness(78/100),最低的是Community & Adoption(39/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

58
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

58
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

4 关注者13 个公开仓库始于 2026年6月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

70良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
4.2/36提交节奏 — 52 周中有 6 周有提交
18/18提交量 — 最近一年 606 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year606
human_commit_share0.8
days_since_last_push0
active_weeks_last_year6

发布纪律

88优秀
评分方式
16.2/27有发布版本 — 63 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 0 天前
27/27发布节奏 — 约每 0.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count63
latest_release_tagv2.5.0
releases_from_tags
days_since_latest_release0
mean_days_between_releases0.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

39存在风险 · 占总体的 18%
评分方式
0/60星标 — 2 个星标
0/25复刻 — 1 个复刻
0/15关注者 — 0 位关注者
所用输入
forks1
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

77良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
38.7/80月度下载量 — npm, pypi 合计每月 797 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesagent-sanitizer, agent-sanitizer
dependents
ecosystemsnpm, pypi
total_downloads
monthly_downloads797
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

49存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
7.3/22.5提交分布 — 头号贡献者编写了 68% 的提交
2.7/13.5贡献者广度 — 2 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled2
top_contributor_share0.676
评分方式
11.7/46.8议题解决 — 25% 的议题已关闭
35.3/38.3PR 接受 — 已裁定的 PR 中 167/181 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/14 approved changesets -- score normalized to 0
所用输入
merged_prs167
open_issues6
closed_issues2
issue_closed_ratio0.25
closed_unmerged_prs14
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
5/25所有者影响力 — AlexanderMattTurner 有 4 位关注者
8.7/25既往记录 — 13 个公开仓库,账户约 0 年
所用输入
followers4
owner_typeOrganization
is_verified
owner_loginAlexanderMattTurner
public_repos13
account_age_days58
评分方式
25/25已发布且可解析 — npm, pypi 上有 2 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 12 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesagent-sanitizer, agent-sanitizer
ecosystemsnpm, pypi
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

72良好 · 占总体的 20%

工程实践

94优秀
评分方式
24/24CI 工作流 — 37 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.mjs
9.6/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

40存在风险
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

56中等 · 占总体的 16%

安全态势

45存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/14 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.5
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages473
unassessed_packages1
affected_by_severitymoderate 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 473 个已解析依赖与 OSV 比对。 有 1 项无法评估——没有已解析的版本、生态系统不受支持,或超出所报告的软件包清单。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

78良好 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 80 次人类提交中有 78 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.975
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes17,470
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.mjs
11/11静态类型检查 — tsconfig.json
10/10可复现环境 — lockfile
4/10已体现的代理实践 — 最近 100 次提交中有 2 次由代理编写或署名代理
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
8/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
所用输入
has_nix
has_tests
lockfilespnpm-lock.yaml, uv.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configstsconfig.json
agent_commit_share0.02
toolchain_manifests
dependency_bot_commit_share0
评分方式
27/45可类型检查的代码 — JavaScript,已配置类型检查(tsconfig.json)
53.5/55可控的文件大小 — 采样的 178 个源文件中有 5 个超过 60KB
所用输入
primary_languageJavaScript
largest_source_bytes91,158
source_files_sampled178
oversized_source_files5

关键数据

2GitHub 星标
2贡献者
606最近 12 个月提交数
0距最近推送天数
63发布版本数
1巴士系数(bus factor)
6开放议题
npm, PyPI软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index npm:agent-sanitizer@2.5.0; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 4.5 / 10
4.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-30 06:10 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/14 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
直接依赖 9
注册表软件包版本约束清单文件
npmagent-control-plane-core0.2.13package.json
npmnamespace-guard0.20.0package.json
npmcss-tree^3.2.1package.json
npmrehype-parse9.0.1package.json
npmremark-gfm4.0.1package.json
npmremark-parse11.0.0package.json
npmstyle-to-object1.0.14package.json
npmunified11.0.5package.json
npmunist-util-visit5.1.0package.json
全部依赖 474

来自 GitHub 依赖图的完整解析依赖集合:9 个直接依赖与 465 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npmagent-control-plane-core0.2.13直接
npmcss-tree3.2.1直接
npmnamespace-guard0.20.0直接
npmrehype-parse9.0.1直接
npmremark-gfm4.0.1直接
npmremark-parse11.0.0直接
npmstyle-to-object1.0.14直接
npmunified11.0.5直接
npmunist-util-visit5.1.0直接
npm@babel/code-frame7.29.7间接
npm@babel/compat-data7.29.7间接
npm@babel/core7.29.7间接
npm@babel/generator7.29.7间接
npm@babel/helper-annotate-as-pure7.29.7间接
npm@babel/helper-compilation-targets7.29.7间接
npm@babel/helper-create-class-features-plugin7.29.7间接
npm@babel/helper-globals7.29.7间接
npm@babel/helper-member-expression-to-functions7.29.7间接
npm@babel/helper-module-imports7.29.7间接
npm@babel/helper-module-transforms7.29.7间接
npm@babel/helper-optimise-call-expression7.29.7间接
npm@babel/helper-plugin-utils7.29.7间接
npm@babel/helper-replace-supers7.29.7间接
npm@babel/helper-skip-transparent-expression-wrappers7.29.7间接
npm@babel/helper-string-parser7.29.7间接
npm@babel/helper-validator-identifier7.29.7间接
npm@babel/helper-validator-option7.29.7间接
npm@babel/helpers7.29.7间接
npm@babel/parser7.29.7间接
npm@babel/plugin-proposal-decorators7.29.7间接
npm@babel/plugin-syntax-decorators7.29.7间接
npm@babel/plugin-syntax-jsx7.29.7间接
npm@babel/plugin-syntax-typescript7.29.7间接
npm@babel/plugin-transform-destructuring7.29.7间接
npm@babel/plugin-transform-explicit-resource-management7.29.7间接
npm@babel/plugin-transform-modules-commonjs7.29.7间接
npm@babel/plugin-transform-typescript7.29.7间接
npm@babel/preset-typescript7.28.5间接
npm@babel/template7.29.7间接
npm@babel/traverse7.29.7间接
npm@babel/types7.29.7间接
npm@bcoe/v8-coverage1.0.2间接
npm@commitlint/cli21.2.1间接
npm@commitlint/config-conventional21.2.0间接
npm@commitlint/config-validator21.2.0间接
npm@commitlint/ensure21.2.0间接
npm@commitlint/execute-rule21.0.1间接
npm@commitlint/format21.2.0间接
npm@commitlint/is-ignored21.2.0间接
npm@commitlint/lint21.2.0间接
npm@commitlint/load21.2.0间接
npm@commitlint/message21.2.0间接
npm@commitlint/parse21.2.0间接
npm@commitlint/read21.2.1间接
npm@commitlint/resolve-extends21.2.0间接
npm@commitlint/rules21.2.0间接
npm@commitlint/to-lines21.0.1间接
npm@commitlint/top-level21.2.0间接
npm@commitlint/types21.2.0间接
npm@conventional-changelog/git-client3.1.0间接
npm@conventional-changelog/template1.2.1间接
npm@esbuild/aix-ppc640.28.1间接
npm@esbuild/android-arm0.28.1间接
npm@esbuild/android-arm640.28.1间接
npm@esbuild/android-x640.28.1间接
npm@esbuild/darwin-arm640.28.1间接
npm@esbuild/darwin-x640.28.1间接
npm@esbuild/freebsd-arm640.28.1间接
npm@esbuild/freebsd-x640.28.1间接
npm@esbuild/linux-arm0.28.1间接
npm@esbuild/linux-arm640.28.1间接
npm@esbuild/linux-ia320.28.1间接
npm@esbuild/linux-loong640.28.1间接
npm@esbuild/linux-mips64el0.28.1间接
npm@esbuild/linux-ppc640.28.1间接
npm@esbuild/linux-riscv640.28.1间接
npm@esbuild/linux-s390x0.28.1间接
npm@esbuild/linux-x640.28.1间接
npm@esbuild/netbsd-arm640.28.1间接
npm@esbuild/netbsd-x640.28.1间接
npm@esbuild/openbsd-arm640.28.1间接
npm@esbuild/openbsd-x640.28.1间接
npm@esbuild/openharmony-arm640.28.1间接
npm@esbuild/sunos-x640.28.1间接
npm@esbuild/win32-arm640.28.1间接
npm@esbuild/win32-ia320.28.1间接
npm@esbuild/win32-x640.28.1间接
npm@eslint-community/eslint-utils4.10.1间接
npm@eslint-community/regexpp4.12.2间接
npm@eslint/config-array0.23.5间接
npm@eslint/config-helpers0.6.0间接
npm@eslint/core1.2.1间接
npm@eslint/js10.0.1间接
npm@eslint/object-schema3.0.5间接
npm@eslint/plugin-kit0.7.2间接
npm@humanfs/core0.19.2间接
npm@humanfs/node0.16.8间接
npm@humanfs/types0.15.0间接
npm@humanwhocodes/module-importer1.0.1间接
npm@humanwhocodes/retry0.4.3间接
npm@inquirer/ansi2.0.7间接
npm@inquirer/checkbox5.2.1间接
npm@inquirer/confirm6.1.1间接
npm@inquirer/core11.2.1间接
npm@inquirer/editor5.2.2间接
npm@inquirer/expand5.1.1间接
npm@inquirer/external-editor3.0.3间接
npm@inquirer/figures2.0.7间接
npm@inquirer/input5.1.2间接
npm@inquirer/number4.1.1间接
npm@inquirer/password5.1.1间接
npm@inquirer/prompts8.5.2间接
npm@inquirer/rawlist5.3.1间接
npm@inquirer/search4.2.1间接
npm@inquirer/select5.2.1间接
npm@inquirer/type4.0.7间接
npm@istanbuljs/schema0.1.6间接
npm@jridgewell/gen-mapping0.3.13间接
npm@jridgewell/remapping2.3.5间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@jridgewell/trace-mapping0.3.31间接
npm@sec-ant/readable-stream0.4.1间接
npm@simple-libs/child-process-utils2.0.0间接
npm@simple-libs/stream-utils2.0.0间接
npm@sindresorhus/merge-streams4.0.0间接
npm@stryker-mutator/api9.6.1间接
npm@stryker-mutator/core9.6.1间接
npm@stryker-mutator/instrumenter9.6.1间接
npm@stryker-mutator/tap-runner9.6.1间接
npm@stryker-mutator/util9.6.1间接
npm@types/debug4.1.13间接
npm@types/esrecurse4.3.1间接
npm@types/estree1.0.9间接
npm@types/hast3.0.5间接
npm@types/istanbul-lib-coverage2.0.6间接
npm@types/json-schema7.0.15间接
npm@types/mdast4.0.4间接
npm@types/ms2.1.0间接
npm@types/node25.9.1间接
npm@types/unist3.0.3间接
npm@typescript-eslint/eslint-plugin8.61.0间接
npm@typescript-eslint/parser8.61.0间接
npm@typescript-eslint/project-service8.61.0间接
npm@typescript-eslint/scope-manager8.61.0间接
npm@typescript-eslint/tsconfig-utils8.61.0间接
npm@typescript-eslint/type-utils8.61.0间接
npm@typescript-eslint/types8.61.0间接
npm@typescript-eslint/typescript-estree8.61.0间接
npm@typescript-eslint/utils8.61.0间接
npm@typescript-eslint/visitor-keys8.61.0间接
npmacorn8.18.0间接
npmacorn-jsx5.3.2间接
npmagent-sanitizer2.1.0间接
npmajv6.15.0间接
npmajv8.18.0间接
npmajv8.20.0间接
npmangular-html-parser10.4.0间接
npmansi-regex5.0.1间接
npmansi-regex6.2.2间接
npmansi-styles4.3.0间接
npmansi-styles6.2.3间接
npmargparse2.0.1间接
npmargue-cli3.1.0间接
npmbail2.0.2间接
npmbalanced-match4.0.4间接
npmbaseline-browser-mapping2.11.6间接
npmbrace-expansion5.0.8间接
npmbrowserslist4.28.7间接
npmc811.0.0间接
npmcall-bind-apply-helpers1.0.2间接
npmcall-bound1.0.4间接
npmcallsites3.1.0间接
npmcaniuse-lite1.0.30001806间接
npmccount2.0.1间接
npmchalk5.6.2间接
npmcharacter-entities2.0.2间接
npmchardet2.2.0间接
npmcli-width4.1.0间接
npmcliui8.0.1间接
npmcliui9.0.1间接
npmcolor-convert2.0.1间接
npmcolor-name1.1.4间接
npmcomma-separated-tokens2.0.3间接
npmcommander14.0.3间接
npmconventional-changelog-angular9.2.1间接
npmconventional-changelog-conventionalcommits10.2.1间接
npmconventional-commits-parser7.1.1间接
npmconvert-source-map2.0.0间接
npmcosmiconfig9.0.2间接
npmcosmiconfig-typescript-loader6.3.0间接
npmcross-spawn7.0.6间接
npmdebug4.4.3间接
npmdecode-named-character-reference1.3.0间接
npmdeep-is0.1.4间接
npmdequal2.0.3间接
npmdes.js1.1.0间接
npmdevlop1.1.0间接
npmdiff-match-patch1.0.5间接
npmdunder-proto1.0.1间接
npmelectron-to-chromium1.5.398间接
npmemoji-regex10.6.0间接
npmemoji-regex8.0.0间接
npmentities6.0.1间接
npmenv-paths2.2.1间接
npmerror-ex1.3.4间接
npmes-define-property1.0.1间接
npmes-errors1.3.0间接
npmes-object-atoms1.1.2间接
npmes-toolkit1.50.0间接
npmesbuild0.28.1间接
npmescalade3.2.0间接
npmescape-string-regexp4.0.0间接
npmescape-string-regexp5.0.0间接
npmeslint10.4.0间接
npmeslint-scope9.1.2间接
npmeslint-visitor-keys3.4.3间接
npmeslint-visitor-keys5.0.1间接
npmespree11.2.0间接
npmesquery1.7.0间接
npmesrecurse4.3.0间接
npmestraverse5.3.0间接
npmesutils2.0.3间接
npmevents-to-array2.0.3间接
npmexeca9.6.1间接
npmextend3.0.2间接
npmfast-check4.8.0间接
npmfast-deep-equal3.1.3间接
npmfast-json-stable-stringify2.1.0间接
npmfast-levenshtein2.0.6间接
npmfast-string-truncated-width3.0.3间接
npmfast-string-width3.0.2间接
npmfast-uri3.1.4间接
npmfast-wrap-ansi0.2.2间接
npmfdir6.5.0间接
npmfigures6.1.0间接
npmfile-entry-cache8.0.0间接
npmfind-up5.0.0间接
npmflat-cache4.0.1间接
npmflatted3.4.3间接
npmforeground-child3.3.1间接
npmfunction-bind1.1.2间接
npmgensync1.0.0-beta.2间接
npmget-caller-file2.0.5间接
npmget-east-asian-width1.6.0间接
npmget-intrinsic1.3.0间接
npmget-proto1.0.1间接
npmget-stream9.0.1间接
npmglob13.0.6间接
npmglob-parent6.0.2间接
npmglobal-directory5.0.0间接
npmglobals17.6.0间接
npmgopd1.2.0间接
npmhas-flag4.0.0间接
npmhas-symbols1.1.0间接
npmhasown2.0.4间接
npmhast-util-from-html2.0.3间接
npmhast-util-from-parse58.0.3间接
npmhast-util-parse-selector4.0.0间接
npmhastscript9.0.1间接
npmhtml-escaper2.0.2间接
npmhuman-signals8.0.1间接
npmiconv-lite0.7.3间接
npmignore5.3.2间接
npmignore7.0.6间接
npmimport-fresh3.3.1间接
npmimurmurhash0.1.4间接
npminherits2.0.4间接
npmini6.0.0间接
npminline-style-parser0.2.7间接
npmis-arrayish0.2.1间接
npmis-extglob2.1.1间接
npmis-fullwidth-code-point3.0.0间接
npmis-glob4.0.3间接
npmis-plain-obj4.1.0间接
npmis-stream4.0.1间接
npmis-unicode-supported2.1.0间接
npmisexe2.0.0间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-report3.0.1间接
npmistanbul-reports3.2.0间接
npmjiti2.6.1间接
npmjs-md40.3.2间接
npmjs-tokens4.0.0间接
npmjs-yaml4.3.0间接
npmjsesc3.1.0间接
npmjson-buffer3.0.1间接
npmjson-parse-even-better-errors2.3.1间接
npmjson-rpc-2.01.7.1间接
npmjson-schema-traverse0.4.1间接
npmjson-schema-traverse1.0.0间接
npmjson-stable-stringify-without-jsonify1.0.1间接
npmjson52.2.3间接
npmkeyv4.5.4间接
npmlevn0.4.1间接
npmlines-and-columns1.2.4间接
npmlint-staged17.2.0间接
npmlocate-path6.0.0间接
npmlodash.groupby4.6.0间接
npmlongest-streak3.1.0间接
npmlru-cache11.5.2间接
npmlru-cache5.1.1间接
npmmake-dir4.0.0间接
npmmarkdown-table3.0.4间接
npmmath-intrinsics1.1.0间接
npmmdast-util-find-and-replace3.0.2间接
npmmdast-util-from-markdown2.0.3间接
npmmdast-util-gfm3.1.0间接
npmmdast-util-gfm-autolink-literal2.0.1间接
npmmdast-util-gfm-footnote2.1.0间接
npmmdast-util-gfm-strikethrough2.0.0间接
npmmdast-util-gfm-table2.0.0间接
npmmdast-util-gfm-task-list-item2.0.0间接
npmmdast-util-phrasing4.1.0间接
npmmdast-util-to-markdown2.1.2间接
npmmdast-util-to-string4.0.0间接
npmmdn-data2.27.1间接
npmmicromark4.0.2间接
npmmicromark-core-commonmark2.0.3间接
npmmicromark-extension-gfm3.0.0间接
npmmicromark-extension-gfm-autolink-literal2.1.0间接
npmmicromark-extension-gfm-footnote2.1.0间接
npmmicromark-extension-gfm-strikethrough2.1.0间接
npmmicromark-extension-gfm-table2.1.1间接
npmmicromark-extension-gfm-tagfilter2.0.0间接
npmmicromark-extension-gfm-task-list-item2.1.0间接
npmmicromark-factory-destination2.0.1间接
npmmicromark-factory-label2.0.1间接
npmmicromark-factory-space2.0.1间接
npmmicromark-factory-title2.0.1间接
npmmicromark-factory-whitespace2.0.1间接
npmmicromark-util-character2.1.1间接
npmmicromark-util-chunked2.0.1间接
npmmicromark-util-classify-character2.0.1间接
npmmicromark-util-combine-extensions2.0.1间接
npmmicromark-util-decode-numeric-character-reference2.0.2间接
npmmicromark-util-decode-string2.0.1间接
npmmicromark-util-encode2.0.1间接
npmmicromark-util-html-tag-name2.0.1间接
npmmicromark-util-normalize-identifier2.0.1间接
npmmicromark-util-resolve-all2.0.1间接
npmmicromark-util-sanitize-uri2.0.1间接
npmmicromark-util-subtokenize2.1.0间接
npmmicromark-util-symbol2.0.1间接
npmmicromark-util-types2.0.2间接
npmminimalistic-assert1.0.1间接
npmminimatch10.2.6间接
npmminipass7.1.3间接
npmms2.1.3间接
npmmutation-server-protocol0.4.1间接
npmmutation-testing-elements3.7.3间接
npmmutation-testing-metrics3.7.3间接
npmmutation-testing-report-schema3.7.3间接
npmmute-stream3.0.0间接
npmnatural-compare1.4.0间接
npmnode-releases2.0.51间接
npmnpm-run-path6.0.0间接
npmobject-inspect1.13.4间接
npmoptionator0.9.4间接
npmp-limit3.1.0间接
npmp-locate5.0.0间接
npmparent-module1.0.1间接
npmparse-json5.2.0间接
npmparse-ms4.0.0间接
npmparse57.3.0间接
npmpath-exists4.0.0间接
npmpath-key3.1.1间接
npmpath-key4.0.0间接
npmpath-scurry2.0.2间接
npmpicocolors1.1.1间接
npmpicomatch4.0.5间接
npmprelude-ls1.2.1间接
npmprettier3.9.6间接
npmpretty-ms9.3.0间接
npmprogress2.0.3间接
npmproperty-information7.2.0间接
npmpunycode2.3.1间接
npmpure-rand8.4.2间接
npmqs6.15.1间接
npmremark-stringify11.0.0间接
npmrequire-directory2.1.1间接
npmrequire-from-string2.0.2间接
npmresolve-from4.0.0间接
npmresolve-from5.0.0间接
npmrxjs7.8.2间接
npmsafer-buffer2.1.2间接
npmsemver6.3.1间接
npmsemver7.7.4间接
npmsemver7.8.5间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmside-channel1.1.1间接
npmside-channel-list1.0.1间接
npmside-channel-map1.0.1间接
npmside-channel-weakmap1.0.2间接
npmsignal-exit4.1.0间接
npmsource-map0.7.6间接
npmsource-map-js1.2.1间接
npmspace-separated-tokens2.0.2间接
npmstring-argv0.3.2间接
npmstring-width4.2.3间接
npmstring-width7.2.0间接
npmstring-width8.2.2间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.2.0间接
npmstrip-final-newline4.0.0间接
npmsupports-color7.2.0间接
npmtap-parser17.0.0间接
npmtap-yaml3.0.0间接
npmtest-exclude8.0.0间接
npmtinyexec1.2.4间接
npmtinyglobby0.2.17间接
npmtree-kill1.2.2间接
npmtrough2.2.0间接
npmts-api-utils2.5.0间接
npmtslib2.8.1间接
npmtunnel0.0.6间接
npmtype-check0.4.0间接
npmtyped-inject5.0.0间接
npmtyped-rest-client2.3.1间接
npmtypescript6.0.3间接
npmtypescript-eslint8.61.0间接
npmunderscore1.13.8间接
npmundici-types7.24.6间接
npmunicorn-magic0.3.0间接
npmunist-util-is6.0.1间接
npmunist-util-stringify-position4.0.0间接
npmunist-util-visit-parents6.0.2间接
npmupdate-browserslist-db1.2.3间接
npmuri-js4.4.1间接
npmv8-to-istanbul9.3.0间接
npmvfile6.0.3间接
npmvfile-location5.0.3间接
npmvfile-message4.0.3间接
npmweapon-regex1.3.6间接
npmweb-namespaces2.0.1间接
npmwhich2.0.2间接
npmword-wrap1.2.5间接
npmwrap-ansi7.0.0间接
npmwrap-ansi9.0.2间接
npmy18n5.0.8间接
npmyallist3.1.1间接
npmyaml2.9.0间接
npmyaml-types0.3.0间接
npmyargs17.7.3间接
npmyargs18.1.0间接
npmyargs-parser21.1.1间接
npmyargs-parser22.0.0间接
npmyocto-queue0.1.0间接
npmyoctocolors2.2.0间接
npmzod4.4.3间接
npmzwitch2.0.4间接
PyPIagent-sanitizer0.0.0间接
PyPIagent-sanitizer2.1.0间接
PyPIcertifi2026.6.17间接
PyPIcharset-normalizer3.4.7间接
PyPIcolorama0.4.6间接
PyPIdetect-secrets间接
PyPIdetect-secrets1.5.0间接
PyPIexceptiongroup1.3.1间接
PyPIhypothesis6.155.7间接
PyPIidna3.18间接
PyPIiniconfig2.3.0间接
PyPIpackaging26.2间接
PyPIpluggy1.6.0间接
PyPIpygments2.20.0间接
PyPIpytest9.0.3间接
PyPIpyyaml6.0.3间接
PyPIregexploit1.0.0间接
PyPIrequests2.34.2间接
PyPIsortedcontainers2.4.0间接
PyPItomli2.4.1间接
PyPItyping-extensions4.15.0间接
PyPIurllib32.7.0间接
依赖安全公告 1

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 473 个包,其中也包含从不交付的开发与测试版本固定:1 个存在已知公告,0 个为直接依赖。 有 1 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。

软件包版本关系严重程度公告数修复版本
qs6.15.1间接16.15.2

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3628,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Shell": 42546,
        "Python": 386020,
        "JavaScript": 1397607,
        "TypeScript": 12060
      },
      "pushed_at": "2026-07-30T06:08:45Z",
      "created_at": "2026-06-21T18:28:59Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T06:08:56Z",
      "description": "Strip common prompt injection surfaces.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "AlexanderMattTurner",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/289737770?v=4",
      "created_at": "2026-06-01T15:25:24Z",
      "is_verified": null,
      "public_repos": 13,
      "account_age_days": 58
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-30T06:08:32Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-30T05:33:54Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-30T05:24:50Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-07-30T04:45:38Z"
        },
        {
          "tag": "v2.2.2",
          "kind": "patch",
          "published_at": "2026-07-30T03:47:26Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2026-07-30T01:53:26Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-07-30T01:05:22Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-29T18:27:36Z"
        },
        {
          "tag": "v2.0.3",
          "kind": "patch",
          "published_at": "2026-07-28T22:30:16Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-07-28T21:11:53Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-07-27T22:03:59Z"
        },
        {
          "tag": "v1.47.14",
          "kind": "patch",
          "published_at": "2026-07-23T20:31:27Z"
        },
        {
          "tag": "v1.47.11",
          "kind": "patch",
          "published_at": "2026-07-23T06:40:19Z"
        },
        {
          "tag": "v1.47.10",
          "kind": "patch",
          "published_at": "2026-07-22T23:53:59Z"
        },
        {
          "tag": "v1.47.9",
          "kind": "patch",
          "published_at": "2026-07-21T16:32:49Z"
        },
        {
          "tag": "v1.47.8",
          "kind": "patch",
          "published_at": "2026-07-21T16:29:49Z"
        },
        {
          "tag": "v1.47.7",
          "kind": "patch",
          "published_at": "2026-07-21T15:47:32Z"
        },
        {
          "tag": "v1.47.6",
          "kind": "patch",
          "published_at": "2026-07-21T14:08:32Z"
        },
        {
          "tag": "v1.47.5",
          "kind": "patch",
          "published_at": "2026-07-21T07:37:48Z"
        },
        {
          "tag": "v1.47.4",
          "kind": "patch",
          "published_at": "2026-07-21T06:57:11Z"
        },
        {
          "tag": "v1.47.3",
          "kind": "patch",
          "published_at": "2026-07-21T06:36:07Z"
        },
        {
          "tag": "v1.47.2",
          "kind": "patch",
          "published_at": "2026-07-21T03:18:48Z"
        },
        {
          "tag": "v1.47.0",
          "kind": "minor",
          "published_at": "2026-07-21T02:43:34Z"
        },
        {
          "tag": "v1.46.0",
          "kind": "minor",
          "published_at": "2026-07-19T21:37:28Z"
        },
        {
          "tag": "v1.6.4",
          "kind": "patch",
          "published_at": "2026-07-01T04:52:56Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2026-07-01T04:16:38Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2026-07-01T04:15:04Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2026-07-01T03:52:49Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-06-30T18:01:49Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-06-30T17:19:09Z"
        },
        {
          "tag": "v1.4.10",
          "kind": "patch",
          "published_at": "2026-06-30T06:31:06Z"
        },
        {
          "tag": "v1.4.9",
          "kind": "patch",
          "published_at": "2026-06-30T05:35:03Z"
        },
        {
          "tag": "v1.4.8",
          "kind": "patch",
          "published_at": "2026-06-30T05:21:49Z"
        },
        {
          "tag": "v1.4.7",
          "kind": "patch",
          "published_at": "2026-06-30T05:09:11Z"
        },
        {
          "tag": "v1.4.6",
          "kind": "patch",
          "published_at": "2026-06-30T05:08:09Z"
        },
        {
          "tag": "v1.4.5",
          "kind": "patch",
          "published_at": "2026-06-30T04:50:02Z"
        },
        {
          "tag": "v1.4.4",
          "kind": "patch",
          "published_at": "2026-06-30T04:24:13Z"
        },
        {
          "tag": "v1.4.3",
          "kind": "patch",
          "published_at": "2026-06-30T03:43:56Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-06-29T22:42:04Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-06-29T19:20:17Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-06-29T14:28:26Z"
        },
        {
          "tag": "v1.3.5",
          "kind": "patch",
          "published_at": "2026-06-29T06:44:14Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-06-29T02:11:19Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-06-29T00:52:35Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-06-29T00:51:48Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-06-29T00:23:34Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-06-29T00:21:54Z"
        },
        {
          "tag": "v1.2.16",
          "kind": "patch",
          "published_at": "2026-06-29T00:19:36Z"
        },
        {
          "tag": "v1.2.15",
          "kind": "patch",
          "published_at": "2026-06-29T00:11:24Z"
        },
        {
          "tag": "v1.2.10",
          "kind": "patch",
          "published_at": "2026-06-29T00:05:51Z"
        },
        {
          "tag": "v1.2.8",
          "kind": "patch",
          "published_at": "2026-06-28T23:20:34Z"
        },
        {
          "tag": "v1.2.6",
          "kind": "patch",
          "published_at": "2026-06-28T22:17:35Z"
        },
        {
          "tag": "v1.2.5",
          "kind": "patch",
          "published_at": "2026-06-28T21:53:16Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2026-06-28T21:28:16Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-06-28T21:24:03Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-06-28T20:47:28Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-06-23T20:46:34Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2026-06-23T20:02:12Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-06-23T18:47:12Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2026-06-23T04:49:53Z"
        },
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2026-06-23T03:18:21Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-06-23T02:59:27Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-06-22T07:23:41Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e0db8b2353b7756013582ee766bb6ff23cea40e9",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.5.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T06:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e5b383c1760661a0d5b5cc3ade5654ba08b0cc5",
          "body": "…er-exports-lutkzd\n\nfeat: publish the claude-hooks composition surface as typed subpaths",
          "is_bot": false,
          "headline": "Merge pull request #190 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T06:07:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59779bfa4b3e26dd7304888fbc467539bc08dd61",
          "body": "2.4.1 shipped the four Claude Code hooks and their nine shared libs in the\ntarball behind a single `\"./claude-hooks\"` exports entry pointing at\nplugin-hooks.mjs, whose only export is the `--hook=` CLI dispatcher. Every\ncomposable piece — sanitizeText, evaluateToolOutput, composeContext, the whole\nho\n[…]\ner had.\n\nA pattern rather than a hand-listed set: `files` already ships the whole\nclaude-hooks tree, and a per-module allowlist would leave the next lib\nunreachable until someone remembered to add it.",
          "is_bot": false,
          "headline": "feat: publish the claude-hooks composition surface as typed subpaths",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:55:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b570839ebb0681afc9603e3512d85032b26520eb",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.4.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T05:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ba401da7c2dd41c02d9fac2f62d9ecd12c3038e",
          "body": "…gin-migration-v68rdg\n\ndocs(readme): cut the README by a quarter and unbury the examples",
          "is_bot": false,
          "headline": "Merge pull request #189 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T05:33:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f49171d92c6226b67760b79d9c6f682b29f0e1",
          "body": "345 -> 263 lines. The Claude Code section spelled the same settings.json\nentry four times (60 lines of JSON) where one entry plus an event ->\n--hook= table says it; the comparison and Python sections restated their\ntables in prose; and the API examples sat under '## How this compares',\nwhich is not what they compare. Examples is now its own section.\n\nNo content dropped: every entry point, code, command, env var and link\nsurvives.",
          "is_bot": false,
          "headline": "docs(readme): cut the README by a quarter and unbury the examples",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:28:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad245af82ec7cac9086afd9510f950f445bc1e5",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.4.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T05:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6c7f141e86b9e0d34f62e669c4f666f9b242923",
          "body": "…gin-migration-v68rdg\n\nfeat: publish the Claude Code hooks as agent-sanitizer/claude-hooks",
          "is_bot": false,
          "headline": "Merge pull request #188 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T05:24:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a50596bef33d4e46bf6944cfe0423816b4a368eb",
          "body": "…its stated reason\n\nThe floor claimed to ratchet against deleting the un-bundled entry tests.\nDeleting all three of them leaves coverage identical at 95/3297 lines, so\nit never observed them: `plugin-hooks.mjs` measures 0% while three tests\nspawn it, and the 95 covered lines are scattered import-tim\n[…]\n is worth less than nothing. The behavioural gates hold this code:\nthe degraded-verdict matrix, the env-var coverage enumeration, the egress\npin, the new fail-closed peer test and the live-engine job.",
          "is_bot": false,
          "headline": "fix(ci): drop the claude-hooks coverage floor, which cannot fail for …",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:05:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74219c2db293ae713bc2c1de7ebae3961bada051",
          "body": "The four hooks were reachable only by installing the marketplace plugin.\nThis exports the un-bundled sources so a project can wire them into its\nown settings.json against the npm package, with the plugin remaining the\nzero-config path.\n\n`agent-control-plane-core` and `namespace-guard` move to depend\n[…]\ned guards instead. Observed: with agent-control-plane-core\nremoved from a consumer install, sanitize-output emitted\n`[SANITIZATION FAILED …]` and the AWS key did not survive; before, stdout\nwas empty.",
          "is_bot": false,
          "headline": "feat: publish the Claude Code hooks as agent-sanitizer/claude-hooks",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T04:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d280f7cb1a30398cb87d95dc44131450dd9069f",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.3.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T04:45:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42e8804a5ca98ceefe9840a8307b53239b9db898",
          "body": "…er-plugin-26isvp\n\nfeat(plugin): ship the Claude Code plugin from this repo",
          "is_bot": false,
          "headline": "Merge pull request #184 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T04:45:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31c90b49fa144678062ace54d5b473a749127f3",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.2 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T03:47:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91fe81758ead6f6dae0bd876fe132b739ce91900",
          "body": "…action-false-positive-glvldl\n\nfix(secrets): stop a lone PEM header from redacting the rest of the file",
          "is_bot": false,
          "headline": "Merge pull request #187 from AlexanderMattTurner/claude/edit-tool-red…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T03:46:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0481df6ed6a75ae325e7fc8c0e747c648448fa37",
          "body": "PEM_BLOCK_RE ended an unterminated block at end-of-string, so a bare\n\"-----BEGIN PRIVATE KEY-----\" (a test fixture, a doc example) collapsed\nevery byte after it into one [REDACTED: Private Key] placeholder. In a 98 kB\nfile that hid 13 kB of unrelated source from the model's view, and made\nrehydrateR\n[…]\n line.\n\nThe R1 intrusion deny now reports both byte ranges it compared, so a caller can\ntell a true overlap from a mis-sized redaction instead of re-reading text the\nmessage wrongly implies is hidden.",
          "is_bot": false,
          "headline": "fix(secrets): stop a lone PEM header from redacting the rest of the file",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T02:59:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5002fc375bd76bd931f523b08bbc8bced74fe1e",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T01:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a037cfb78471abf894244952fe6532e72619ad3",
          "body": "…gin-migration-v68rdg\n\ndocs(skills): require PR bodies to state the current head, never their own history",
          "is_bot": false,
          "headline": "Merge pull request #186 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T01:52:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b4d40dbd21249e70589ec764741d52c57daf9d3",
          "body": "…ts skeleton",
          "is_bot": false,
          "headline": "docs(skills): carry the current-head rule into the update-after-commi…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bfeef192400eee037a176b5c8d991a891d55bfb",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): trim the current-head rule to substitutions, not additions",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ccee07190a36960c9cc90e803b4b97509b9bb53",
          "body": "…r own history\n\nThe body template asked for 'what you ran and the outcome', which in\npractice licenses session chronology, and nothing banned a body from\nnarrating its own earlier claims. Align with the current-state rule:\n'How it was tested' is claims about the CURRENT head paired with the\ncommands\n[…]\nt falsify them now; a false claim in an earlier body version\nis replaced, never corrected in place; evidence cycles appear as the\ncurrent-state fact they established, not the runs that established it.",
          "is_bot": false,
          "headline": "docs(skills): require PR bodies to state the current head, never thei…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:42:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8a7a426090da15a378de21495e1cb5c9bbe30c6",
          "body": "The trace module's contract is that every defense layer announces it\nRAN, and sanitize-user-prompt was the one stdin hook that never did — a\nsilently disabled prompt gate was invisible on the channel. The trace\ntest now derives per-hook coverage: all three stdin hooks must emit\nhook_ran.",
          "is_bot": false,
          "headline": "feat(plugin): announce prompt-gate engagement on the trace channel",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:25:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8d40d22fa98eef25488de308ddb6524a0505cc9",
          "body": "The wiring kill test is complete: node-tests-passed went red on the\ncorrupted head (run 30505171252), so the plugin suite is proven wired\ninto the required check, not presumed.\n\nAlso isolates the live-engine corpus onto a per-run socket. The echo-stub\nkill test caught the corpus trusting the DEFAULT\n[…]\n the stub\nreds two corpus checks (secret survives, no REDACTED marker) and the\nreal engine passes all seven; the credential-var check also gains a\npositive control so silence cannot pass as redaction.",
          "is_bot": false,
          "headline": "test(plugin): revert the deliberate red; isolate the live-engine socket",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:20:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b254c85b7d3fbbb30e0e9f0e51df715ab8e0bf9",
          "body": "Wiring kill test: a suite whose CI-redness has never been observed is\npresumed unwired. Reverted in the next commit.",
          "is_bot": false,
          "headline": "test(plugin): deliberate red to observe node-tests-passed fail",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:16:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a18ef34ecc54bb4f41c22c7f48f5c15fc22ff869",
          "body": "The JS side is one committed bundle, but the Python redactor still\nrequired a SessionStart PyPI install: no venv (or no network) meant\nsanitize-output failed closed on every tool call. plugin/dist/redactor/\ndaemon.pyz closes that hole — a self-contained, platform-independent\nzipapp of the pinned age\n[…]\ne committed\nartifact is tracked, pure-Python, and actually redacts.\n\nAlso adds the degraded-posture completeness test: every wired hook must\nsit in exactly one posture table (fail-closed or advisory).",
          "is_bot": false,
          "headline": "feat(plugin): ship the redaction engine as a committed zipapp",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:15:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "409e7e8e93d970a9a2ea2204dc7948c7bcb73878",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T01:05:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15498063ac3a37493f05122f4bc0b8640447f8ec",
          "body": "…ential-vocabulary-7t86vy\n\nfeat(secrets): publish the credential-noun vocabulary as a shared export",
          "is_bot": false,
          "headline": "Merge pull request #185 from AlexanderMattTurner/claude/upstream-cred…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T01:04:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f83f74520f982f2e6c1ce2ecaad61d8b6284c8",
          "body": null,
          "is_bot": true,
          "headline": "chore(plugin): regenerate dist for the pinned engine",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T00:58:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94a1cd58c5c2cf036df14df24a55d4128374a197",
          "body": "Kill test for the plugin-suite CI wiring. The previous attempt also touched a\nbuild input, so plugin-dist-autofix healed it before the required check could\nreport. plugin/dist is not in that workflow's paths, so this one stands.",
          "is_bot": false,
          "headline": "test(plugin): dist-only corruption to observe node-tests-passed go red",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:57:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7194aa4e99ad7af4795d287deddc8cc9e359d54a",
          "body": null,
          "is_bot": true,
          "headline": "chore(plugin): regenerate dist for the pinned engine",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T00:52:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "031f4368133eb839cec476d9d10503a2a2300329",
          "body": "Kill test for the plugin-suite CI wiring. Reverted in the next commit.\nA suite whose redness has never been observed is presumed unwired.",
          "is_bot": false,
          "headline": "test(plugin): corrupt the bundle to observe node-tests-passed go red",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:51:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67b1e85b3c7ae4a01cbba69507a6fe8e618bd6db",
          "body": "The name claimed an ordering assertion the test does not make.",
          "is_bot": false,
          "headline": "test(secrets): name the dedup test for what it asserts",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a4338ea23a26c49a5a63eb2fd9333e8993e971",
          "body": "Layer 2 was dead in the shipped plugin. css-tree pulls its CSS syntax\ntables through `createRequire(import.meta.url)(\"../data/patch.json\")`;\nesbuild inlines the surrounding JS but leaves that require, which then\nresolves against the BUNDLE's directory. An installed plugin has no\n`plugin/dist/data/`,\n[…]\nmerated\n  from the sources so a new one cannot ship unexercised\n- a degraded-verdict matrix derived from hooks.json\n- an egress pin: the artifact's only outbound surface is the local\n  redactor socket",
          "is_bot": false,
          "headline": "fix(plugin): inline the JSON data css-tree requires at runtime",
          "author_name": "t",
          "author_login": null,
          "committed_at": "2026-07-30T00:50:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a237d3814dd62ee50c4e5ede4fb5947480939ca",
          "body": "The words that make an identifier name a secret existed twice with no link\nbetween them: as regex fragments in the engine's `_FIELD_NAMES`, and as an\nenv-var-name segment list in a downstream consumer. A newly recognized noun had\nto be added in both trees by hand, and a noun added to one side only l\n[…]\nly rather than\nthrough a conditions object (so the new export would have been unguarded), and\nit parsed npm's stdout whole, reddening when pnpm's deps check wrote a\n\"Progress:\" line ahead of the JSON.",
          "is_bot": false,
          "headline": "feat(secrets): publish the credential-noun vocabulary as a shared export",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:37:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0ef2c9381e7b361444bc37327a30e465a5b0179",
          "body": "…s on\n\nThe plugin ships a committed esbuild bundle that inlines 69 third-party\npackages, and `committed bundle matches a fresh build` runs inside the\nRequired node-tests check. With pnpm-lock.yaml gitignored, CI resolved\nthose packages fresh on every run across 695 ranged dependency edges, so\nthe ne\n[…]\nand\npack-smoke, mutation, hook-lifecycle and plugin-dist-autofix all list it\nas a trigger path. It also restores setup-node's `cache: pnpm`, which\nthe removed comment named as the cost of ignoring it.",
          "is_bot": false,
          "headline": "fix(ci): commit the lockfile the bundle's reproducibility gate depend…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:19:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f11463741b6ead8c9fa6c6e775595ceaa820dab0",
          "body": "`dist/` in .gitignore matched plugin/dist/, so `git add -A` silently skipped\nthe one file the plugin cannot work without. Every local assertion still passed\nbecause the build had just written it as an untracked file; only a fresh clone\nsaw the truth, which is what CI reported (12 red).\n\nRe-include t\n[…]\nt that catches the class: ask `git ls-files` what is\nTRACKED rather than the filesystem what exists, so an ignore rule that swallows\na shipped artifact reds a test instead of shipping an empty plugin.",
          "is_bot": false,
          "headline": "fix(plugin): commit the bundle the .gitignore was swallowing",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:40:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "219bfec7a5e6f9a7f28d79108fd5ea37cb272975",
          "body": "The repo's check-json pre-commit hook parses every .json with a strict decoder,\nso a tsconfig carrying JS comments fails the push.",
          "is_bot": false,
          "headline": "fix(plugin): drop JSONC comments from tsconfig.hooks.json",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:34:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "006d1d8813ee00b422df0d7363734feb4c52cd79",
          "body": "…equired\n\nThe hook modules are loaded by the bundle entry (or by `node <path>` for the\nbuild script), never executed as `./path`, so a shebang without the executable\nbit is the mismatch the tier-1 check flags. The dist-autofix workflow pushes an\nartifact onto the PR branch rather than reporting a status, so its paths filter\nstrands no required check.",
          "is_bot": false,
          "headline": "chore(plugin): drop unused shebangs and mark the dist autofix never-r…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:33:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1575c628abc4067fdd1d24502c9c0f32d9331aea",
          "body": "Port the sanitizer plugin out of agent-glovebox and into the engine's own\nrepo, bundled against the PUBLISHED npm package rather than sibling workspace\nsources. The plugin's committed bundle therefore only moves when the engine pin\nmoves, which is what kills the perpetual merge-conflict churn that m\n[…]\nLOVEBOX_* env var. The three redactor configs are\nimported as JSON modules instead of read from disk by __dirname arithmetic, so\nesbuild inlines them and the bundle has no config directory to resolve.",
          "is_bot": false,
          "headline": "chore(plugin): ship the Claude Code plugin from this repo",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:26:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55e6566f5cdbf62d8a447e428a6eb232c1fa760a",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.1.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-29T18:27:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45651cc636a4fc0d9e4e754a0c62d0bce6046fbd",
          "body": "…lockfile-conflicts-xefa1t\n\nfeat(ci): auto-regenerate conflicted lockfiles in auto-resolve instead of handing off",
          "is_bot": false,
          "headline": "Merge pull request #183 from AlexanderMattTurner/claude/auto-resolve-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-29T18:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "665d3a8d737bc936a3d3f5f7551128d3b58a2e66",
          "body": "The absent-tool test filtered PATH by dirname(command -v pnpm), which names\nonly the FIRST match — a runner carrying a second pnpm elsewhere on PATH kept\nthe tool reachable, so the lockfile took the deferred-regen branch and the test\npassed on the wrong branch until needs_commit tripped it in CI.\n\nF\n[…]\ntly: pnpm\nunreachable, git and dirname still reachable. Losing dirname would make\nlockfile_tool decline the path and route it to the LLM — a third wrong branch\nthat also satisfies the first assertion.",
          "is_bot": false,
          "headline": "test(ci): strip every pnpm from PATH and assert the absent-tool premise",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:36:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2075e4087835d6487a75c30bc92cdb024c34d2fb",
          "body": "…entials\n\nReview of the deferred-lockfile stage surfaced a silent wrong-resolution path\nand a privilege leak:\n\n- Seed regeneration from --theirs (base), not --ours (PR head). Every lockfile\n  tool preserves the resolutions it finds on disk, so seeding from the PR's own\n  lockfile regenerated it byte\n[…]\nmanifest branches, and assert the tool's argv,\nseeded content, and scrubbed environment so each rail is load-bearing. Wire\nthe auto-resolve suites into CI, which node --test's default discovery skips.",
          "is_bot": false,
          "headline": "fix(ci): seed lockfile regeneration from the base side and scrub cred…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:31:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f719de0ff63242270902a9f818fc76e5e0c54693",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.0.3 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-28T22:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "718c5f3a10b7d7bb2d63038ec4326211c3fabcd9",
          "body": "…er-180-146rqc\n\nfix(release): skip re-runs against an already-released SHA",
          "is_bot": false,
          "headline": "Merge pull request #181 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T22:29:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2e6f2c7cc6a4dda9e125877928b8522a74bf425",
          "body": "…ry API\n\nThe known-vulnerable-actions audit only fires when GH_TOKEN is visible, so it\nran in agent sessions and nowhere else; there the advisories endpoint is 403 and\nzizmor aborts, making every .github/ change unpushable. Run offline audits only\nin the hook; CI is the place to restore online coverage with a token.",
          "is_bot": false,
          "headline": "fix(ci): stop the zizmor hook failing closed on an unreachable adviso…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:20:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18f8117ffc5315b5c1a9f0e166ae9486bd02f2be",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): restore the executable bit on version-bump.sh",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:13:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf496b742e107563e656c67143c66db9fb7a0564",
          "body": null,
          "is_bot": false,
          "headline": "style(ci): apply shfmt case-indent formatting to auto-resolve-lib",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:10:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22027ad21f9dd19050877ce9396d50c7b320d359",
          "body": "Auto-resolve previously classified any conflicted lockfile as unresolvable\nand handed off to a human, even though the fix is purely mechanical. Prepare\nnow defers lockfiles with a known owning tool (pnpm-lock.yaml,\npackage-lock.json, uv.lock) to a new deferred_lock class; finalize re-runs\nthe owning\n[…]\nved manifests and stages the result. Only\nbinaries and unsupported lockfiles still hand off — and the handoff now\nlabels the PR auto-resolve-blocked so base pushes stop retrying into the\nsame refusal.",
          "is_bot": false,
          "headline": "feat(ci): auto-regenerate conflicted lockfiles instead of refusing them",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:09:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d5b7faf1cb2c66e5acdceacfe849fb636f2ee19",
          "body": "The lowest v-tag containing HEAD is the release that shipped it; a descending\nsort named the newest release instead, misdirecting anyone reading the log.\nAlso correct the tagging comment, which still claimed a re-trigger sees\nHEAD == tag SHA — the false premise the already-released guard exists to fix.",
          "is_bot": false,
          "headline": "fix(release): name the tag that actually released HEAD when skipping",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T22:08:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af10c30fc9cdb2f0ad9c90693ccae851dafc65be",
          "body": null,
          "is_bot": false,
          "headline": "test(release): cover a re-run against an already-released SHA",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T21:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3948579198524d7c6fad3a01167cd0eafe6ce01",
          "body": "The release tag lands on the release-docs commit, a child of the SHA that\nwas published, so a re-run against that published SHA saw only ancestor\ntags: `git describe` reported the previous release and the run re-cut the\nsame commit range under a fresh version number, publishing a byte-identical\nduplicate. Exit early when `git tag --contains HEAD` finds a release tag.\n\nCloses #180",
          "is_bot": false,
          "headline": "fix(release): skip re-runs against an already-released SHA",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T21:57:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a5ec9d6f698c411053751eb820ddb1048331ae6",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.0.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-28T21:11:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a193945a4910239f7601f5e501115c2a2f9b7b",
          "body": "…p-edges-uqdwzh\n\nfix(secrets): make unknown assignment operators fail wholesale, never partially match",
          "is_bot": false,
          "headline": "Merge pull request #179 from AlexanderMattTurner/claude/gh-audit-shar…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4793e3ab7eb99e5c3bd9d5677d98ed43719d45ab",
          "body": "… partially match\n\nA multi-char operator the field-value alternation doesn't know (===, =~) had\nits first byte matched by the one-byte arm, gluing the rest onto the captured\nvalue where the stray byte defeats every fullmatch-anchored value-shape skip\nat once — the class behind both shipped false pos\n[…]\nroduces a false negative instead, and === is\nexplicit. An operator x skip-shape grid test pins every combination, with a\npositive redaction marker per operator so the benign half can't pass\nvacuously.",
          "is_bot": false,
          "headline": "fix(secrets): make unknown assignment operators fail wholesale, never…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T20:47:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d0ad21df25568316fa5d6228c20b968e65cdf3f",
          "body": "…and-pin\n\nfix(hooks): stop tag pushes from rebuilding the whole pre-commit suite",
          "is_bot": false,
          "headline": "Merge pull request #175 from AlexanderMattTurner/claude/pre-push-tag-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:29:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c14b5502cb42394261188c9e69388dd1e5d43d1",
          "body": "…p-edges-uqdwzh\n\nfix(secrets): stop redacting shell parameter-expansion defaults and secret-location fields",
          "is_bot": false,
          "headline": "Merge pull request #178 from AlexanderMattTurner/claude/gh-audit-shar…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:29:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff7e64f47d95e03cfa5ccde511b5bbaa7b35070a",
          "body": "…ecret-location fields\n\nThe field-value regex treated the : in ${SECRET_FILE:-/etc/app/secret} as a\none-byte assignment, gluing the -/+/? operator byte onto the captured value so\nevery value-shape skip (filesystem path, env reference, placeholder) stopped\nmatching and an ordinary shell default was m\n[…]\no adds path/file to the metadata-field suffixes: secret_path / key_file\nfields name where a secret lives, and their variable-rooted or relative values\nescape the absolute-path and env-reference skips.",
          "is_bot": false,
          "headline": "fix(secrets): stop redacting shell parameter-expansion defaults and s…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T20:16:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "038b49a79435ddea18faeed11376c429c237dd16",
          "body": "ci: print PyPI's rejection reason on publish failures",
          "is_bot": false,
          "headline": "Merge pull request #176 from AlexanderMattTurner/claude/pypi-verbose",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T07:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87f4f0d16aa94a6bc49be110807132c33a4161f6",
          "body": "The break-glass publish died with a bare \"HTTPError: 400 Bad Request\" —\ntwine only prints the registry's response body (which names the offending\nmetadata field or publisher mismatch) under --verbose, so the failed run\ncarries no diagnosis. Both publish steps now pass verbose: true.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01MNEMrPimpPVH8HUAGqzEMu",
          "is_bot": false,
          "headline": "ci: print PyPI's rejection reason on publish failures",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T06:11:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ae4d2365e2914e0aba91d02a1f1f5ec74d72f3af",
          "body": "`git push origin <tag>` fed the pushed-range check a tag ref, which has no\nupstream to diff against, so it fell through to the new-branch fallback and\nswept the merge base with origin/HEAD — a stale branch on this clone. Skip tag\nrefs: a tag adds no commits, and the tagged commit was already checked\n[…]\n this very file. Use exit code 3 instead: pre-commit maps hook failures to 1\n  and everything else, including a failed environment install, to 3.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): stop tag pushes from rebuilding the whole pre-commit suite",
          "author_name": "Alexander Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T05:21:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9be965ad0a1bf3c2cb8d0da3b7bb10d439ecfc84",
          "body": "fix(ci): give the conflict resolver uvx so the pre-push hook can run",
          "is_bot": false,
          "headline": "Merge pull request #174 from AlexanderMattTurner/claude/resolver-uvx",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T00:49:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d7d8f1c6920c504c7ed30ef2eb0f1273c5e7907",
          "body": "The resolution push executes the checked-out PR head's .hooks/pre-push,\nwhich runs the pushed-range pre-commit suite through uvx. The resolver\njob never installed uv, so the hook degraded on every run — and a PR\nhead carrying an older hook revision fails closed, rejecting the\nresolution push with \"required tool 'pre-commit' not found\" (PR #169).\nWith uv present the hook checks the range for real on any branch\nvintage.",
          "is_bot": false,
          "headline": "fix(ci): give the conflict resolver uvx so the pre-push hook can run",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T00:46:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655b7fb5471fc14476270e08a0835461ab680fc4",
          "body": "ci: source the org PAT (TEMPLATE_SYNC_TOKEN_ORG) in every workflow",
          "is_bot": false,
          "headline": "Merge pull request #172 from AlexanderMattTurner/claude/org-pat-sweep",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-27T22:34:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f35dcf52fac8a7b015c9eac64f72a739b681f4e",
          "body": "…xandermattturner/agent-input-sanitizer into claude/org-pat-sweep",
          "is_bot": false,
          "headline": "Merge branch 'claude/org-pat-sweep' of http://127.0.0.1:41729/git/ale…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:19:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d26b9cec451d01c3212b61be9854e2566a664173",
          "body": "GitHub rejects approving reviews minted with the Actions GITHUB_TOKEN\n(\"GitHub Actions is not permitted to approve pull requests\"), so the\npush-time approve step and the hourly sweep both source\nTEMPLATE_SYNC_TOKEN_ORG, falling back to GITHUB_TOKEN which fails loud\non the approve when the PAT is unset. Explicitly user-directed.",
          "is_bot": false,
          "headline": "ci: approve with the org PAT in the reviewer-hold clear paths",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf84535e652f6336ea3011fd11011d5081199d35",
          "body": null,
          "is_bot": true,
          "headline": "style: apply prettier",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-27T22:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "021d6a16b05457213ab68a3bd541473fc05aac0c",
          "body": "The four workflows still reading the cross-account TEMPLATE_SYNC_TOKEN\njoin auto-version and template-sync on the org-level PAT, which is the\ntoken actually authorized on this repo (version-bump.test.mjs pins the\ndistinction). Operator-facing messages and the auto-resolve env plumbing\nfollow the secret's name so remediation instructions point at the secret\nthat exists. The PR-approval step is untouched and stays on the Actions\nGITHUB_TOKEN.",
          "is_bot": false,
          "headline": "ci: source the org PAT (TEMPLATE_SYNC_TOKEN_ORG) in every workflow",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e653e479ed6732a611033a7393d09714c0db317b",
          "body": "…sanitizer\n\nfeat!: rename the package to agent-sanitizer",
          "is_bot": false,
          "headline": "Merge pull request #170 from AlexanderMattTurner/claude/rename-agent-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-27T22:03:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6450a51a7ad08716fc03d7cdb297b3caa728ecb9",
          "body": "The pinned 1.38.0 was only ever published under the old package name, so\nunder agent-sanitizer it can never resolve and the install step would 404\nevery review workflow on first run after merge. 2.0.0 is the version the\nrename's feat! merge makes auto-version cut from the 1.47.x line — the\nfirst release that will exist under the new name.",
          "is_bot": false,
          "headline": "fix(ci): pin the review-pipeline sanitizer install to 2.0.0",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T21:17:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b49ead8b9e83ea37f0bee8e5e56567649399a6f",
          "body": null,
          "is_bot": true,
          "headline": "style: apply prettier",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-27T21:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adc05fac55b65a2b440088fd42c1a9f7b65aae98",
          "body": "BREAKING CHANGE: the npm package, the PyPI distribution, and the Python\nimport package are now `agent-sanitizer` / `agent_sanitizer` (previously\n`agent-input-sanitizer` / `agent_input_sanitizer`), with no compatibility\nalias. The tool sanitizes an agent's whole content surface — tool output,\nuser pr\n[…]\n-referential GitHub URLs move to the renamed repo;\nnpm provenance validates repository.url against the publishing repo, so\nthe GitHub repo rename must land before the first release under the new\nname.",
          "is_bot": false,
          "headline": "feat!: rename the package to agent-sanitizer",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T21:09:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "77d78aa01191547927050d35c439178d7e746fdf",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.14 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T20:31:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51535335d0e05334319a12b14b8aa6f35d5b7398",
          "body": "…h-workflow-1pff2b\n\nfix(ci): rebase release-docs push when main advances mid-run",
          "is_bot": false,
          "headline": "Merge pull request #167 from AlexanderMattTurner/claude/python-publis…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T20:30:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0a5eb2a2b9d1b1a96e8cf3d316c00ceda4bac80",
          "body": "…notate rebase marker\n\nTwo CI-red fixes:\n\n- The release-docs race test spawns the real version-bump.sh, which reads\n  GITHUB_REF_NAME as the push target. Under Actions that names the PR merge\n  ref (167/merge), so the run targeted the wrong branch and the\n  rebase-on-reject path never fired — the te\n[…]\n to inline-only\n  workflow guards. Add its documented allow-externalized-marker opt-out with\n  a truthful reason: auto-version.yaml checks out fetch-depth: 0, the exact\n  invariant the guard protects.",
          "is_bot": false,
          "headline": "test(ci): stop leaking GITHUB_REF_NAME into the release-race test, an…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T20:26:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e31a12ebf58ef8efbbe2ba616394f03ff10476d3",
          "body": "The template ships its own version-bump.test.mjs, and template-sync landed\nit at .github/scripts/version-bump.test.mjs. It tests the template's release\ndesign (plain-string npm view, GITHUB_TOKEN-only push) against this repo's\nhardened live script (npm view --json, TEMPLATE_SYNC_TOKEN_ORG push), so it\nfails 5/6 and is red on main. scripts/version-bump.test.mjs already covers the\nlive script and passes; extend its SSOT contract test to assert the template\nduplicate stays gone.",
          "is_bot": false,
          "headline": "test(ci): drop incompatible template-synced version-bump test",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T20:11:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d83625e050a477d66b854fc3aac409dd04518ab",
          "body": "In a restricted-egress sandbox, pre-commit can't download a linter's\nbinary (shellcheck/shfmt fetch from GitHub releases -> HTTP 403) and\nhard-fails the environment install before running anything. That is not a\nlint failure, but it aborted every 'git push' from such an environment.\n\nCapture pre-com\n[…]\nthe existing 'skip loudly when uvx is absent' path. A\ngenuine lint/format failure from a hook that actually ran still aborts the\npush. CI (pre-commit.yaml) re-runs the full suite on the PR regardless.",
          "is_bot": false,
          "headline": "ci: skip pushed-range pre-commit run when a hook can't be provisioned",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T19:40:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9ae63d5a537db238d61431041cc3ba67f7f43e9",
          "body": "The main-merge auto-resolver garbled the version-bump.sh conflict: it\ndropped the RELEASE_DOCS_PUSH_FAILED=0 initialization (leaving a set -u\nunbound-variable crash right after the release-docs push, before tagging)\nand mangled the push call into the nonsensical\n`retry_cmd push_with_rebase \"HEAD:$DE\n[…]\nutostash on non-fast-forward so a racing merge can't strand the\nrelease), and set RELEASE_DOCS_PUSH_FAILED on failure so the tag is skipped\nwhen docs did not land. The race regression test now passes.",
          "is_bot": false,
          "headline": "fix(ci): repair botched auto-merge of release-docs push logic",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T19:33:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5419a32e41a6813ca5c948931aaf2257b53d2049",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into claude/python-publish-workflow-1pff2b",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T19:20:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1040443e88e2488346f66b1e853a2d8de6cc9a0b",
          "body": "The auto-version concurrency group serializes the workflow, but main can\nstill advance via an ordinary PR merge while a release run is in flight.\nThe run then holds a stale tip and its `git push HEAD:main` is rejected\nnon-fast-forward; the old retry_cmd just re-ran the identical push, which\ncan neve\n[…]\navioral test that runs the real script against a bare remote which\nadvances out from under it, asserting the release-docs commit and tag land\non top of the concurrent commit (never force-pushed away).",
          "is_bot": false,
          "headline": "fix(ci): rebase release-docs push when main advances mid-run",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T17:20:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84cf21d49fa22914598c55111c3e52550b2583ca",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.13 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T16:36:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc62986c85078db8c4f77eb72a7839e35a2d527",
          "body": "chore: sync from template repository",
          "is_bot": false,
          "headline": "Merge pull request #163 from AlexanderMattTurner/template-sync",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T16:35:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1471d2a6c15b9eadff1ad3b312933b253556a82",
          "body": "Finalize PR #163 (sync from template f2b22de) by resolving the 12 conflicted\nfiles, keeping project-specific customizations and adopting genuine template\nimprovements:\n\n- pre-push-check.sh: take template's ruff runner (local's string form is broken\n  against the `\"$@\"` run_check).\n- session-setup.sh\n[…]\ns at three jq sites (added matcher-content check), and\nmatchers must be tool-name filters (real settings.json already uses `Bash` + an\n`if` field), so the fixture's command-content matcher is updated.",
          "is_bot": false,
          "headline": "chore: resolve template-sync merge conflicts",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T15:55:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "671bc5b4f34bd4a598d84ed06b46d6518db983be",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.11 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T06:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96e834030c46d55c29f1b519d6e4668dddcd2e38",
          "body": "…anitizer-py310-cjqrie\n\nfix(python): lower requires-python to 3.10 by removing 3.11-only regex",
          "is_bot": false,
          "headline": "Merge pull request #165 from AlexanderMattTurner/claude/agent-input-s…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T06:31:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9053a7f1dea05197860bf3f7b14a4713529e745",
          "body": "Run pytest only on Python 3.10 (the package's declared floor) in validate-config\ninstead of also on 3.11. Running the floor immediately surfaced a real gap:\ntests/test_gitleaks_allowlist.py imported the stdlib `tomllib`, which only exists\non 3.11+, so the guard could never have run on 3.10. Fall back to `tomli` (a\nmarker-gated dev dependency, installed only below 3.11) so the allowlist guard\nruns on the floor with real TOML parsing rather than a hand-rolled approximation.",
          "is_bot": false,
          "headline": "test(python): make the suite run on the 3.10 floor in CI",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T06:29:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "014de1e13b137e6441f65e66eed1d97ffe0b6bec",
          "body": "The published wheel declared `requires-python = \">=3.11\"` and the secrets\nredaction engine used a possessive quantifier (`*+`) in `_ENV_REFERENCE_RE`,\na regex feature `re` only gained in Python 3.11. Downstream bases on Python\n3.10 (e.g. Ubuntu 22.04 / 3.10.6) therefore had no installable wheel, eve\n[…]\npy.\n\nRun the pytest suite on both 3.10 (the floor) and 3.11 in CI, so a future\n3.11-only construct can no longer slip in unnoticed — the gap that let the\npossessive quantifier land in the first place.",
          "is_bot": false,
          "headline": "fix(python): lower requires-python to 3.10 by removing 3.11-only regex",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T06:15:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebde9617ceacbb8f4118fbec2a086e5f262675a9",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync from template repository (f2b22de)",
          "author_name": "alexander-turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T05:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa5ec791a7ac5d97d817b7c74ccb4f25ef9d045b",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.10 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-22T23:53:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d322cb0e15919649059b08319aaf56442f68e518",
          "body": "…t-sanitizer-control-plane-syat46\n\nfix(sanitizer): hidden-text false positives, scale-collapse miss, base64url beacon, lone-surrogate re-redact",
          "is_bot": false,
          "headline": "Merge pull request #164 from AlexanderMattTurner/claude/parallel-audi…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-22T23:53:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e27b4b681f462ec85e612a8d3aa3611fa9cfa38b",
          "body": "Same template-synced file, same pre-existing drift as the control-plane repo:\nruff-format wants two blank lines before the top-level\ntest_survives_self_overwrite_with_longer_file def. Surfaced by pre-commit\nrun --all-files; fixing to get the PR's pre-commit check green.",
          "is_bot": false,
          "headline": "style: satisfy ruff-format blank-line rule in test_template_sync",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:45:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71cdb9f96d230a45ea8dba782fee6cf1e53b0881",
          "body": "…e branches\n\nThe strict c8 100% gate (lines/branches/functions) rejected three\nnewly-uncovered spots:\n\n- html.mjs isTextPaintedVisible re-checked -webkit-text-fill-color, but the\n  same-color/transparent branches now resolve the EFFECTIVE fill BEFORE calling\n  it, so a concrete fill keeps effectiveC\n[…]\nunder a 100% gate) and the atomicReplaceFile\n  rename-catch cleanup (a LOW temp-leak nit that would need a new public seam +\n  two branch tests to cover). The CLI cwd validation and docblock fix stay.",
          "is_bot": false,
          "headline": "fix(coverage): restore 100% — drop dead fill check, revert unreachabl…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:42:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f05ae55a427152b8e771c06b444c3f1ba68218f",
          "body": "…y tail\n\ncheckExfilUrl measured the long-query length from a raw indexOf(\"?\"), which can\nmatch a \"?\" inside the FRAGMENT — leaving parsed.search empty so allParamsBenign\nruns [].every(...) and vacuously suppresses the flag. Measure from parsed.search\n(the fragment is length-checked separately). No o\n[…]\n target and is a legal\nquery sub-delimiter WITHIN it, so a ?a=1;data=<blob> exfil tail was dropped. A\nquoted value now runs to its closing quote; an unquoted value stops only at\nwhitespace or a quote.",
          "is_bot": false,
          "headline": "fix(html): measure query from parsed.search; keep meta-refresh ;-quer…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:25:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "addaf3f4caf2b00e2da0518de00d1eff5b8ecaee",
          "body": "…, CLI cwd\n\ncleanFile now returns the documented null (not true) when scanText flagged a\npayload but stripInvisible removed nothing — a preserved-payload signal, so a\ncaller is never told a preserved run was cleaned. @returns corrected to\nboolean|null. The path is currently unreachable (every scan-f\n[…]\ntionFiles now fails loud on a present-but-non-string cwd\ninstead of silently dropping it and scanning process.cwd() (wrong scope). Stale\none-shot docblock corrected to say \"one-line reason on stderr\".",
          "is_bot": false,
          "headline": "fix(instructions): cleanFile null signal, temp cleanup on rename fail…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:21:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "742c1b50162d2b0cfbfb5a9d41e0b62043a73359",
          "body": "…omment\n\nisSgrColorOnly's second conjunct re-tested the SGR-stripped prompt against the\nsame C1 introducer class isSgrOnly already checks, so it was dead code, and its\ncomment falsely claimed isSgrOnly is blind to the C1 OSC introducer U+009D.\nisSgrOnly's control-introducer class already covers the whole C1 block\n(U+0080 through U+009F), U+009D included, plus 7-bit ESC. Behavior is unchanged;\nthe misleading comment is corrected so a future editor does not re-add a\nredundant OSC check.",
          "is_bot": false,
          "headline": "refactor(prompt): drop dead SGR-only conjunct and correct its false c…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f2c4019c7fbe802a77a8600018777c7c85066a8",
          "body": "Layer-5 span deletion can splice two kept regions across a lone UTF-16 surrogate\n(e.g. deleting one half of a surrogate pair), both reconstituting a secret the\nfirst redaction pass never saw intact AND leaving a lone surrogate the redactor\nreads as U+FFFD — so the reconstituted secret survives the r\n[…]\ne layer1.mjs docstring, which claimed applyLayer1\nnormalizes lone surrogates — it does not; LONE_SURROGATE_RE is exported for\nconsumers to apply at the redactor/HTML boundary, which is what this does.",
          "is_bot": false,
          "headline": "fix(output): normalize lone surrogates on the Layer-5 re-redact path",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T22:54:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55c9d087c3ea71cbf77c82444f69050f8321af13",
          "body": "… base64url beacon\n\nHidden-text detection: collapse the same-color/transparent branches onto one\neffective-fill-color and a centralized hasImageLayer() guard. The background-color\nLONGHAND path ignored a co-declared background-image, splicing text painted over\nan image; the same-color branch compare\n[…]\n word-slug shows neither. Raises recall\non scattered-separator beacons while keeping slugs benign (precision-first).\n\nRegression rows added to the hidden-style SSOT table and checkExfilUrl unit suite.",
          "is_bot": false,
          "headline": "fix(html): kill same-color false positives, multi-arg scale collapse,…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T22:51:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f1009e0d9bbd084336b4c5315f29f634035bb4f",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.9 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T16:32:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2c17cc218cecea211301439cfe82a0c954ae9dc",
          "body": "…force-merge-qtv3bi\n\nci: use TEMPLATE_SYNC_TOKEN_ORG as the primary template-sync token",
          "is_bot": false,
          "headline": "Merge pull request #162 from AlexanderMattTurner/claude/templatesync-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-21T16:32:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fcd5977be397412d1ff52e67585ecf7df41bef4",
          "body": null,
          "is_bot": false,
          "headline": "ci: use TEMPLATE_SYNC_TOKEN_ORG as the primary template-sync token",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-21T16:31:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00612cedff99ca89b2b2e484a0121ed37d446e25",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.8 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T16:29:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 63,
      "commits_last_year": 606,
      "latest_release_at": "2026-07-30T06:08:32Z",
      "latest_release_tag": "v2.5.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "agent-sanitizer",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "llm",
            "prompt-injection",
            "sanitize",
            "unicode",
            "invisible-characters",
            "ansi",
            "exfiltration",
            "rag",
            "agent",
            "security",
            "homoglyph",
            "confusables",
            "redaction",
            "tool-output",
            "edit-repair"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/agent-sanitizer",
          "is_deprecated": false,
          "latest_version": "2.5.0",
          "repository_url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 797,
          "first_published_at": "2026-07-28T00:49:03.964000Z",
          "latest_published_at": "2026-07-30T06:08:31.970000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "agent-sanitizer",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ansi",
            "prompt-injection",
            "sanitizer",
            "security",
            "unicode",
            "License :: OSI Approved :: Apache Software License"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/agent-sanitizer/",
          "is_deprecated": false,
          "latest_version": "2.5.0",
          "repository_url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-07-28T15:58:16.326054Z",
          "latest_published_at": "2026-07-30T06:09:06.106909Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-04",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 91158,
      "source_files_sampled": 178,
      "oversized_source_files": 5,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 17470
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "plugin/requirements.txt",
        "pyproject.toml",
        "python/pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.1",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-q8mj-m7cp-5q26"
            ],
            "fixed_version": "6.15.2",
            "advisory_count": 1,
            "oldest_advisory_days": 68
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 473,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 1,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "agent-control-plane-core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.2.13"
        },
        {
          "name": "namespace-guard",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.20.0"
        },
        {
          "name": "css-tree",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.2.1"
        },
        {
          "name": "rehype-parse",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "9.0.1"
        },
        {
          "name": "remark-gfm",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "4.0.1"
        },
        {
          "name": "remark-parse",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "11.0.0"
        },
        {
          "name": "style-to-object",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.0.14"
        },
        {
          "name": "unified",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "11.0.5"
        },
        {
          "name": "unist-util-visit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "5.1.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "agent-control-plane-core",
            "direct": true,
            "version": "0.2.13",
            "ecosystem": "npm"
          },
          {
            "name": "css-tree",
            "direct": true,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "namespace-guard",
            "direct": true,
            "version": "0.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "rehype-parse",
            "direct": true,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-gfm",
            "direct": true,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-parse",
            "direct": true,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "style-to-object",
            "direct": true,
            "version": "1.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "unified",
            "direct": true,
            "version": "11.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-visit",
            "direct": true,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-annotate-as-pure",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-create-class-features-plugin",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-member-expression-to-functions",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-optimise-call-expression",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-replace-supers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-skip-transparent-expression-wrappers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-proposal-decorators",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-decorators",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-destructuring",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-explicit-resource-management",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-modules-commonjs",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-typescript",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/preset-typescript",
            "direct": false,
            "version": "7.28.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/cli",
            "direct": false,
            "version": "21.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/config-conventional",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/config-validator",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/ensure",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/execute-rule",
            "direct": false,
            "version": "21.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/format",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/is-ignored",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/lint",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/load",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/message",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/parse",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/read",
            "direct": false,
            "version": "21.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/resolve-extends",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/rules",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/to-lines",
            "direct": false,
            "version": "21.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/top-level",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/types",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@conventional-changelog/git-client",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@conventional-changelog/template",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.23.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/ansi",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/checkbox",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/confirm",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/core",
            "direct": false,
            "version": "11.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/editor",
            "direct": false,
            "version": "5.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/expand",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/external-editor",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/figures",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/input",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/number",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/password",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/prompts",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/rawlist",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/search",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/select",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/type",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@sec-ant/readable-stream",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@simple-libs/child-process-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@simple-libs/stream-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sindresorhus/merge-streams",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/api",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/core",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/instrumenter",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/tap-runner",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/util",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/debug",
            "direct": false,
            "version": "4.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "@types/esrecurse",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/hast",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/mdast",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/ms",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/unist",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "angular-html-parser",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "argue-cli",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "bail",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.11.6",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.7",
            "ecosystem": "npm"
          },
          {
            "name": "c8",
            "direct": false,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001806",
            "ecosystem": "npm"
          },
          {
            "name": "ccount",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "character-entities",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "chardet",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-width",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "comma-separated-tokens",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "14.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-changelog-angular",
            "direct": false,
            "version": "9.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-changelog-conventionalcommits",
            "direct": false,
            "version": "10.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-commits-parser",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cosmiconfig",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "cosmiconfig-typescript-loader",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decode-named-character-reference",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "des.js",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "devlop",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff-match-patch",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.398",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "env-paths",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-toolkit",
            "direct": false,
            "version": "1.50.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "9.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "11.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "events-to-array",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "4.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "figures",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "13.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "global-directory",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "17.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-from-html",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-from-parse5",
            "direct": false,
            "version": "8.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-parse-selector",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "hastscript",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "inline-style-parser",
            "direct": false,
            "version": "0.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jiti",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-md4",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-rpc-2.0",
            "direct": false,
            "version": "1.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "17.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.groupby",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "longest-streak",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "markdown-table",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-find-and-replace",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-from-markdown",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-autolink-literal",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-footnote",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-strikethrough",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-table",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-task-list-item",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-phrasing",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-to-markdown",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-to-string",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdn-data",
            "direct": false,
            "version": "2.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-core-commonmark",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-autolink-literal",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-footnote",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-strikethrough",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-table",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-tagfilter",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-task-list-item",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-destination",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-label",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-space",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-title",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-whitespace",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-character",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-chunked",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-classify-character",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-combine-extensions",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-decode-numeric-character-reference",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-decode-string",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-encode",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-html-tag-name",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-normalize-identifier",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-resolve-all",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-sanitize-uri",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-subtokenize",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-symbol",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-types",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimalistic-assert",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-server-protocol",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-elements",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-metrics",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-report-schema",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mute-stream",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.51",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse-ms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.9.6",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-ms",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "progress",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "property-information",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-stringify",
            "direct": false,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "rxjs",
            "direct": false,
            "version": "7.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "space-separated-tokens",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-argv",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "8.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tap-parser",
            "direct": false,
            "version": "17.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tap-yaml",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tree-kill",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "trough",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tunnel",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-inject",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-rest-client",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "underscore",
            "direct": false,
            "version": "1.13.8",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "unicorn-magic",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-is",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-stringify-position",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-visit-parents",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "vfile",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vfile-location",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vfile-message",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "weapon-regex",
            "direct": false,
            "version": "1.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "web-namespaces",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml-types",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "18.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yoctocolors",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zwitch",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.6.17",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.7",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "detect-secrets",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "detect-secrets",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "exceptiongroup",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis",
            "direct": false,
            "version": "6.155.7",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.18",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "regexploit",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "sortedcontainers",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 474,
        "direct_count": 9,
        "indirect_count": 465
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 167,
        "open_issues": 6,
        "closed_ratio": 0.25,
        "closed_issues": 2,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "claude",
          "commits": 382,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "alexander-turner",
          "commits": 183,
          "avatar_url": "https://avatars.githubusercontent.com/u/3458070?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.676
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-resolve-conflicts.yaml",
        "auto-version.yaml",
        "build-publish-notify.yaml",
        "cancel-on-pr-close.yaml",
        "ci-failure-notify.yaml",
        "claude-merge-delta-review.yaml",
        "claude-pr-review.yaml",
        "claude-review-thread-resolve.yaml",
        "claude-reviewer-hold-clear.yaml",
        "claude.yaml",
        "decide-reusable.yaml",
        "dependabot-auto-merge.yaml",
        "format-autofix.yaml",
        "format-check.yaml",
        "fuzz-nightly.yaml",
        "gitleaks.yaml",
        "history-integrity.yaml",
        "hook-lifecycle.yaml",
        "lint.yaml",
        "merge-conflict-labeler.yaml",
        "mutation.yaml",
        "node-tests.yaml",
        "pack-smoke.yaml",
        "phone-home.yaml",
        "plugin-dist-autofix.yaml",
        "pr-desc-accuracy.yaml",
        "pr-review-advisory-comment.yaml",
        "pr-review-advisory.yaml",
        "pre-commit.yaml",
        "publish-python.yaml",
        "release-canary.yaml",
        "remerge-diff-report.yaml",
        "security-vulnerability-scan.yaml",
        "sync-required-checks.yaml",
        "template-sync.yaml",
        "validate-config.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/14 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e0db8b2353b7756013582ee766bb6ff23cea40e9",
        "ran_at": "2026-07-30T06:10:36Z",
        "aggregate_score": 4.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-30T06:09:58Z",
      "oldest_open_prs": [
        {
          "number": 169,
          "created_at": "2026-07-24T10:52:52Z",
          "last_comment_at": "2026-07-29T11:13:52Z",
          "last_comment_author": "alexander-turner"
        }
      ],
      "last_merged_pr_at": "2026-07-30T06:07:47Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 166,
          "created_at": "2026-07-23T16:37:24Z",
          "last_comment_at": "2026-07-28T21:26:29Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 168,
          "created_at": "2026-07-24T08:42:14Z",
          "last_comment_at": "2026-07-29T09:08:19Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 171,
          "created_at": "2026-07-27T21:53:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 173,
          "created_at": "2026-07-27T22:36:17Z",
          "last_comment_at": "2026-07-28T20:52:36Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 177,
          "created_at": "2026-07-28T07:08:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 182,
          "created_at": "2026-07-28T22:08:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
    "host": "github.com",
    "name": "agent-sanitizer",
    "owner": "AlexanderMattTurner"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 56,
        "vitality": 70,
        "community": 39,
        "governance": 49,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 606,
              "human_commit_share": 0.8,
              "days_since_last_push": 0,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "606 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 606
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 63,
              "latest_release_tag": "v2.5.0",
              "releases_from_tags": true,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "63 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 63
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 39,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "packages": [
                "agent-sanitizer",
                "agent-sanitizer"
              ],
              "dependents": null,
              "ecosystems": "npm, pypi",
              "total_downloads": null,
              "monthly_downloads": 797
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "797 downloads/month across npm, pypi",
                "points": 38.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 797,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.676
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 68% of commits",
                "points": 7.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 68
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "merged_prs": 167,
              "open_issues": 6,
              "closed_issues": 2,
              "issue_closed_ratio": 0.25,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "25% of issues closed",
                "points": 11.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 25
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "167/181 decided PRs merged",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 167,
                      "decided": 181
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/14 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "AlexanderMattTurner",
              "public_repos": 13,
              "account_age_days": 58
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of AlexanderMattTurner",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "AlexanderMattTurner"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "13 public repos, account ~0 yr old",
                "points": 8.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 13
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "agent-sanitizer",
                "agent-sanitizer"
              ],
              "ecosystems": "npm, pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm, pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "37 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 45,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/14 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 473 resolved dependencies against OSV; 1 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 473
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 1
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 473,
              "unassessed_packages": 1,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 473,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 78,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.975,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 17470
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "78 of 80 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 78,
                      "sampled": 80
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml",
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 91158,
              "source_files_sampled": 178,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/178 source files over 60KB",
                "points": 53.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 178,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index npm:agent-sanitizer@2.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T06:10:51.422009Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/AlexanderMattTurner/agent-sanitizer.svg",
  "full_name": "AlexanderMattTurner/agent-sanitizer",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm, PyPI.