公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 21:03 UTC

AtlasDevHQ / atlas

TypeScriptAGPL-3.0★ 1 星标⑂ 3 复刻始于 2026年3月在 GitHub 上查看 ↗

AtlasDevHQ/atlas 的健康指数为 100 分中的 64 分,处于「中等」区间。 其得分最高的类别是Vitality(87/100),最低的是Community & Adoption(36/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

64
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

64
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

0 关注者4 个公开仓库始于 2026年2月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npmcreate-atlas-agent0.3.349783 天前atlastext-to-sqldata-analystagentsemantic-layerbunhono
npmcreate-atlas-plugin0.1.122283 天前atlastext-to-sqlpluginscaffoldbun

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

87优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
14.5/36提交节奏 — 52 周中有 21 周有提交
18/18提交量 — 最近一年 3,439 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year3,439
human_commit_share1
days_since_last_push0
active_weeks_last_year21

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 68 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 0.6 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count68
latest_release_tagv0.1.0
releases_from_tags
days_since_latest_release1
mean_days_between_releases0.6
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

36存在风险 · 占总体的 18%
评分方式
0/60星标 — 1 个星标
2.5/25复刻 — 3 个复刻
0/15关注者 — 0 位关注者
所用输入
forks3
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

77良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(AGPL-3.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
24.8/80月度下载量 — npm 合计每月 71 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagescreate-atlas-agent, create-atlas-plugin
dependents
ecosystemsnpm
total_downloads
monthly_downloads71
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

55中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0.4/22.5提交分布 — 头号贡献者编写了 98% 的提交
4.1/13.5贡献者广度 — 3 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled3
top_contributor_share0.984
评分方式
46.1/46.8议题解决 — 99% 的议题已关闭
37.7/38.3PR 接受 — 已裁定的 PR 中 2,326/2,362 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs2,326
open_issues31
closed_issues2,401
issue_closed_ratio0.987
closed_unmerged_prs36
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
0/25所有者影响力 — AtlasDevHQ 有 0 位关注者
5.9/25既往记录 — 4 个公开仓库,账户约 0 年
所用输入
followers0
owner_typeOrganization
is_verified
owner_loginAtlasDevHQ
public_repos4
account_age_days147
评分方式
25/25已发布且可解析 — npm 上有 2 个软件包
35/35发布时效 — 最近一次发布于 83 天前
20/20版本历史 — 7 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagescreate-atlas-agent, create-atlas-plugin
ecosystemsnpm
any_deprecated
min_days_since_publish83

工程质量

基础的工程与文档实践是否到位?

69中等 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 12 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 23 out of 23 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

70良好
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.useatlas.dev
0/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepagehttps://www.useatlas.dev
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

70良好 · 占总体的 16%

安全态势

63中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 23 out of 23 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 78 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.3
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
25/25间接依赖不含已知公告 — 没有间接依赖携带已知公告
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages7
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):没有长期未处理的公告。 其余权重已重新归一化。 比对的是 npm:create-atlas-agent@0.3.3 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 7 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

77良好 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md
15/15机器可读文档(llms.txt) — 存在 llms.txt
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes46,249
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — apps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json
10/10可复现环境 — Dockerfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
8/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsapps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
53.9/55可控的文件大小 — 采样的 3,784 个源文件中有 74 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes438,644
source_files_sampled3,784
oversized_source_files74
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — apps/docs/openapi.json
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_filesapps/docs/openapi.json

关键数据

1GitHub 星标
3贡献者
3,439最近 12 个月提交数
0距最近推送天数
68发布版本数
1巴士系数(bus factor)
31开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 3 ⇿
0Star
3Fork
27发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

12233312026-062026-062026-07
主版本 0次版本 0修订 27
OpenSSF Scorecard 6.3 / 10
6.3综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 21:03 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests23 out of 23 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities78 existing vulnerabilities detected
直接依赖 71
注册表软件包版本约束清单文件
npm@clack/prompts^1.6.0create-atlas-plugin/package.json
npmpicocolors^1.1.1create-atlas-plugin/package.json
npm@clack/prompts^1.1.0create-atlas/package.json
npmpicocolors^1.1.1create-atlas/package.json
npm@atlas/apiworkspace:*ee/package.json
npm@useatlas/chatworkspace:*ee/package.json
npm@useatlas/twentyworkspace:*ee/package.json
npm@useatlas/typesworkspace:*ee/package.json
npm@useatlas/webhook-publisherworkspace:*ee/package.json
npmeffect^3.14.8ee/package.json
npmipaddr.js^2.3.0ee/package.json
npmnode-sql-parser^5.4.0ee/package.json
npm@ai-sdk/amazon-bedrock^4.0.119package.json
npm@ai-sdk/anthropic^3.0.85package.json
npm@ai-sdk/gateway^3.0.133package.json
npm@ai-sdk/openai^3.0.74package.json
npm@ai-sdk/provider^3.0.10package.json
npm@ai-sdk/react^3.0.210package.json
npm@aws-sdk/client-bedrock^3.1075.0package.json
npm@better-auth/api-key^1.6.20package.json
npm@better-auth/oauth-provider^1.6.20package.json
npm@better-auth/passkey^1.6.20package.json
npm@better-auth/scim^1.6.20package.json
npm@better-auth/stripe^1.6.20package.json
npm@clack/prompts^1.6.0package.json
npm@clickhouse/client^1.22.0package.json
npm@effect/ai^0.36.0package.json
npm@effect/ai-anthropic^0.26.0package.json
npm@effect/ai-openai^0.39.2package.json
npm@effect/platform^0.96.2package.json
npm@effect/sql^0.51.1package.json
npm@hono/zod-openapi^1.4.0package.json
npm@hookform/resolvers^5.4.0package.json
npm@opentelemetry/exporter-metrics-otlp-http^0.218.0package.json
npm@opentelemetry/exporter-trace-otlp-http^0.218.0package.json
npm@opentelemetry/resources^2.8.0package.json
npm@opentelemetry/sdk-metrics^2.8.0package.json
npm@opentelemetry/sdk-node^0.218.0package.json
npm@opentelemetry/semantic-conventions^1.41.1package.json
npm@radix-ui/react-slot^1.3.0package.json
npm@shikijs/transformers^4.2.0package.json
npm@tailwindcss/cli^4.3.1package.json
npm@tailwindcss/postcss^4.3.1package.json
npm@tanstack/react-query^5.101.1package.json
npm@tanstack/react-query-devtools^5.101.1package.json
npm@types/nodemailer^8.0.1package.json
npmai^6.0.208package.json
npmbetter-auth^1.6.20package.json
npmdate-fns^4.4.0package.json
npmeffect^3.21.4package.json
npmfumadocs-core~16.9.3package.json
npmfumadocs-openapi^10.9.1package.json
npmfumadocs-ui~16.9.3package.json
npmhappy-dom^20.10.6package.json
npmhono^4.12.27package.json
npmipaddr.js^2.4.0package.json
npmjs-yaml^5.1.0package.json
npmjsforce^3.10.16package.json
npmlucide-react^1.21.0package.json
npmmysql2^3.22.4package.json
npmnanoid^5.1.15package.json
npmnext^16.2.9package.json
npmnodemailer^9.0.1package.json
npmobsidian^1.13.1package.json
npmradix-ui^1.6.0package.json
npmreact-dom^19.2.6package.json
npmreact-hook-form^7.80.0package.json
npmreact-resizable-panels^4package.json
npmsnowflake-sdk^2.4.3package.json
npmtailwindcss^4.3.1package.json
npmzustand^5.0.14package.json
全部依赖 161

来自 GitHub 依赖图的完整解析依赖集合:71 个直接依赖与 90 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@ai-sdk/amazon-bedrock^4.0.119直接
npm@ai-sdk/anthropic^3.0.85直接
npm@ai-sdk/gateway^3.0.133直接
npm@ai-sdk/openai^3.0.74直接
npm@ai-sdk/provider^3.0.10直接
npm@ai-sdk/react^3.0.210直接
npm@aws-sdk/client-bedrock^3.1075.0直接
npm@better-auth/api-key^1.6.20直接
npm@better-auth/oauth-provider^1.6.20直接
npm@better-auth/passkey^1.6.20直接
npm@better-auth/scim^1.6.20直接
npm@better-auth/stripe^1.6.20直接
npm@clack/prompts^1.1.0直接
npm@clack/prompts^1.6.0直接
npm@clickhouse/client^1.22.0直接
npm@effect/ai^0.36.0直接
npm@effect/ai-anthropic^0.26.0直接
npm@effect/ai-openai^0.39.2直接
npm@effect/platform^0.96.2直接
npm@effect/sql^0.51.1直接
npm@hono/zod-openapi^1.4.0直接
npm@hookform/resolvers^5.4.0直接
npm@opentelemetry/exporter-metrics-otlp-http^0.218.0直接
npm@opentelemetry/exporter-trace-otlp-http^0.218.0直接
npm@opentelemetry/resources^2.8.0直接
npm@opentelemetry/sdk-metrics^2.8.0直接
npm@opentelemetry/sdk-node^0.218.0直接
npm@opentelemetry/semantic-conventions^1.41.1直接
npm@radix-ui/react-slot^1.3.0直接
npm@shikijs/transformers^4.2.0直接
npm@tailwindcss/cli^4.3.1直接
npm@tailwindcss/postcss^4.3.1直接
npm@tanstack/react-query^5.101.1直接
npm@tanstack/react-query-devtools^5.101.1直接
npm@types/nodemailer^8.0.1直接
npm@useatlas/twenty^0.0.6直接
npm@useatlas/types^0.1.0直接
npm@useatlas/types^0.5.0直接
npm@useatlas/webhook-publisher^0.0.1直接
npmai^6.0.208直接
npmbetter-auth^1.6.16直接
npmbetter-auth^1.6.20直接
npmdate-fns^4.4.0直接
npmeffect^3.14.8直接
npmeffect^3.21.4直接
npmfumadocs-core~16.9.3直接
npmfumadocs-openapi^10.9.1直接
npmfumadocs-ui~16.9.3直接
npmhappy-dom^20.10.6直接
npmhono^4.12.27直接
npmipaddr.js^2.3.0直接
npmipaddr.js^2.4.0直接
npmjs-yaml^5.1.0直接
npmjsforce^3.10.16直接
npmlucide-react^1.21.0直接
npmmysql2^3.22.4直接
npmnanoid^5.1.15直接
npmnext^16.2.1直接
npmnext^16.2.9直接
npmnode-sql-parser^5.4.0直接
npmnodemailer^9.0.1直接
npmobsidian^1.13.1直接
npmpicocolors^1.1.1直接
npmradix-ui^1.6.0直接
npmreact-dom^19.2.4直接
npmreact-dom^19.2.6直接
npmreact-hook-form^7.80.0直接
npmreact-resizable-panels^4直接
npmsnowflake-sdk^2.4.3直接
npmtailwindcss^4.3.1直接
npmzustand^5.0.14直接
npm@axe-core/playwright^4.11.3间接
npm@better-auth/agent-auth0.6.2间接
npm@chat-adapter/discord4.23.0间接
npm@chat-adapter/gchat4.23.0间接
npm@chat-adapter/github4.23.0间接
npm@chat-adapter/linear4.23.0间接
npm@chat-adapter/slack4.23.0间接
npm@chat-adapter/state-memory4.23.0间接
npm@chat-adapter/teams4.23.0间接
npm@chat-adapter/telegram4.23.0间接
npm@chat-adapter/whatsapp4.23.0间接
npm@daytonaio/sdk^0.185.0间接
npm@dnd-kit/core^6.3.1间接
npm@dnd-kit/modifiers^9.0.0间接
npm@dnd-kit/sortable^10.0.0间接
npm@dnd-kit/utilities^3.2.2间接
npm@duckdb/node-api^1.5.3-r.3间接
npm@effect/experimental^0.60.0间接
npm@effect/sql-mysql2^0.52.0间接
npm@effect/sql-pg^0.52.1间接
npm@modelcontextprotocol/sdk^1.29.0间接
npm@opentelemetry/api^1.9.1间接
npm@playwright/test^1.60.0间接
npm@tanstack/react-table^8.21.3间接
npm@testing-library/dom^10.4.1间接
npm@testing-library/react^16.3.2间接
npm@types/bun^1.3.14间接
npm@types/diff^8.0.0间接
npm@types/json-schema^7.0.15间接
npm@types/node^25.9.4间接
npm@types/pg^8.20.0间接
npm@types/react^19.2.14间接
npm@types/react^19.2.15间接
npm@types/react-dom^19.2.3间接
npm@types/react-syntax-highlighter^15.5.13间接
npm@typescript/native-preview^7.0.0-dev.20260623.1间接
npm@useatlas/react^0.2.0间接
npm@useatlas/sdk^0.1.0间接
npm@vercel/og0.11.1间接
npm@vercel/sandbox^2间接
npm@vercel/sandbox^2.2.1间接
npmbabel-plugin-react-compiler^1.0.0间接
npmbetter-auth-harmony^1.3.2间接
npmchat4.23.0间接
npmclass-variance-authority^0.7.1间接
npmclsx^2.1.1间接
npmcmdk^1.1.1间接
npmcroner^10.0.1间接
npmdiff^9.0.0间接
npmdomhandler^5.0.3间接
npmdrizzle-kit^0.31.10间接
npmdrizzle-orm^0.45.2间接
npme2b^2.28.2间接
npmentities^4.5.0间接
npmesbuild^0.28.1间接
npmexceljs^4.4.0间接
npmfflate^0.8.2间接
npmfumadocs-mdx^15.0.12间接
npmgithub-slugger2.0.0间接
npmhtmlparser2^9.1.0间接
npminput-otp^1.4.2间接
npmjose^6.2.3间接
npmjust-bash^3.0.2间接
npmnext-themes^0.4.6间接
npmnuqs^2.8.9间接
npmoxlint^1.72.0间接
npmoxlint-plugin-eslint^1.72.0间接
npmoxlint-tsgolint^0.24.0间接
npmpg^8.22.0间接
npmpg-mem^3.0.14间接
npmpino^10.3.1间接
npmpino-pretty^13.1.3间接
npmreact^19.2.4间接
npmreact^19.2.6间接
npmreact-day-picker^10.0.1间接
npmreact-grid-layout^2.2.3间接
npmreact-markdown^10.1.0间接
npmreact-syntax-highlighter^16.1.1间接
npmrecharts^3.8.1间接
npmremark-gfm^4.0.1间接
npmshadcn^4.11.0间接
npmsonner^2.0.7间接
npmstripe^22.2.3间接
npmsyncpack^15.3.2间接
npmtailwind-merge^3.5.0间接
npmtsup^8.5.1间接
npmtw-animate-css^1.4.0间接
npmtypescript^6.0.2间接
npmtypescript^6.0.3间接
npmzod^4.4.3间接
依赖安全公告 0

安装 npm:create-atlas-agent@0.3.3 会引入 7 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 99999,
      "has_wiki": false,
      "homepage": "https://www.useatlas.dev",
      "languages": {
        "CSS": 41037,
        "MDX": 2692397,
        "HTML": 137557,
        "Shell": 290001,
        "PLpgSQL": 94877,
        "Dockerfile": 37544,
        "JavaScript": 3712576,
        "TypeScript": 42492708
      },
      "pushed_at": "2026-07-25T21:00:48Z",
      "created_at": "2026-03-05T12:44:30Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T22:00:55Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "AtlasDevHQ",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/264680315?v=4",
      "created_at": "2026-02-28T19:12:52Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 147
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-24T18:52:28Z"
        },
        {
          "tag": "v0.0.67",
          "kind": "patch",
          "published_at": "2026-07-23T00:27:02Z"
        },
        {
          "tag": "v0.0.66",
          "kind": "patch",
          "published_at": "2026-07-19T23:37:28Z"
        },
        {
          "tag": "v0.0.65",
          "kind": "patch",
          "published_at": "2026-07-19T23:12:14Z"
        },
        {
          "tag": "v0.0.64",
          "kind": "patch",
          "published_at": "2026-07-19T22:39:41Z"
        },
        {
          "tag": "v0.0.63",
          "kind": "patch",
          "published_at": "2026-07-19T22:26:24Z"
        },
        {
          "tag": "v0.0.62",
          "kind": "patch",
          "published_at": "2026-07-19T21:06:54Z"
        },
        {
          "tag": "v0.0.61",
          "kind": "patch",
          "published_at": "2026-07-19T19:53:01Z"
        },
        {
          "tag": "v0.0.60",
          "kind": "patch",
          "published_at": "2026-07-19T18:55:35Z"
        },
        {
          "tag": "v0.0.59",
          "kind": "patch",
          "published_at": "2026-07-19T16:06:15Z"
        },
        {
          "tag": "v0.0.58",
          "kind": "patch",
          "published_at": "2026-07-18T21:32:36Z"
        },
        {
          "tag": "v0.0.57",
          "kind": "patch",
          "published_at": "2026-07-18T18:31:06Z"
        },
        {
          "tag": "v0.0.56",
          "kind": "patch",
          "published_at": "2026-07-18T17:32:31Z"
        },
        {
          "tag": "v0.0.55",
          "kind": "patch",
          "published_at": "2026-07-17T19:28:57Z"
        },
        {
          "tag": "v0.0.54",
          "kind": "patch",
          "published_at": "2026-07-13T20:44:20Z"
        },
        {
          "tag": "v0.0.53",
          "kind": "patch",
          "published_at": "2026-07-13T20:00:57Z"
        },
        {
          "tag": "v0.0.52",
          "kind": "patch",
          "published_at": "2026-07-13T18:22:04Z"
        },
        {
          "tag": "v0.0.51",
          "kind": "patch",
          "published_at": "2026-07-13T15:13:58Z"
        },
        {
          "tag": "v0.0.50",
          "kind": "patch",
          "published_at": "2026-07-13T14:01:15Z"
        },
        {
          "tag": "v0.0.49",
          "kind": "patch",
          "published_at": "2026-07-12T13:39:30Z"
        },
        {
          "tag": "v0.0.48",
          "kind": "patch",
          "published_at": "2026-07-12T03:16:56Z"
        },
        {
          "tag": "v0.0.47",
          "kind": "patch",
          "published_at": "2026-07-11T01:40:49Z"
        },
        {
          "tag": "v0.0.46",
          "kind": "patch",
          "published_at": "2026-07-10T22:01:44Z"
        },
        {
          "tag": "v0.0.45",
          "kind": "patch",
          "published_at": "2026-07-10T22:01:43Z"
        },
        {
          "tag": "v0.0.44",
          "kind": "patch",
          "published_at": "2026-07-05T15:51:11Z"
        },
        {
          "tag": "v0.0.43",
          "kind": "patch",
          "published_at": "2026-07-04T22:37:32Z"
        },
        {
          "tag": "v0.0.42",
          "kind": "patch",
          "published_at": "2026-07-04T01:20:07Z"
        },
        {
          "tag": "v0.0.41",
          "kind": "patch",
          "published_at": "2026-07-03T17:15:18Z"
        },
        {
          "tag": "v0.0.40",
          "kind": "patch",
          "published_at": "2026-07-02T19:07:08Z"
        },
        {
          "tag": "v0.0.39",
          "kind": "patch",
          "published_at": "2026-07-02T01:17:13Z"
        },
        {
          "tag": "v0.0.38",
          "kind": "patch",
          "published_at": "2026-07-01T21:30:00Z"
        },
        {
          "tag": "v0.0.37",
          "kind": "patch",
          "published_at": "2026-07-01T17:39:47Z"
        },
        {
          "tag": "v0.0.36",
          "kind": "patch",
          "published_at": "2026-07-01T12:44:22Z"
        },
        {
          "tag": "v0.0.35",
          "kind": "patch",
          "published_at": "2026-06-29T17:57:02Z"
        },
        {
          "tag": "v0.0.34",
          "kind": "patch",
          "published_at": "2026-06-29T01:45:27Z"
        },
        {
          "tag": "v0.0.33",
          "kind": "patch",
          "published_at": "2026-06-28T21:21:39Z"
        },
        {
          "tag": "v0.0.32",
          "kind": "patch",
          "published_at": "2026-06-27T02:01:03Z"
        },
        {
          "tag": "v0.0.31",
          "kind": "patch",
          "published_at": "2026-06-26T23:33:59Z"
        },
        {
          "tag": "v0.0.30",
          "kind": "patch",
          "published_at": "2026-06-26T16:40:37Z"
        },
        {
          "tag": "v0.0.29",
          "kind": "patch",
          "published_at": "2026-06-25T17:52:33Z"
        },
        {
          "tag": "v0.0.28",
          "kind": "patch",
          "published_at": "2026-06-25T15:17:33Z"
        },
        {
          "tag": "v0.0.27",
          "kind": "patch",
          "published_at": "2026-06-25T11:34:59Z"
        },
        {
          "tag": "v0.0.26",
          "kind": "patch",
          "published_at": "2026-06-24T16:41:55Z"
        },
        {
          "tag": "v0.0.25",
          "kind": "patch",
          "published_at": "2026-06-23T19:41:23Z"
        },
        {
          "tag": "v0.0.24",
          "kind": "patch",
          "published_at": "2026-06-23T18:11:43Z"
        },
        {
          "tag": "v0.0.23",
          "kind": "patch",
          "published_at": "2026-06-23T13:38:31Z"
        },
        {
          "tag": "v0.0.22",
          "kind": "patch",
          "published_at": "2026-06-23T12:00:26Z"
        },
        {
          "tag": "v0.0.21",
          "kind": "patch",
          "published_at": "2026-06-22T18:00:07Z"
        },
        {
          "tag": "v0.0.20",
          "kind": "patch",
          "published_at": "2026-06-20T20:38:04Z"
        },
        {
          "tag": "v0.0.19",
          "kind": "patch",
          "published_at": "2026-06-19T14:47:32Z"
        },
        {
          "tag": "v0.0.18",
          "kind": "patch",
          "published_at": "2026-06-18T20:27:21Z"
        },
        {
          "tag": "v0.0.17",
          "kind": "patch",
          "published_at": "2026-06-17T16:56:54Z"
        },
        {
          "tag": "v0.0.16",
          "kind": "patch",
          "published_at": "2026-06-15T20:55:52Z"
        },
        {
          "tag": "v0.0.15",
          "kind": "patch",
          "published_at": "2026-06-14T21:14:11Z"
        },
        {
          "tag": "v0.0.14",
          "kind": "patch",
          "published_at": "2026-06-13T15:51:50Z"
        },
        {
          "tag": "v0.0.13",
          "kind": "patch",
          "published_at": "2026-06-12T15:07:05Z"
        },
        {
          "tag": "v0.0.12",
          "kind": "patch",
          "published_at": "2026-06-06T22:29:39Z"
        },
        {
          "tag": "v0.0.11",
          "kind": "patch",
          "published_at": "2026-06-06T01:12:58Z"
        },
        {
          "tag": "v0.0.10",
          "kind": "patch",
          "published_at": "2026-06-05T19:41:52Z"
        },
        {
          "tag": "v0.0.9",
          "kind": "patch",
          "published_at": "2026-06-05T00:55:36Z"
        },
        {
          "tag": "v0.0.8",
          "kind": "patch",
          "published_at": "2026-06-03T21:14:51Z"
        },
        {
          "tag": "v0.0.7",
          "kind": "patch",
          "published_at": "2026-06-03T14:59:50Z"
        },
        {
          "tag": "v0.0.6",
          "kind": "patch",
          "published_at": "2026-06-03T00:34:16Z"
        },
        {
          "tag": "v0.0.5",
          "kind": "patch",
          "published_at": "2026-06-02T15:53:26Z"
        },
        {
          "tag": "v0.0.4",
          "kind": "patch",
          "published_at": "2026-06-02T00:50:32Z"
        },
        {
          "tag": "v0.0.3",
          "kind": "patch",
          "published_at": "2026-06-01T00:03:31Z"
        },
        {
          "tag": "v0.0.2",
          "kind": "patch",
          "published_at": "2026-05-31T15:08:47Z"
        },
        {
          "tag": "v0.0.1",
          "kind": "patch",
          "published_at": "2026-05-29T03:29:21Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ae4b7320a8571d52b0be6b1857da0eaa8dd18538",
          "body": "…mode (#4795)\n\nBrain M1 (milestone #91, issues #4767-#4775) is a nine-issue vertical slice\nthat should not reach main half-built while the v0.1.0 tag is still uncut.\nIt will accumulate on `milestone/v0.2.0-brain-m1` and land as one merge.\n\nWithout this, a PR stacked onto that branch runs ZERO requir\n[…]\ne,\n  and merges into it are discipline-gated, not protection-gated.\n\nNo untrusted input reaches any run: block; fork PRs arrive as pull_request,\nnever push, so the push filter adds no trigger surface.",
          "is_bot": false,
          "headline": "ci: gate milestone/** integration branches; add ship-issue milestone …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T22:00:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4703ed877156e992c77ef9796cfb3b23fa305c9",
          "body": "…on' (#4788)\n\nWalks back the chat-availability wording merged in #4787, which was\nwritten on a wrong premise ('only Slack is live'). Verified against\nplugins/chat/src/adapter-registry.ts + the static-bot install handlers\nand deploy/api/atlas.config.ts (no overrideImplementationStatus):\n\n  Slack — on\n[…]\n'installable today, Google Chat coming soon'. Region + /security fixes\nfrom #4787 are correct and unaffected. Blog announcing-atlas left\nuntouched (its 'Eight integrations' line was already accurate).",
          "is_bot": false,
          "headline": "www/docs: correct chat-reach copy — installable today, not 'coming so…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T17:48:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4aa9a583b08e7d70241dae6d80a4c1275167bc7",
          "body": "- Regions → area-level (US/EU/APAC), dropping city/country pins so copy\n  stays true as physical regions move. Resolves the EU www-vs-docs\n  mismatch (www: Netherlands/Eemshaven, docs: Ireland). Real Railway EU\n  region is europe-west4 (Netherlands); genericized rather than pinned.\n- /security: rewo\n[…]\nnding comparison: add '(Slack live; Google Chat coming soon)' caveat.\n- NOT touched: DPA Ireland governing-law/forum (legal jurisdiction);\n  blog/announcing-atlas (launch content, flagged separately).",
          "is_bot": false,
          "headline": "www/docs: fix accuracy drifts from /www-audit (#4787)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T16:52:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d13cb3ffffec94f44edc134c4a7b85c40671a71b",
          "body": "…tus decision closed",
          "is_bot": false,
          "headline": "docs(roadmap): v0.1.0 milestone fully clear — security pass + OpenSta…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T14:11:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ae60d79c84c8c14adfda12e5600100c1b332e7b",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): bank the #4785 explore/sandbox hardening ship (PR #4786)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T14:00:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4179888be55967d648988f5565913f01c624ecd2",
          "body": "…ainment docs (#4785) (#4786)\n\nDefense-in-depth residue from the #3351 live security pass:\n\n- explore/nsjail output truncation is now surfaced from a byte-accurate flag\n  (readLimited -> { text, truncated }, threaded onto ExecResult, marked at the\n  tool seam via markCappedStream) instead of re-deri\n[…]\ns reword).\n- Documented that the vercel-sandbox deny-all policy does not block the\n  link-local Firecracker MMDS (provider-controlled, not app-blockable) rather\n  than shipping a non-functional block.",
          "is_bot": false,
          "headline": "fix(sandbox): byte-accurate explore truncation signal + accurate cont…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T13:59:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8bf15aeae66a019c421ce3bb6f08e89fa2c9a720",
          "body": "…4779/#4780/#4781); #3351 findings closed",
          "is_bot": false,
          "headline": "docs(roadmap): tidy — bank the 2026-07-24 security-pass ship-batch (#…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T13:25:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e5a9e561ffc4ec626e272e8c5b1c7bd5e7a9670",
          "body": "…#4779) (#4784)\n\n* fix(security): DNS-aware egress guard closes hostname→internal SSRF (#4779)\n\nisSafeExternalUrl is synchronous (it backs a Zod refine) so a public\nhostname that RESOLVES to an internal IP (e.g. 127.0.0.1.nip.io, cloud\nmetadata via wildcard DNS, or a live DNS-rebind record) passed t\n[…]\nk proving\n  getModelFromWorkspaceConfig installs createGuardedFetch() on the custom\n  provider (captures the fetch option; a literal internal IP is rejected by the\n  guard's sync first pass — no DNS).",
          "is_bot": false,
          "headline": "fix(security): DNS-aware egress guard closes hostname→internal SSRF (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T13:19:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31ac41450f5ac44698d765f2d318eb2e24231d24",
          "body": "…#4781) (#4783)\n\nThe /api/v1/explore endpoint + agent-facing tool description advertised a\npath-jail ('read-only, path-traversal-protected access scoped to semantic/;\nwrites, shell escapes, and traversal outside the semantic directory are\nrejected') that the sandbox backend does not enforce. On SaaS\n[…]\negenerated openapi.json + api-reference MDX.\n\nDoc-first accuracy fix; the optional defense-in-depth items (block link-local\n169.254.0.0/16 egress; add a truncated flag to capped output) are split out.",
          "is_bot": false,
          "headline": "docs(explore): reword containment claims to match enforced behavior (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T12:59:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0793899c5d57b1c3e0243f4e59f49f0f58f9d4f1",
          "body": "…t (#4780) (#4782)\n\nTwo authenticated DoS levers via unbounded parser inputs, from the #3351 live pass:\n\n- validate-sql accepted a 2 MB `sql` body (no cap) while execute-sql capped at\n  100k; both feed the same node-sql-parser on the API event loop. Hoist\n  `MAX_SQL_LEN` into lib/tools/sql.ts (the p\n[…]\n22 (never reaches parse/persist) and at-cap ->\naccepted, for both caps. Pure input-bound hardening; no behavior change for\nlegitimate inputs. openapi.json regenerated for the two new maxLength bounds.",
          "is_bot": false,
          "headline": "fix(api): cap parser-fed inputs — validate-sql sql + admin yamlConten…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T12:53:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed5d6fbfdaaa013c251093b0946ffbae69476273",
          "body": "… ride next tag (#4778)\n\nv0.0.67 (Seam Consolidation & Aggregate-Review Hardening) tagged @ 343215486\n2026-07-22 but was still framed as unreleased. Bank it to History, update the\nlatest-tag pointer, and reframe Next: the query soft-deadline (#4741) shipped\nin v0.0.67; per-tier KB caps (#4235) + tool-span coverage (#4464) ride v0.0.68.",
          "is_bot": false,
          "headline": "docs(roadmap): tidy — bank v0.0.67 into History; KB caps + tool-spans…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T02:33:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9f9c2bfa6ab0a59ad8a9521b09464daf06cd16",
          "body": "Road-to-launch note covering the month since the beta recap: making\nAtlas Cloud's promises mechanical (self-verifying backups, executing\nresidency deletion, an honest sandbox carve-out) and six MCP fixes\nforced by real AI clients. Wires the post into POSTS (sitemap auto-derives).",
          "is_bot": false,
          "headline": "feat(www): add \"The last mile\" blog post (#4777)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T02:24:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9505978e01e61654c11f238b5ca97856b82d6d33",
          "body": "…7–#4775 (#4776)\n\nAdds the v0.2.0 — Brain M1: Thin Wedge Slice planned-tag entry (ADR-0036\nmilestone cut, parked until v0.1.0 ships per the re-aim guide).\n\nClaude-Session: https://claude.ai/code/session_01SBCZPiF95TDTLqfnzENRXn",
          "is_bot": false,
          "headline": "docs(roadmap): bank the Brain M1 kickoff — milestone #91, issues #476…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T01:34:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5afec03675512085b98965e4149b3fe11686803",
          "body": "…#4755) (#4766)\n\nThe synthesis/handoff ADR for the \"Atlas as the company brain\" wayfinder\nmap (#4755, all ten decision tickets closed). Each section is one locked\ndecision (T2-T10); T1's landscape research grounds the Context section\nand lands alongside as .claude/research/4756-company-brain-landsca\n[…]\nefault) are folded in. Per T10's disposition, ADR-0028/\n0020/0030 are deliberately untouched; the 0028 amendment lands with M1.\n\nClaude-Session: https://claude.ai/code/session_01SBCZPiF95TDTLqfnzENRXn",
          "is_bot": false,
          "headline": "docs(adr): ADR-0036 — Atlas becomes the data-grounded company brain (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-24T01:19:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2634b5b7ec9fb286c36ebbdd2aff77b4d572d5fe",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): tidy — bank the tool-span coverage ship (#4464)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T18:27:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63433c2d3905b4eeb5069aa0de3cc25fc0872465",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): bank the per-tier KB caps ship (#4235)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T18:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6184cf69b2848a08ee92107c3dd501ad1e309f05",
          "body": "* feat(billing): per-tier Knowledge Base caps as a SaaS entitlement lever (#4235)\n\nKB ingest caps shipped platform-scoped only (`ATLAS_KNOWLEDGE_INGEST_*`), so\non SaaS the only lever for an enterprise customer's 100 MB knowledge base was\nraising the cap for every tenant in the region. KB size is sto\n[…]\nthe getWorkspaceDetails-null coupling.\n- Drop a duplicate assertion; fix two indentation nits.\n\n* fix(test): correct api-test-mocks alias + add maxKnowledgeCollections to billing wire fixtures (#4235)",
          "is_bot": false,
          "headline": "feat: per-tier Knowledge Base caps as a SaaS entitlement lever (#4754)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T18:08:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d77f7821bbc60e42420d82e8fe04755ae7cb3f1a",
          "body": "…64) (#4753)\n\n`searchKnowledge`, `createDashboard`, `executeRestOperation` and the action\ntools carried no `atlas.*` span of their own — only the tools that remembered\nto self-instrument did — so latency couldn't be attributed within a turn from\nthe `atlas.`-prefixed views. The registry had no span \n[…]\nthe grandfathered off-prefix names, which are documented\nrather than renamed since renames break live dashboards. The operator-facing\nobservability page is updated for the new hierarchy.\n\nCloses #4464",
          "is_bot": false,
          "headline": "feat(telemetry): trace every agent tool at the ToolRegistry seam (#44…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T16:31:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f96ddb33a5c46863f5c5383fa19de97282f9b743",
          "body": "…ening",
          "is_bot": false,
          "headline": "docs(changelog): v0.0.67 — Seam Consolidation & Aggregate-Review Hard…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T00:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3432154863e6a984286e4b635006f83b528c8687",
          "body": "…ardown no-op, doc drift (#4751) (#4752)\n\n* fix(plugins,docs): aggregate-review residue — restore tenant-isolation guard, close silent credential-teardown no-op (#4751)\n\n* fix(review): .js import extension, tighten deadline comment, cover S3 endpoint field (#4751)",
          "is_bot": false,
          "headline": "fix: aggregate-review residue — tenant-isolation guard, credential-te…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-23T00:16:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0055ac396a12d5b7abab3fb994e8d2c3883e9c38",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): tidy — bank the 2026-07-22 ship-batch runs (9 issues)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T23:38:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e619dd92b2c9101a02136b69cc8490a60a83057f",
          "body": "…eOrgContext (#4356) (#4748)\n\n* refactor(api): migrate inline org-context null checks onto requireOrgContext (#4356)\n\n`requireOrgContext()` is the canonical org-context seam, but ~53 handlers\nhand-rolled the identical check inline and the copies had drifted into 5\ndifferent messages and 4 different \n[…]\nno_organization` / `org_required` codes stay the onboarding contract.\nRecorded in the `noActiveOrgBody` doc comment.\n\n* docs(api): note admin-model-config in the noActiveOrgBody carve-out list (#4356)",
          "is_bot": false,
          "headline": "refactor(api): migrate the inline org-context null checks onto requir…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T23:17:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fc33d3b6d61b1c51a98ea6cb8f2df5b6c328bcf",
          "body": "…#4750)\n\n* refactor(api): give conversation scope a first-class module (#4351)\n\nConversation scope (SQL routing + REST scope + reach + voice, ADR-0011 /\nADR-0022) was a loose column bag: five byte-identical-bar-the-column\nwriters, an 11-column INSERT hand-copied per id-branch, and five parallel\ndecl\n[…]\nity note: the SET list is built from\n  the closed `CONVERSATION_SCOPE_COLUMNS` constant, never caller input; every\n  value is bound.\n- Comment fix: five axes ⇒ up to five independent writes, not four.",
          "is_bot": false,
          "headline": "refactor(api): give conversation scope a first-class module (#4351) (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T23:07:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb3b5eda1ee8491f7d84a6f4a9b8e38839098f22",
          "body": "…ll shim into tearDownWorkspaceInstall (#4353) (#4749)\n\n* refactor(plugins): one teardown contract — fold the hook-only uninstall shim into tearDownWorkspaceInstall (#4353)\n\n`invokeOnUninstallHookForInstallRow` resolved `(catalog_id, slug)` from an\ninstallation id and then ran the `onUninstall` hook\n[…]\nat shape.\n\nDeliberately NOT re-derived from the DELETE's RETURNING tuple: that second\npath is exactly what this issue removes, and post-DELETE the hook could no\nlonger authenticate to revoke anything.",
          "is_bot": false,
          "headline": "refactor(plugins): one teardown contract — fold the hook-only uninsta…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T23:01:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac79ae0091d2e6addf777a20ac9c90083d3ed46b",
          "body": "…dsAtFrom (#4354) (#4747)\n\n* refactor(billing): route every trial-clock stamper through fullTrialEndsAtFrom (#4354)\n\nThe rule \"a full trial clock = now + TRIAL_DAYS\" lived in four places: the\ncanonical stamper `fullTrialEndsAtFrom` (one caller), the reader\n`effectiveTrialEndsAt` which independently \n[…]\nds are what actually catch a re-inlined stamper;\n- correct the DST wording (the table straddles a US spring-forward and sits\n  on the edge of an EU fall-back) and note TZ-invariance of the assertions.",
          "is_bot": false,
          "headline": "refactor(billing): route all trial-clock stampers through fullTrialEn…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T22:53:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a397877bb3e2deb7d16bebaa101cb59fd4292cc",
          "body": "…e (ADR-0035) (#4746)\n\n* refactor(notebook): phase-2 — DROP COLUMN conversations.notebook_state (ADR-0035)\n\nContract half of the two-phase drop staged by #4587 (phase 1, shipped in\nv0.0.47): migration 0179 drops `conversations.notebook_state`, and the\nDrizzle mirror is removed in the same commit so \n[…]\ndy removed in #4587 and migration\n0169 converted the remaining rows to `'web'` — no wire-type work remains.\n\nCloses #4588\n\n* style(schema): separate the notebook tombstone from the org-scoping comment",
          "is_bot": false,
          "headline": "refactor(notebook): phase-2 — DROP COLUMN conversations.notebook_stat…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T22:51:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6724e46ea776feaf69f197c2fe06602a84fd930",
          "body": "…path (#4745)\n\n* feat(backups): abort stale incomplete multipart uploads in the purge path (#4727)\n\nA failed S3 backup upload deliberately never finalizes — finalizing would\nproduce a truncated object that could pass a header-only verify. The parts\nalready uploaded therefore linger as an incomplete \n[…]\n\n\n* docs(backups): correct the degradation-level note after the 403 carve-out\n\nThe module header still claimed every unsupported response no-ops at debug\nlevel; a 403 now warns with the grants to add.",
          "is_bot": false,
          "headline": "feat(backups): abort stale incomplete multipart uploads in the purge …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T21:24:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4de4d679cb10f02e52c79eae4337e7360cbe30a",
          "body": "… checkout (#4655) (#4744)\n\nThe dual-write sync layer persists per-org YAML under\n`{getSemanticRoot()}/.orgs/<orgId>/`, and `getSemanticRoot()` defaults to\n`{cwd}/semantic`. Every suite exercising the real write path (the `-pg`\namendment / connection-profile family, the wizard, `importFromDisk`) the\n[…]\nor the env override.\n- New `src/__tests__/semantic-root-sandbox.test.ts` pins the contract, including\n  an end-to-end `syncEntityToDisk` that asserts `{cwd}/semantic` is never\n  created.\n\nCloses #4655",
          "is_bot": false,
          "headline": "fix(test): sandbox the semantic root so -pg suites stop littering the…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T21:20:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e95f4b31a37734446f23b869c09d17b6cb2f3c37",
          "body": "… (#4462) (#4743)\n\n* fix(settings): lock RESEND_API_KEY + ATLAS_PROVIDER as SaaS-immutable (#4462)\n\nBoth keys are validated by a SaaS boot guard yet were freely mutable at\nruntime. Deleting a registry-only RESEND_API_KEY override post-boot\nsilently flips the platform email transport to the ATLAS_SMT\n[…]\n\"live cache\" read as the internal `_liveCache`; say what\nactually happens (setSetting updates the in-process cache getSetting /\ngetSettingAuto read). Name the 409 envelope explicitly in the admin doc.",
          "is_bot": false,
          "headline": "fix(settings): lock RESEND_API_KEY + ATLAS_PROVIDER as SaaS-immutable…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T21:14:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4672d268c89eef1a6a6471635e97ff8fa3fd996",
          "body": "* test(mcp): stub the billing agent-gate in smoke.test.ts (#4370)\n\n`smoke.test.ts` was the only MCP test that did not stub\n`@atlas/api/lib/billing/agent-gate`, so its `executeSQL` dispatch ran the\nreal billing enforcement gate. That gate reads the internal DB\n(`organization` / `settings`) and fails \n[…]\niew panel: the codebase numbers the billing gate as gate 0\n(datasource-tools.ts, dispatch-gate.ts) — action-policy is gate 1,\nmcp:write is gate 2, RBAC is gate 3. The new stub's comment said\n\"Gate-2\".",
          "is_bot": false,
          "headline": "test(mcp): stub the billing agent-gate in smoke.test.ts (#4742)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T21:07:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f391e7fb990b8a4d660b5491ecff3cd196506561",
          "body": "ROADMAP's History stopped at v0.0.57 while nine tags shipped (the backups +\nresidency wave, then the eight-tag hosted-MCP fix train). Adds one line per\ntag, collapses the now-tagged v0.0.58 bullet out of Planned tags, and points\nthe \"latest tag\" statements at v0.0.66 with the #4741 soft-deadline follow-on\nnoted as riding the next tag.",
          "is_bot": false,
          "headline": "docs(roadmap): tidy — bank v0.0.58 through v0.0.66 into History",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T19:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1783bc0407d1ef0bbb931a0b3f6310c6f11fae8a",
          "body": "…velope (#4734) (#4741)\n\n* fix(mcp): cap the query agent run with a soft deadline + query_timeout envelope (#4734)\n\nCorrected root cause (verified live against prod): the >120s drop is NOT a\nRailway edge idle-timeout the server can defeat — it's the MCP CLIENT's own\nrequest-timeout ceiling (~120s), \n[…]\nthe resolve path too and share one envelope builder\nacross both exits. Docs + the `AtlasMcpToolErrorCode` comment described\n`query_timeout` as statement_timeout only; both now cover the agent-run cap.",
          "is_bot": false,
          "headline": "fix(mcp): cap query agent run with a soft deadline + query_timeout en…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-22T19:52:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5dc1b3fb4b118e416c96046b53b01597266fb08c",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.66 — Hosted-MCP Query Keepalive",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T23:37:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8105484d907c7461dd817c61ce5603b49e0f273",
          "body": "…#4734) (#4740)\n\nVerified live against prod: a >120s query STILL dropped the transport after the\nprogress-heartbeat fix, because the heartbeat only puts bytes on the wire when\nthe client sent a progressToken — and the reporting client (and this Claude Code\nMCP client) doesn't. The heartbeat was a no\n[…]\nytes naturally suppress the keepalive.\n\nTests: stream-liveness.test.ts — keepalive injected during idle gaps with data\nintact + in order; no keepalive when keepaliveMs omitted (GET streams unchanged).",
          "is_bot": false,
          "headline": "fix(mcp): transport-agnostic SSE keepalive on POST tool-call stream (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T23:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "063f1de0574e3af394c6eba7088970c8d7ffbcb7",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.65 — describeEntity Display-Name Fix",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T23:12:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbfdfe73953289ab416ba3d8d88e65c0258a44d6",
          "body": "… too (#4733 follow-up) (#4739)\n\nVerified live against hosted prod after the first #4733 fix: describing a\ngroup-scoped entity by its TABLE worked, but by the NAME listEntities advertises\nstill 404'd — the exact reported symptom (describeEntity({name:\"Conversation\"})\n=> unknown_entity) was still liv\n[…]\nsly conflated the name column with the YAML name, so\nit passed while prod failed. Fixture now models all three identifiers distinctly\n(column=stem, name=display, table) and asserts resolution by each.",
          "is_bot": false,
          "headline": "fix(mcp): describeEntity resolves entities by their YAML display name…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T23:11:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8658344ae3d1ae2bc587519975a808e102aaa020",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.64 — Hosted-MCP Deploy Fix",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T22:39:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20548b52013e536505eb7655e3f219a097ec7a89",
          "body": "…eploy (#4737)\n\nThe api service (all 3 regions) serves the hosted MCP — it depends on\n@atlas/mcp (workspace:*) and bundles packages/mcp into its image. But\ndeploy/api*/railway.json watchPatterns omitted packages/mcp/**, so a change\nconfined to packages/mcp produced skippedReason:'No changes to watch\n[…]\nson copies, covered by packages/**/package.json); the broad 'COPY . .'\nthat bundles mcp source is invisible to it. Broader watchPatterns-vs-workspace-dep\naudit + gate extension tracked as a follow-up.",
          "is_bot": false,
          "headline": "fix(deploy): watch packages/mcp in api services so hosted-MCP fixes d…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T22:38:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ed0095bd79af9d7745f4694ee70fc3351ca41a8",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.63 — Hosted-MCP Tool Fixes",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T22:26:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ab3c04b30c09a5ac26d23a6fa5606ae630f5dc0",
          "body": "…t drop transport (#4734) (#4736)\n\nThe query POST response is a Streamable-HTTP text/event-stream that emits zero\napplication bytes during the server-side agent run, so an intermediary\nidle-timeout (Railway edge/LB, ~120s) closes it before a long run finishes →\nclient sees 'transport dropped'.\n\nAdd \n[…]\n.test.ts (heartbeat helper — monotonic <1, stop clears timer,\nend-to-end monotonicity through the wrapper), query-tool.test.ts (interim\nprogress fires during a >interval run; timer cleared on settle).",
          "is_bot": false,
          "headline": "fix(mcp): keepalive heartbeat on hosted query tool so >120s runs don'…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T22:21:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99afdbaa696ea12ff4333b997d1e7f46500a6f2d",
          "body": "…d DB path (#4733) (#4735)\n\ndescribeEntity called the disk-only getEntityByName while listEntities reads\nthe org-scoped semantic_entities DB. On SaaS (entities are DB-only) every\ndescribe of a group-scoped entity missed → unknown_entity, even for names\nlistEntities returns.\n\nRoute describeEntity thr\n[…]\nti-group → validation_failed);\nthe no-DB disk path stays covered by lookups.test.ts + the canonical MCP eval.\ntelemetry.test.ts gains the AmbiguousEntityError re-export + a hermetic\nadmin-source mock.",
          "is_bot": false,
          "headline": "fix(mcp): describeEntity resolves group-scoped entities via org-scope…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T22:14:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "890aa157a250e04e9c0b4d7d7555f8802d86db90",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.62 — Hosted-MCP Transport Fix",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T21:07:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "227eb0db81b700997bfb232ea9088845268b3624",
          "body": "…across installer, SDK, wizard, docs (#4732)\n\nHosted MCP clients that followed Atlas's own setup surfaces got a config\nspeaking the deprecated HTTP+SSE transport against a Streamable-HTTP-only\nendpoint: OAuth completed, then the first request 400'd. Root cause was a\n`/sse` connect URL plus a missing\n[…]\n JSON example; SDK + load-test docs. Self-hosted --transport sse\n  (standalone server's own listener) and legacy-alias notes left intact.\n\nDependency refs stay pinned; publish tags follow after merge.",
          "is_bot": false,
          "headline": "fix(mcp): emit canonical Streamable-HTTP config (type:http, no /sse) …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T20:51:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a890ea6aa90b26dc4d713e4a7527739b74e22b5",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.61 — Scheduled-Backup Hang Fix",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T19:53:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfadbeab4d540c4b47aab3045e87992001f8bf86",
          "body": "… await (#4731)\n\nScheduled backups have never once succeeded in prod: every region sat with a\nsingle backup row stuck `in_progress` (no error, no size), so no `verified`\nbackup ever existed and /health reported `backups: degraded` in all 3 regions.\n\nRoot cause is an event-ordering bug in `performBac\n[…]\n— it times out against the old\nordering and passes with the latch. The existing engine.test.ts mocks\nre-fire `close` on every listener attach and resolve put instantly, so they\ncould never catch this.",
          "is_bot": false,
          "headline": "fix(backups): register pg_dump exit-code listener before the pipeline…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T19:52:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a4ec5a65237948d68458dc57571b44e0960d883",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.60 — MCP OAuth Consent Fix",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T18:56:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "228dcfc4158c4430017f67f0557ebc3d74058b56",
          "body": "…4) (#4730)\n\nAdmin-merge rationale: all required checks green (ci, api-tests 1-4, Deploy Validation, Symlink Stub Build) plus the full non-required battery; the required 'Analyze (javascript-typescript)' (CodeQL) gate never triggered on this non-fork PR — no workflow run, queue, or check-run on the head SHA after ~30min, while it fired promptly for #4725/#4726/#4729. Judged a GitHub default-setup miss (not a failure); owner-authorized admin merge.",
          "is_bot": false,
          "headline": "fix(mcp): pin OAuth login/consent pages to the web origin (consent 40…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T18:47:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fde17b68a9faf967add17934eae21a510e271edc",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.59 — Backup Engine & Residency Cleanup",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T16:06:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd3ec725ae8bc3682818059a81fef57745be39d6",
          "body": "… get refresh tokens (#4728) (#4729)\n\n* fix(mcp): advertise offline_access in scopes_supported so DCR clients get refresh tokens (#4728)\n\nDCR clients (Claude Code among them) register with exactly the\nprotected-resource metadata's advertised scope list, and\n@better-auth/oauth-provider validates auth\n[…]\nurfaces the compile-time satisfies can't reach.\n\nNegative test (renaming offline_access in the union) confirmed all three\ncompile-time tethers fail the build; new fixture tests cover the runtime gate.",
          "is_bot": false,
          "headline": "fix(mcp): advertise offline_access in scopes_supported so DCR clients…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T14:51:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f03da89c9377074fdc6af8b16ef329051d4209fa",
          "body": "…the backup engine (#4457) (#4726)\n\nThe scheduled-backup engine shipped in #4723 spawns pg_dump/psql, but the\napi runner image never installed a postgres client — every backup cycle\nwould fail with spawn ENOENT (surfacing as the /health backups tripwire's\ndegraded state, boot-green-but-broken exactl\n[…]\n\ndefault client is insufficient.\n\nVerified against the exact pinned base image digest:\ndocker run oven/bun:1.3.13@sha256:87416c... + this RUN block\n-> pg_dump (PostgreSQL) 18.4, psql (PostgreSQL) 18.4",
          "is_bot": false,
          "headline": "fix(deploy): install PostgreSQL 18 client tools in the api image for …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T02:19:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "798cceec1244b0e2982565281ce259731de7f002",
          "body": "…utes (#4458) (#4725)\n\n* fix(residency): region-migration Phase 4 source cleanup actually executes (#4458)\n\nThe destructive half of migration Phase 4: a new\nregion_migration_source_cleanup periodic fiber (hourly) consumes the\npreviously-unconsumed getCleanupDueMigrations and deletes a migrated\nworks\n[…]\nts\n\nThe compile-time CleanupScopedTable derivation reads\nBUNDLE_TABLE_DECISIONS directly; EXPORTED_TABLES/STAYS_TABLES are\nconsumed only by the tripwire test (github-code-quality finding on\nPR #4725).",
          "is_bot": false,
          "headline": "fix(residency): region-migration Phase 4 source cleanup actually exec…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T01:58:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "866a8b87be6c8b5964b71d428cb0ce48fc2dd95b",
          "body": "…iber, S3 storage driver, health tripwire (#4457) (#4723)\n\n* fix(backups): wire the scheduled-backup automation for real — cadence-window fiber, S3 storage driver, health tripwire (#4457)\n\nstartScheduler was dead code: zero production callers, so the sold/promised\nautomated-backup feature never ran,\n[…]\nd (#4723 review)\n\ngithub-code-quality[bot]: 'backupsComponent' always evaluates to true —\nboth the try and catch arms assign it. Encode that in the declaration\n(no undefined arm) and pass it directly.",
          "is_bot": false,
          "headline": "fix(backups): wire the scheduled-backup automation — cadence-window f…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T01:07:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f2e57a9979bb2395c8188a774dfcbb07a31ab5d",
          "body": "…2 bundle + drift tripwire) (#4724)\n\n* fix(residency): close the region-migration export bundle scope drift (#4460)\n\nThe export bundle covered only the four original pillars (conversations,\nsemantic entities, learned patterns, settings); everything shipped since —\ndashboards, knowledge documents, sc\n[…]\nonse-shape guard now covers all four sections the cast claims\n- Owner re-shares phrasing in the two remaining spots\n\n* docs(roadmap): bank #4460 — region-migration export bundle scope drift (PR #4724)",
          "is_bot": false,
          "headline": "fix(residency): region-migration export bundle covers every pillar (v…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-19T00:55:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68b6eb3bf8e023031dd5a5ad6bf75e88ea37297b",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.58 — Dashboard & Sharing Residue",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T21:32:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "188a6db7ec60fea676001728bd0e1e179a675628",
          "body": "…(milestone #90 closed; 3 issues, PRs #4720/#4721/#4722)",
          "is_bot": false,
          "headline": "docs(roadmap): v0.0.58 — Dashboard & Sharing Residue shipped to main …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T21:21:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f71a3701f76d547d45ae51a01d3cbd8693d38be1",
          "body": "….58 closeout)",
          "is_bot": false,
          "headline": "docs(guides): SameSite scope caveat for org-scoped share embeds (v0.0…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T21:21:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "761cb7306729b7db205475b7b8cfdb1035350463",
          "body": "…ard share pattern (#4719) (#4722)\n\n* fix(web): shared conversation surface parity with the hardened dashboard share pattern (#4719)\n\n- no-store + React cache() intra-render dedup replaces revalidate:60 — a\n  revoked/expired share link dies immediately\n- token-hash-only logging (#4317 discipline) — \n[…]\nm ADR-0024 §5 refs\n- tests: token-echo redaction (SSR + client), messages:[null] -> server-error,\n  page-seam hand-off tests for page + embed, draftMode added to next/headers\n  mocks (all three sites)",
          "is_bot": false,
          "headline": "fix(web): shared conversation surface parity with the hardened dashbo…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T21:18:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17e5f25255b8c3a1db8a63e60021f3ecda6d8014",
          "body": "…of silently writing published cache (#4720)\n\n* fix(dashboards): draft Refresh-all surfaces 503 on a thrown draft load instead of silently writing the published cache (#4685)\n\nloadDraft collapsed both \"no draft exists\" and \"the load threw\" to null.\nThe bulk draft Refresh-all branch (a WRITE path, #4\n[…]\n Log label 'loadDraft failed' -> 'dashboard draft load failed' (the\n  catch now lives in loadDraftChecked; caller-agnostic label).\n- Test comment made name-agnostic; assert loadDraftChecked call args.",
          "is_bot": false,
          "headline": "fix(dashboards): draft Refresh-all 503s on thrown draft load instead …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T20:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53ccfcbe5605cc8b4d38ca032c0b83aeea23657f",
          "body": "…e viewer session client-side (#4718) (#4721)\n\n* fix(dashboards): resolve org-scoped shares client-side when SSR hits the auth wall (#4718)\n\nUnder ADR-0024 the SaaS session cookie is host-only on the per-region API\ndomain, so the shared page's RSC cookie forward is structurally empty\ncross-origin — \n[…]\nody cast\n- tests: isAuthWallReason exhaustive pin, resolveAuthReason direct pins,\n  mapper-totality + no-values-in-log pins, embed login-required split,\n  full use-dark-mode mock, mockResolve teardown",
          "is_bot": false,
          "headline": "fix(dashboards): org-scoped shares dead-end cross-origin — resolve th…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T20:39:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92a9ceb64bcc7ca9e2a443fefb9b869948bc44d3",
          "body": "…one #90: #4685 + #4718 + #4719)",
          "is_bot": false,
          "headline": "docs(roadmap): kick off v0.0.58 — Dashboard & Sharing Residue (milest…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T20:02:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a128589b8d521c6fcc6f72984c313769900fd372",
          "body": "…v0.0.56 detail, fix latest-tag drift)",
          "is_bot": false,
          "headline": "docs: tidy — bank tags v0.0.56/v0.0.57 (collapse to History, archive …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T19:48:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71832104c58dbe4eab47c22c1cf25f9e9d23af08",
          "body": "…OST allowlist, PR #4717) + #4669 (platform-tier settings console, PR #4716); unblocks agents-repo #203/#204/#205",
          "is_bot": false,
          "headline": "docs(roadmap): Agent Auth cluster residue closed — #4707 (read-safe P…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T19:42:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e41dff26c8d29286453593e4ed99c6c695b4c29",
          "body": "…lore/metrics/validate-sql) into the capability surface (#4707) (#4717)\n\n* feat(agent-auth): admit a curated read-safe POST allowlist into the capability surface (#4707)\n\nREAD_SAFE_OPERATIONS admits the four analyst read actions (POST /api/v1/query,\n/explore, /metrics/{id}/run, /validate-sql) into t\n[…]\nAttribute auto-LIMIT/statement-timeout to execution, not validateSQL\n- Soften the isWriteOperation param note (same default, not 'can never diverge')\n- querySalesforce grouped as a read, not an action",
          "is_bot": false,
          "headline": "feat(agent-auth): admit a curated read-safe POST allowlist (query/exp…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T19:40:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1fb1cdf9c9d036ad882269e8575721273e7f8e48",
          "body": "…the platform console (#4669) (#4716)\n\n* feat(admin): explicit platform-tier write path for workspace-scoped settings (#4669)\n\n- PUT/DELETE /api/v1/admin/settings/{key}?tier=platform targets the\n  global (org_id IS NULL) row explicitly — never inferred from the\n  session org — gated to platform_admi\n[…]\nboth verbs, pin no-default platformValue\n  shape, complete the partial settings mock (mock-all-exports)\n\n* review-panel round 2 polish (#4669): comment accuracy + DELETE workspace-tier audit assertion",
          "is_bot": false,
          "headline": "feat(admin): platform-tier writes for workspace-scoped settings from …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T19:31:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5048720dc348ec632858574cd839c95e90015c53",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.57 — Two-Phase Drop Cleanup",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T18:31:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c4b2b5dc1d6978208f3a2e95323218294b525e6",
          "body": "… drop",
          "is_bot": false,
          "headline": "docs(roadmap): record #4561 → PR #4714 merged alongside #4551 phase-2…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T18:16:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bfa46c73875e3ba47fb64b5519beb92a316140c",
          "body": "…1) (#4714)\n\nPhase 2 of the two-phase drop (parent #4553, ADR-0034): phase 1 (#4555,\nshipped v0.0.55) removed every reader/writer, so migration 0176 drops the\ntable. The Drizzle mirror in schema.ts is removed in the same commit per\nthe drop-table discipline; migrate test counts/lists bumped, and the\n0083 real-PG shape/CHECK/cascade tests are replaced by a drop assertion.",
          "is_bot": false,
          "headline": "chore(db): drop dashboard_stage_changes — stage tracker phase 2 (#456…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T18:14:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a5e6f6b31f538e87c68590ac1afd2f9397ee132",
          "body": "…ides the next tag",
          "is_bot": false,
          "headline": "docs(roadmap): bank #4551 config-block removal phase 2 (PR #4713) — r…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T18:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "577d9a143b8a0b991d38cb38daaad1a7782bfbde",
          "body": "… the sole Query Cache surface (#4551) (#4713)\n\n* feat(config): remove the `cache:` config block — settings registry is the sole Query Cache surface (#4551)\n\nPhase 2 of the two-phase config-block drop (PRD #4544, ADR-0033). Phase 1\n(#4545, ignored-with-boot-warning) shipped in tag v0.0.56; this land\n[…]\nk's removal\n- multi-tenancy.mdx: qualify ATLAS_CACHE_* / atlas.config.ts sentences as\n  self-hosted (audience-invariant-leak class from the v0.0.42 audit);\n  Admin-page sentence stays audience-neutral",
          "is_bot": false,
          "headline": "feat(config): remove the `cache:` config block — settings registry is…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T18:12:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d22c297e366722c517b74acf2352b045dd26922",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.56 — Admin Cache Elevation",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T17:32:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53dc3755b101ede0ab0733ba9ea19a0dbcf8f58e",
          "body": "… (#4712)\n\n* docs(cache): v0.0.56 closeout reconciliation — catch guides up to the shipped contracts\n\nguides/caching.mdx predated the milestone's admin-API rework:\n- cache key is five components post-ADR-0033 (#4547): resolved RLS config\n  joins the material, so an RLS change orphans pre-change entr\n[…]\n cache page (PR #4711), closeout docs\nreconciliation. #4551 graduates to the next tag per two-phase drop\ndiscipline. Planned-tags bullet updated: all three 2026-07-10 elevate\nclusters are now shipped.",
          "is_bot": false,
          "headline": "docs: v0.0.56 closeout — cache guide reconciliation + ROADMAP banking…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T17:20:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b75112825a8ea434e3f40829841080aad9e76d0",
          "body": "Presentation-only fixes from a design/a11y audit of the reworked cache\npage (#4549/#4550); wire schemas untouched:\n\n- Fill stat renders an honest em dash (no gauge) when entryCount/maxSize\n  are unreported by the cache backend, instead of a confident 0.0%\n- disabled Flush button is the tooltip trigg\n[…]\nical to the empty state\n- hit-rate readout row wraps on narrow viewports\n- TTL input: aria-invalid + inline error for unsaveable values, live\n  human-units preview while dirty, aria-describedby wiring",
          "is_bot": false,
          "headline": "polish(admin): impeccable audit pass on the Query Cache page (#4711)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T16:53:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "895cb7d18524f9121b88dc74b88c1b645ce972f3",
          "body": "…Rs #4705/#4706/#4708/#4709) (#4710)",
          "is_bot": false,
          "headline": "docs(roadmap): bank shipped v0.0.56 slices #4545/#4546/#4549/#4550 (P…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T16:09:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "182b1a1fc04683661fe5522e594db442a17a5c36",
          "body": "… on the admin cache page (#4550) (#4709)\n\n* feat(cache): entry inspection table + org-authorized per-entry delete on the admin cache page (#4550)\n\n- CacheEntry gains sqlPreview (~200-char cap, stamped at the sql.ts write\n  site from the same post-beforeQuery SQL that built the key — no full-SQL\n  r\n[…]\nenant audit shape; managed-no-org\n  400s on all four routes; caller-vs-target enabled gate pinned\n\n* fix(cache): void the fire-and-forget refetch in the 404-delete recovery path (no-floating-promises)",
          "is_bot": false,
          "headline": "feat(cache): entry inspection table + org-authorized per-entry delete…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T16:02:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "766c6f72103844b0bf7c3f9f9ddee26fee18683d",
          "body": "…through the cockpit (#4549) (#4708)\n\n* feat(cache): org-scoped flush contract + org-bucketed windowed stats through the cockpit (#4549)\n\n- New module-level org stats registry (lib/cache/stats-registry.ts): per-org\n  hit/miss buckets with a since-labeled lifetime rate plus a last-hour rate\n  via two\n[…]\nuded) in sql-cache-elevation; fanout per-leg accounting\n  pinned; no-org (single-tenant) stats+flush branches; plugin-backend\n  stats/flush/audit behavior; LRU self-heal; de-vacuumed the 422 assertion",
          "is_bot": false,
          "headline": "feat(cache): org-scoped flush contract + org-bucketed windowed stats …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T15:23:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0537361054eb2fd726f1c0f1e89a1548e534c7ed",
          "body": "…ntrols, config-block deprecation (#4545) (#4706)\n\n* feat(cache): Query Cache knobs → settings registry, inline cockpit controls, config-block deprecation (phase 1)\n\nMove the Query Cache's three knobs into the settings registry so they are\nruntime-controllable end-to-end with no redeploy (#4545):\n- \n[…]\nning split per deploy mode, restart caveat removed, three audit\n  ride-alongs (L8/L10/L14).\n\nCloses #4545\n\n* docs(cache): correct getCacheMaxSize comment — getSettingAuto delegates to getSetting today",
          "is_bot": false,
          "headline": "feat(cache): Query Cache knobs → settings registry, inline cockpit co…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T14:24:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "007fe7012d5b8f002b4ede5646e1402580c11709",
          "body": "…cuteSQL seam (#4546) (#4705)\n\nA Query Cache hit stops being invisible staleness. Slice 2 of v0.0.56\n(milestone #89), building on the async CacheBackend contract from #4548.\n\n- Hit responses carry `cacheAgeMs` (now minus the entry's write timestamp,\n  clamped at 0; omitted when `cachedAt` is non-fin\n[…]\n-hit, clock-skew clamp, bypass read-skip/write-keep, refreshed-entry\nre-hit, all-hit vs mixed vs partial-failure fanout propagation, merger per-leg\npropagation, and web formatCacheAge/render branches.",
          "is_bot": false,
          "headline": "feat(cache): surface hit age + governance-safe bypassCache at the exe…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T14:08:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3489519a69dc7a828a016080de0f8b634af1077f",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): bank shipped v0.0.56 slices #4547/#4548 (PRs #4703/#4704)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T14:07:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fffe75be683e9e61adbfbff60283cbb2b02796ba",
          "body": "… before the cache check (#4547) (#4703)\n\nThe cache key captures every row-determining input (ADR-0033): resolved RLS config hashed into the key (closes H3), beforeQuery dispatch + re-validation moved above the cache check (closes M11 governance half), afterQuery/metrics live-only, single RLS-config snapshot threaded to key+injector, L9 invariant + custom-validator fingerprint gate.",
          "is_bot": false,
          "headline": "feat(cache): ADR-0033 governance — RLS config in the key, beforeQuery…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T01:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1204f1db14765dd53c69bf3e0b13e86fb4d432ca",
          "body": "…l-plugin validation (#4548) (#4704)\n\n* feat(cache): async CacheBackend contract with scope tags, org index, fail-plugin validation (#4548)\n\n- CacheBackend fully async (get/set/delete/flush/flushByOrg/stats return Promise);\n  kills the phantom-hit failure mode (unawaited Promise read as a truthy hit\n[…]\nen path (delete still completes + warning);\n  admin-workspace cache mock gains validateCacheBackend (mock-all-exports).\n- lru.ts: correct the flushByOrg copy-first comment to describe the real reason.",
          "is_bot": false,
          "headline": "feat(cache): async CacheBackend contract — scope tags, org index, fai…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T01:26:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84dd58e94d82ca3d4ab75463a6afcbc5cd2229f8",
          "body": null,
          "is_bot": false,
          "headline": "docs(roadmap): kickoff v0.0.56 — Admin Cache Elevation (milestone #89)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T00:30:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63d5cf2ba8e5c50abdfe0db34414bd69847b680a",
          "body": "…2/#4533/#4700)",
          "is_bot": false,
          "headline": "docs: tidy — bank the 2026-07-17 /next batch (5 PRs: #4461/#4463/#453…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T00:05:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9c88a6c493eb43d2048cd96819ee70798ce9c4a",
          "body": "…1) (#4702)\n\nSaaS pins `sandbox.priority: [\"vercel-sandbox\"]` (deny-all, no fallback)\nbut nothing asserted the Vercel Sandbox credentials at boot. A region\nwith a missing/mis-stamped per-service VERCEL_TOKEN (Railway shared vars\ndon't auto-inherit) booted green, /health stayed green, and every\nexplo\n[…]\ny keys mutable via setSetting;\n  VERCEL_TOKEN is a pure env secret (matches TURNSTILE_SECRET_KEY /\n  AI_GATEWAY_API_KEY precedent).\n- Boot-smoke fixture populates VERCEL_TOKEN.\n\nv0.1.0 launch blocker.",
          "is_bot": false,
          "headline": "fix(api): SaaS boot guard for pinned vercel-sandbox credentials (#446…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-18T00:04:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b37860fd066702dd57d0dae7c2e000c9d8f87b7",
          "body": "…age test passes (#4700) (#4701)\n\nThe 'every ChatErrorCode is classified' invariant in errors.test.ts drifted\nwhen subscription_required was added to CHAT_ERROR_CODES but never added to\nthe test's retryable/non-retryable arrays, leaving the whole file red on main.\n\nsubscription_required is a billing\n[…]\n_MAP already pins it to false) — a permanent, non-retryable code.\nAdd it to nonRetryableCodes, and to the parallel parseChatError permanent-codes\nlist to keep the two classification arrays consistent.",
          "is_bot": false,
          "headline": "fix(types): classify subscription_required so the ChatErrorCode cover…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T23:54:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7b4e10fe7d9998abacc4a5867fc6b4c2017f29d",
          "body": "…ils fast (#4463) (#4699)\n\nNo pg pool (analytics or internal) set connectionTimeoutMillis, and no mysql2\npool set connectTimeout. pg defaults to 0 (no timeout), so a saturated pool\nqueued pool.connect() indefinitely and an unreachable-but-routable DB stalled\nevery request for the OS TCP keepalive wi\n[…]\ncomment: the internal pool now bounds the acquire,\n  so the 5s audit-write cap is tighter/independent rather than the only guard.\n- Document ATLAS_CONNECT_TIMEOUT in .env.example + env-vars reference.",
          "is_bot": false,
          "headline": "fix(api): bound connectionTimeoutMillis on all pg pools so acquire fa…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T23:53:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3472485c59c99f53fcd5b88b97c501c800f6799d",
          "body": "…laims discriminate keys (#4532) (#4698)\n\nbuildCacheKey serialized auth claims with JSON.stringify(claims,\nObject.keys(claims).sort()). A replacer array is applied at every nesting\nlevel, so a nested claim like { app_metadata: { org_id: \"org-42\" } }\nserialized to {\"app_metadata\":{}} and the discrimi\n[…]\n invariant\nhonestly for the undefined-orgId / nested-claims cases.\n\nAdds regression tests: two claims differing only at a nested path produce\ndifferent keys; nested key order does not affect the hash.",
          "is_bot": false,
          "headline": "fix(cache): deep-canonicalize claims in buildCacheKey so nested RLS c…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T23:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3bcadec5dd28389e5f44a492b199ebedca8f308",
          "body": "…#4697)\n\nThe cache-flush route's own docblock declares that, because flush is\nprocess-global across every workspace on the runtime, attribution is the\nsecurity control. But the handler logged that row via fire-and-forget\nlogAdminAction, whose insert is swallowed by a circuit breaker — during a\ncircu\n[…]\n a silent 200, and the flush never runs.\n\nTests pin both invariants: the audit row commits before the flush, and a\nfailing audit write does not silently succeed (500, flush not called).\n\nSecurity fix.",
          "is_bot": false,
          "headline": "fix(cache): await the flush attribution row before flushing (#4533) (…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T23:52:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cab793ee9a2c2c40560a546828c2c2af2fcf94d5",
          "body": "…detail",
          "is_bot": false,
          "headline": "docs(roadmap): close out v0.0.55 — collapse to History, archive full …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T19:47:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c996d84deec941a632934cf97d4bb24e790dc68",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): v0.0.55 — Dashboard Second Elevation",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T19:29:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8c24cf8ac36cdbdbfef0f6a5abffcb14c1f7c65",
          "body": "…ass (#4691)\n\n* test(dashboards): pin seedDraftCards batch concurrency contract\n\nThe existing wall-clock-budget test (one fast + one 200ms-slow card under a\n10ms budget) resolves identically whether seedDraftCards executes cards\nconcurrently or serially, so it did not actually pin the concurrency co\n[…]\nd accept/discard ghost-overlay staging model (ADR-0034 replaced\n  it with the inline-undo single-edit mechanism).\n\nNo behavior change beyond copy/markup/responsive layout; 304 affected\nweb tests pass.",
          "is_bot": false,
          "headline": "polish(dashboards): design-review nits from the v0.0.55 pre-release p…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T19:04:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c175177fc8c6962953c7c4fea4d706177d4fe446",
          "body": null,
          "is_bot": false,
          "headline": "docs: tidy — bank v0.0.55 design-review polish slice (#4686–#4690)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T18:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27bfa904a12ed3feef3aa20519922ff32e680302",
          "body": "…N_H (#4687) (#4696)\n\n* fix(dashboards): text section-header tiles floor at a shorter TEXT_MIN_H (#4687)\n\nA markdown text / section-header card inherited the shared grid MIN_H=4\nfloor, so a one-line `## Section` header rendered as a ~180px empty box\ninstead of a tight banner over the charts grouped \n[…]\nundo request-body layout schemas now\nvalidate against TextCardLayoutSchema (h minimum 2, not 4), so the\ngenerated OpenAPI spec's layout.h minimum drops accordingly. Keeps\ncheck-openapi-drift.sh green.",
          "is_bot": false,
          "headline": "fix(dashboards): text section-header tiles floor at a shorter TEXT_MI…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T18:01:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccaf6b8bd35847abb8b5c703954e720da133b071",
          "body": "…k control (#4686) (#4695)\n\n* fix(dashboards): embed ?theme= themes charts too + discoverable light/dark control (#4686)\n\nThe share dialog's Embed tab forced theme only via a .dark wrapper: chrome\nthemed but tile charts read useDarkMode() (visitor's documentElement /\nprefers-color-scheme), so a forc\n[…]\nhange deselect comment.\n- tile.test.tsx: make the unforced-path test load-bearing — flip the mocked\n  visitor system to dark and assert the chart follows it, so it can't pass on a\n  hardcoded default.",
          "is_bot": false,
          "headline": "fix(dashboards): embed ?theme= themes charts + discoverable light/dar…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T17:54:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ee83426d1c1c4df27799dde9d0c0ff178f0748b",
          "body": "… to card type (#4688) (#4694)\n\n* fix(dashboards): dashboard tiles render ResultChart plot-only, pinned to the card's type (#4688)\n\nDashboard chart tiles reuse the chat ResultChart, which carried its own caption\nbar + Line/Area/Bar type toggle and auto-detected its type from the data. Inside\na title\n[…]\nt and\n  makes a typo'd member a compile error.\n- Clarify the chartType JSDoc (it pins regardless of embedded; intended paired).\n- Harden the shared-tile async flush against the two-hop dynamic loader.",
          "is_bot": false,
          "headline": "fix(dashboards): dashboard tiles render ResultChart plot-only, pinned…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T17:41:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25f9a116c54797fb14e9c589e8ae639b151f6c08",
          "body": "…4690) (#4693)\n\n* fix(dashboards): distinguish 401 from 403 on shared-view auth wall (#4690)\n\nShared-dashboard fetch collapsed 401 (no session) and 403 (authenticated,\nwrong org) into a single 'auth-required' reason, so a logged-in member of the\nwrong org dead-ended on a 'Log in' CTA they had alread\n[…]\nThe malformed-403 mock's json returns Promise<never>, which tsgo's stricter\ntsconfig.test-check rejected as a direct `as Response` cast (TS2352). Cast via\nunknown, matching the outer stubFetch helper.",
          "is_bot": false,
          "headline": "fix(dashboards): distinguish 401 from 403 on shared-view auth wall (#…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T17:34:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42fa613755b75ac1341b1672daeec97b4e5f1bc9",
          "body": "…ignal (#4689) (#4692)\n\nThe View/Edit toggle + 'drag tiles' help were gated on a coarse-pointer\nmedia query, while the grid degrades to a non-draggable single-column\nstack on measured width < MOBILE_BREAKPOINT. On a narrow-but-mouse-driven\nwindow (fine pointer, <640px) the chrome advertised drag/res\n[…]\none signal, so advertised == deliverable.\nThe narrow-desktop hint reads 'Widen the window to edit' rather than the\nfalse 'Editing is desktop-only'. Coarse-pointer (touch) path unchanged.\n\nCloses #4689",
          "is_bot": false,
          "headline": "fix(dashboards): gate topbar Edit affordances on the grid's stacked s…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T17:30:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a128d67415053fbd2dc3e27c27963a4efbabd08",
          "body": "The existing wall-clock-budget test (one fast + one 200ms-slow card under a\n10ms budget) resolves identically whether seedDraftCards executes cards\nconcurrently or serially, so it did not actually pin the concurrency contract\nADR-0034 Decision 1 makes load-bearing: the budget bounds the WHOLE batch\n\n[…]\nbudget elapses, flipping it to\n`unseeded` and failing the assertion. Verified red under a for/await refactor,\ngreen under the shipped Promise.all.\n\nSurfaced by the v0.0.55 milestone-wide review panel.",
          "is_bot": false,
          "headline": "test(dashboards): pin seedDraftCards batch concurrency contract (#4684)",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T17:00:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb259488d36a82be2918ffbb6242d12d471b8294",
          "body": "…on (#4683)\n\n* docs(dashboards): document the shared-view Embed tab / framable /embed route (#4564)\n\n* docs: reconcile ROADMAP v0.0.55 — all 18 issues merged, milestone closed",
          "is_bot": false,
          "headline": "docs: v0.0.55 closeout — dashboard embed guide + ROADMAP reconciliati…",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T16:36:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b79cc217b231d4f830e70d730d341125a75160af",
          "body": "…Edit; scoped shortcuts (#4560) (#4682)\n\nView mode offers only non-mutating tile affordances (refresh, fullscreen, CSV, drilldown); Rename/Duplicate/Remove and drag are Edit-only. The tile-actions menu renders only when it holds an item (editing or an export handler), never an empty dropdown.\n\nScope\n[…]\nafts row.\n\nTests: View/Edit affordance-set gating on the tile, RGL drag/resize gating in both modes, the shortcut predicate, and the non-forking route seam.\n\nADR-0034 / CONTEXT.md § Dashboard editing.",
          "is_bot": false,
          "headline": "feat(dashboards): View is read-only — mutating tile controls move to …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T16:26:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "191d58b8ec2a2481efbcd05a7ae1214d5f6dffe0",
          "body": "…in the draft with inline undo (#4555) (#4681)\n\n* feat(dashboards): single edit mechanism — destructive bound ops land in the draft with inline undo (#4555)\n\nRetire the stage tracker (ADR-0034 Decision 2, reverses #2365). The bound\neditor's removeCard / updateCardSql now apply straight to the caller\n[…]\ntagedChange/Stage* wire types from @useatlas/types\n- fix stale stage-tracker comments in dashboard-versioning.ts + bound-dashboard.ts\n\n* test: cover the undo route's cross-org getDashboard guard (404)",
          "is_bot": false,
          "headline": "feat(dashboards): single edit mechanism — destructive bound ops land …",
          "author_name": "Matt Sywulak",
          "author_login": "msywulak",
          "committed_at": "2026-07-17T16:21:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 68,
      "commits_last_year": 3439,
      "latest_release_at": "2026-07-24T18:52:28Z",
      "latest_release_tag": "v0.1.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 0.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "create-atlas-agent",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "atlas",
            "text-to-sql",
            "data-analyst",
            "agent",
            "semantic-layer",
            "bun",
            "hono"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/create-atlas-agent",
          "is_deprecated": false,
          "latest_version": "0.3.3",
          "repository_url": "https://github.com/AtlasDevHQ/atlas",
          "versions_count": 7,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 49,
          "first_published_at": "2026-02-24T20:29:37.499000Z",
          "latest_published_at": "2026-05-03T19:55:39.385000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 83
        },
        {
          "name": "create-atlas-plugin",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "atlas",
            "text-to-sql",
            "plugin",
            "scaffold",
            "bun"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/create-atlas-plugin",
          "is_deprecated": false,
          "latest_version": "0.1.1",
          "repository_url": "https://github.com/AtlasDevHQ/atlas",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 22,
          "first_published_at": "2026-05-03T19:29:52.974000Z",
          "latest_published_at": "2026-05-03T19:34:06.439000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 83
        }
      ]
    },
    "popularity": {
      "forks": 3,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-18",
            "count": 1
          },
          {
            "date": "2026-06-29",
            "count": 1
          },
          {
            "date": "2026-07-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 3,
        "total_forks": 3
      },
      "star_history": null,
      "open_issues_and_prs": 37
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "apps/docs/openapi.json"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [
        "apps/docs/tsconfig.json",
        "apps/www/tsconfig.json",
        "create-atlas/templates/docker/tsconfig.json",
        "create-atlas/templates/nextjs-standalone/tsconfig.json",
        "ee/tsconfig.json",
        "examples/embedded-mcp-onboarding/tsconfig.json",
        "examples/nextjs-standalone/tsconfig.json",
        "packages/api/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/oauth-helper/tsconfig.json",
        "packages/plugin-sdk/tsconfig.json",
        "packages/react/tsconfig.json",
        "packages/schemas/tsconfig.json",
        "packages/sdk/tsconfig.json",
        "packages/types/tsconfig.json",
        "packages/web/tsconfig.json",
        "packages/webhook-publisher/tsconfig.json",
        "plugins/bigquery/tsconfig.json",
        "plugins/chat/tsconfig.json",
        "plugins/clickhouse/tsconfig.json",
        "plugins/duckdb/tsconfig.json",
        "plugins/elasticsearch/tsconfig.json",
        "plugins/email-digest/tsconfig.json",
        "plugins/email/tsconfig.json",
        "plugins/jira/tsconfig.json",
        "plugins/mcp/tsconfig.json",
        "plugins/mysql/tsconfig.json",
        "plugins/obsidian-reader/tsconfig.json",
        "plugins/obsidian/tsconfig.json",
        "plugins/salesforce/tsconfig.json",
        "plugins/snowflake/tsconfig.json",
        "plugins/teams/tsconfig.json",
        "plugins/twenty/tsconfig.json",
        "plugins/webhook-action/tsconfig.json",
        "plugins/webhook/tsconfig.json",
        "plugins/yaml-context/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 438644,
      "source_files_sampled": 3784,
      "oversized_source_files": 74,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 46249
    },
    "dependencies": {
      "manifests": [
        "create-atlas-plugin/package.json",
        "create-atlas/package.json",
        "ee/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 7,
        "malicious_count": 0,
        "assessed_package": "npm:create-atlas-agent@0.3.3",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@clack/prompts",
          "manifest": "create-atlas-plugin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "picocolors",
          "manifest": "create-atlas-plugin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@clack/prompts",
          "manifest": "create-atlas/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.0"
        },
        {
          "name": "picocolors",
          "manifest": "create-atlas/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@atlas/api",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@useatlas/chat",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@useatlas/twenty",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@useatlas/types",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@useatlas/webhook-publisher",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "effect",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.14.8"
        },
        {
          "name": "ipaddr.js",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.3.0"
        },
        {
          "name": "node-sql-parser",
          "manifest": "ee/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.0"
        },
        {
          "name": "@ai-sdk/amazon-bedrock",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.119"
        },
        {
          "name": "@ai-sdk/anthropic",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.85"
        },
        {
          "name": "@ai-sdk/gateway",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.133"
        },
        {
          "name": "@ai-sdk/openai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.74"
        },
        {
          "name": "@ai-sdk/provider",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.10"
        },
        {
          "name": "@ai-sdk/react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.210"
        },
        {
          "name": "@aws-sdk/client-bedrock",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1075.0"
        },
        {
          "name": "@better-auth/api-key",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "@better-auth/oauth-provider",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "@better-auth/passkey",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "@better-auth/scim",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "@better-auth/stripe",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "@clack/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@clickhouse/client",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.22.0"
        },
        {
          "name": "@effect/ai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.36.0"
        },
        {
          "name": "@effect/ai-anthropic",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.26.0"
        },
        {
          "name": "@effect/ai-openai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.39.2"
        },
        {
          "name": "@effect/platform",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.96.2"
        },
        {
          "name": "@effect/sql",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.51.1"
        },
        {
          "name": "@hono/zod-openapi",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.0"
        },
        {
          "name": "@hookform/resolvers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.0"
        },
        {
          "name": "@opentelemetry/exporter-metrics-otlp-http",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.218.0"
        },
        {
          "name": "@opentelemetry/exporter-trace-otlp-http",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.218.0"
        },
        {
          "name": "@opentelemetry/resources",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.0"
        },
        {
          "name": "@opentelemetry/sdk-metrics",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.0"
        },
        {
          "name": "@opentelemetry/sdk-node",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.218.0"
        },
        {
          "name": "@opentelemetry/semantic-conventions",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.41.1"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.0"
        },
        {
          "name": "@shikijs/transformers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.2.0"
        },
        {
          "name": "@tailwindcss/cli",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.1"
        },
        {
          "name": "@tailwindcss/postcss",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.1"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.101.1"
        },
        {
          "name": "@tanstack/react-query-devtools",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.101.1"
        },
        {
          "name": "@types/nodemailer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.1"
        },
        {
          "name": "ai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.208"
        },
        {
          "name": "better-auth",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.20"
        },
        {
          "name": "date-fns",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.0"
        },
        {
          "name": "effect",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.21.4"
        },
        {
          "name": "fumadocs-core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "~16.9.3"
        },
        {
          "name": "fumadocs-openapi",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.9.1"
        },
        {
          "name": "fumadocs-ui",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "~16.9.3"
        },
        {
          "name": "happy-dom",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^20.10.6"
        },
        {
          "name": "hono",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.27"
        },
        {
          "name": "ipaddr.js",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.0"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.0"
        },
        {
          "name": "jsforce",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.10.16"
        },
        {
          "name": "lucide-react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.21.0"
        },
        {
          "name": "mysql2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.22.4"
        },
        {
          "name": "nanoid",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.15"
        },
        {
          "name": "next",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.2.9"
        },
        {
          "name": "nodemailer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.1"
        },
        {
          "name": "obsidian",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.13.1"
        },
        {
          "name": "radix-ui",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "react-dom",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.6"
        },
        {
          "name": "react-hook-form",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.80.0"
        },
        {
          "name": "react-resizable-panels",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4"
        },
        {
          "name": "snowflake-sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.3"
        },
        {
          "name": "tailwindcss",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.1"
        },
        {
          "name": "zustand",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.14"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@ai-sdk/amazon-bedrock",
            "direct": true,
            "version": "^4.0.119",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/anthropic",
            "direct": true,
            "version": "^3.0.85",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/gateway",
            "direct": true,
            "version": "^3.0.133",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/openai",
            "direct": true,
            "version": "^3.0.74",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/provider",
            "direct": true,
            "version": "^3.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/react",
            "direct": true,
            "version": "^3.0.210",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/client-bedrock",
            "direct": true,
            "version": "^3.1075.0",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/api-key",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/oauth-provider",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/passkey",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/scim",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/stripe",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "@clack/prompts",
            "direct": true,
            "version": "^1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@clack/prompts",
            "direct": true,
            "version": "^1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@clickhouse/client",
            "direct": true,
            "version": "^1.22.0",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/ai",
            "direct": true,
            "version": "^0.36.0",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/ai-anthropic",
            "direct": true,
            "version": "^0.26.0",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/ai-openai",
            "direct": true,
            "version": "^0.39.2",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/platform",
            "direct": true,
            "version": "^0.96.2",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/sql",
            "direct": true,
            "version": "^0.51.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/zod-openapi",
            "direct": true,
            "version": "^1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@hookform/resolvers",
            "direct": true,
            "version": "^5.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-http",
            "direct": true,
            "version": "^0.218.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": true,
            "version": "^0.218.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": true,
            "version": "^2.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-metrics",
            "direct": true,
            "version": "^2.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-node",
            "direct": true,
            "version": "^0.218.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": true,
            "version": "^1.41.1",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-slot",
            "direct": true,
            "version": "^1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@shikijs/transformers",
            "direct": true,
            "version": "^4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/cli",
            "direct": true,
            "version": "^4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/postcss",
            "direct": true,
            "version": "^4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-query",
            "direct": true,
            "version": "^5.101.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-query-devtools",
            "direct": true,
            "version": "^5.101.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/nodemailer",
            "direct": true,
            "version": "^8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/twenty",
            "direct": true,
            "version": "^0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/types",
            "direct": true,
            "version": "^0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/types",
            "direct": true,
            "version": "^0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/webhook-publisher",
            "direct": true,
            "version": "^0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ai",
            "direct": true,
            "version": "^6.0.208",
            "ecosystem": "npm"
          },
          {
            "name": "better-auth",
            "direct": true,
            "version": "^1.6.16",
            "ecosystem": "npm"
          },
          {
            "name": "better-auth",
            "direct": true,
            "version": "^1.6.20",
            "ecosystem": "npm"
          },
          {
            "name": "date-fns",
            "direct": true,
            "version": "^4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "effect",
            "direct": true,
            "version": "^3.14.8",
            "ecosystem": "npm"
          },
          {
            "name": "effect",
            "direct": true,
            "version": "^3.21.4",
            "ecosystem": "npm"
          },
          {
            "name": "fumadocs-core",
            "direct": true,
            "version": "~16.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "fumadocs-openapi",
            "direct": true,
            "version": "^10.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "fumadocs-ui",
            "direct": true,
            "version": "~16.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "happy-dom",
            "direct": true,
            "version": "^20.10.6",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": true,
            "version": "^4.12.27",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": true,
            "version": "^2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": true,
            "version": "^2.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "^5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsforce",
            "direct": true,
            "version": "^3.10.16",
            "ecosystem": "npm"
          },
          {
            "name": "lucide-react",
            "direct": true,
            "version": "^1.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "mysql2",
            "direct": true,
            "version": "^3.22.4",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": true,
            "version": "^5.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "next",
            "direct": true,
            "version": "^16.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "next",
            "direct": true,
            "version": "^16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "node-sql-parser",
            "direct": true,
            "version": "^5.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "nodemailer",
            "direct": true,
            "version": "^9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "obsidian",
            "direct": true,
            "version": "^1.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": true,
            "version": "^1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "radix-ui",
            "direct": true,
            "version": "^1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "^19.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "^19.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "react-hook-form",
            "direct": true,
            "version": "^7.80.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-resizable-panels",
            "direct": true,
            "version": "^4",
            "ecosystem": "npm"
          },
          {
            "name": "snowflake-sdk",
            "direct": true,
            "version": "^2.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": true,
            "version": "^4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "zustand",
            "direct": true,
            "version": "^5.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "@axe-core/playwright",
            "direct": false,
            "version": "^4.11.3",
            "ecosystem": "npm"
          },
          {
            "name": "@better-auth/agent-auth",
            "direct": false,
            "version": "0.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/discord",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/gchat",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/github",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/linear",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/slack",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/state-memory",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/teams",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/telegram",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@chat-adapter/whatsapp",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "@daytonaio/sdk",
            "direct": false,
            "version": "^0.185.0",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/core",
            "direct": false,
            "version": "^6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/modifiers",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/sortable",
            "direct": false,
            "version": "^10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/utilities",
            "direct": false,
            "version": "^3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-api",
            "direct": false,
            "version": "^1.5.3-r.3",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/experimental",
            "direct": false,
            "version": "^0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/sql-mysql2",
            "direct": false,
            "version": "^0.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "@effect/sql-pg",
            "direct": false,
            "version": "^0.52.1",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": false,
            "version": "^1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": false,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "^1.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-table",
            "direct": false,
            "version": "^8.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/dom",
            "direct": false,
            "version": "^10.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/react",
            "direct": false,
            "version": "^16.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/diff",
            "direct": false,
            "version": "^8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "^7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^25.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/pg",
            "direct": false,
            "version": "^8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^19.2.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^19.2.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "^19.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-syntax-highlighter",
            "direct": false,
            "version": "^15.5.13",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/native-preview",
            "direct": false,
            "version": "^7.0.0-dev.20260623.1",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/react",
            "direct": false,
            "version": "^0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@useatlas/sdk",
            "direct": false,
            "version": "^0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vercel/og",
            "direct": false,
            "version": "0.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@vercel/sandbox",
            "direct": false,
            "version": "^2",
            "ecosystem": "npm"
          },
          {
            "name": "@vercel/sandbox",
            "direct": false,
            "version": "^2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-react-compiler",
            "direct": false,
            "version": "^1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "better-auth-harmony",
            "direct": false,
            "version": "^1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "chat",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "class-variance-authority",
            "direct": false,
            "version": "^0.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "clsx",
            "direct": false,
            "version": "^2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "cmdk",
            "direct": false,
            "version": "^1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "croner",
            "direct": false,
            "version": "^10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "domhandler",
            "direct": false,
            "version": "^5.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "drizzle-kit",
            "direct": false,
            "version": "^0.31.10",
            "ecosystem": "npm"
          },
          {
            "name": "drizzle-orm",
            "direct": false,
            "version": "^0.45.2",
            "ecosystem": "npm"
          },
          {
            "name": "e2b",
            "direct": false,
            "version": "^2.28.2",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "^4.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "^0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "exceljs",
            "direct": false,
            "version": "^4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "fflate",
            "direct": false,
            "version": "^0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "fumadocs-mdx",
            "direct": false,
            "version": "^15.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "github-slugger",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "htmlparser2",
            "direct": false,
            "version": "^9.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "input-otp",
            "direct": false,
            "version": "^1.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "^6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "just-bash",
            "direct": false,
            "version": "^3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "next-themes",
            "direct": false,
            "version": "^0.4.6",
            "ecosystem": "npm"
          },
          {
            "name": "nuqs",
            "direct": false,
            "version": "^2.8.9",
            "ecosystem": "npm"
          },
          {
            "name": "oxlint",
            "direct": false,
            "version": "^1.72.0",
            "ecosystem": "npm"
          },
          {
            "name": "oxlint-plugin-eslint",
            "direct": false,
            "version": "^1.72.0",
            "ecosystem": "npm"
          },
          {
            "name": "oxlint-tsgolint",
            "direct": false,
            "version": "^0.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "pg",
            "direct": false,
            "version": "^8.22.0",
            "ecosystem": "npm"
          },
          {
            "name": "pg-mem",
            "direct": false,
            "version": "^3.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": false,
            "version": "^10.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pino-pretty",
            "direct": false,
            "version": "^13.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "^19.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "^19.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "react-day-picker",
            "direct": false,
            "version": "^10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-grid-layout",
            "direct": false,
            "version": "^2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "react-markdown",
            "direct": false,
            "version": "^10.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-syntax-highlighter",
            "direct": false,
            "version": "^16.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "recharts",
            "direct": false,
            "version": "^3.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-gfm",
            "direct": false,
            "version": "^4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "shadcn",
            "direct": false,
            "version": "^4.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "sonner",
            "direct": false,
            "version": "^2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "stripe",
            "direct": false,
            "version": "^22.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "syncpack",
            "direct": false,
            "version": "^15.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tailwind-merge",
            "direct": false,
            "version": "^3.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsup",
            "direct": false,
            "version": "^8.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "tw-animate-css",
            "direct": false,
            "version": "^1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "^4.4.3",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 161,
        "direct_count": 71,
        "indirect_count": 90
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 2326,
        "open_issues": 31,
        "closed_ratio": 0.987,
        "closed_issues": 2401,
        "closed_unmerged_prs": 36
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "msywulak",
          "commits": 3382,
          "avatar_url": "https://avatars.githubusercontent.com/u/51167140?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 54,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "jstar0",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/54024410?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.984
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "claude.yml",
        "deploy-validation.yml",
        "eval.yml",
        "fork-pr-gate.yml",
        "lighthouse.yml",
        "load-test-mcp.yml",
        "mcp-registry.yml",
        "model-freshness.yml",
        "publish.yml",
        "staging-smoke.yml",
        "sync-starters.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "78 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ae4b7320a8571d52b0be6b1857da0eaa8dd18538",
        "ran_at": "2026-07-25T21:03:13Z",
        "aggregate_score": 6.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T21:01:22Z",
      "oldest_open_prs": [
        {
          "number": 4789,
          "created_at": "2026-07-24T18:43:59Z",
          "last_comment_at": "2026-07-24T18:50:24Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 4790,
          "created_at": "2026-07-24T18:44:01Z",
          "last_comment_at": "2026-07-24T18:50:49Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 4791,
          "created_at": "2026-07-24T18:44:03Z",
          "last_comment_at": "2026-07-24T18:53:26Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 4792,
          "created_at": "2026-07-24T18:44:05Z",
          "last_comment_at": "2026-07-24T18:52:13Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 4793,
          "created_at": "2026-07-24T18:44:07Z",
          "last_comment_at": "2026-07-24T18:53:27Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 4794,
          "created_at": "2026-07-24T18:53:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-25T21:00:47Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 1922,
          "created_at": "2026-04-27T00:06:44Z",
          "last_comment_at": "2026-07-10T00:27:28Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 1928,
          "created_at": "2026-04-27T00:50:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2055,
          "created_at": "2026-05-04T03:31:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2109,
          "created_at": "2026-05-06T02:55:19Z",
          "last_comment_at": "2026-05-09T14:20:19Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 2200,
          "created_at": "2026-05-08T22:35:27Z",
          "last_comment_at": "2026-06-21T11:18:37Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 2802,
          "created_at": "2026-05-25T02:26:03Z",
          "last_comment_at": "2026-06-13T16:01:38Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 2919,
          "created_at": "2026-05-28T14:58:39Z",
          "last_comment_at": "2026-06-24T17:48:16Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 3368,
          "created_at": "2026-06-10T16:02:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3414,
          "created_at": "2026-06-12T06:37:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3765,
          "created_at": "2026-06-17T20:17:37Z",
          "last_comment_at": "2026-06-18T18:04:15Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 3766,
          "created_at": "2026-06-17T20:24:03Z",
          "last_comment_at": "2026-06-23T01:10:41Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 3777,
          "created_at": "2026-06-18T08:06:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3870,
          "created_at": "2026-06-22T11:12:11Z",
          "last_comment_at": "2026-07-09T21:13:32Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 4099,
          "created_at": "2026-06-29T04:05:51Z",
          "last_comment_at": "2026-07-02T00:56:52Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 4379,
          "created_at": "2026-07-06T01:06:04Z",
          "last_comment_at": "2026-07-10T13:17:13Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 4402,
          "created_at": "2026-07-07T03:11:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4403,
          "created_at": "2026-07-07T03:11:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4404,
          "created_at": "2026-07-07T03:11:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4416,
          "created_at": "2026-07-07T22:49:03Z",
          "last_comment_at": "2026-07-08T17:19:07Z",
          "last_comment_author": "msywulak"
        },
        {
          "number": 4438,
          "created_at": "2026-07-09T15:54:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/AtlasDevHQ/atlas",
    "host": "github.com",
    "name": "atlas",
    "owner": "AtlasDevHQ"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 70,
        "vitality": 87,
        "community": 36,
        "governance": 55,
        "engineering": 69
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 87,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 3439,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "3439 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 3439
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 68,
              "latest_release_tag": "v0.1.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 0.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "68 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 68
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 2,
            "inputs": {
              "forks": 3,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "3 forks",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 31,
            "inputs": {
              "packages": [
                "create-atlas-agent",
                "create-atlas-plugin"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 71
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "71 downloads/month across npm",
                "points": 24.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 71,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.984
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 2326,
              "open_issues": 31,
              "closed_issues": 2401,
              "issue_closed_ratio": 0.987,
              "closed_unmerged_prs": 36
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "99% of issues closed",
                "points": 46.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2326/2362 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2326,
                      "decided": 2362
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "AtlasDevHQ",
              "public_repos": 4,
              "account_age_days": 147
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of AtlasDevHQ",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "AtlasDevHQ"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "create-atlas-agent",
                "create-atlas-plugin"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 83
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 83 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 83
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "7 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 69,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "12 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://www.useatlas.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.useatlas.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 70,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "78 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-atlas-agent@0.3.3 runtime dependency closure — what installing the published package pulls in — 7 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:create-atlas-agent@0.3.3",
                  "assessed": 7
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 7,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 7,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 77,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 46249
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "apps/docs/tsconfig.json",
                "apps/www/tsconfig.json",
                "create-atlas/templates/docker/tsconfig.json",
                "create-atlas/templates/nextjs-standalone/tsconfig.json",
                "ee/tsconfig.json",
                "examples/embedded-mcp-onboarding/tsconfig.json",
                "examples/nextjs-standalone/tsconfig.json",
                "packages/api/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/oauth-helper/tsconfig.json",
                "packages/plugin-sdk/tsconfig.json",
                "packages/react/tsconfig.json",
                "packages/schemas/tsconfig.json",
                "packages/sdk/tsconfig.json",
                "packages/types/tsconfig.json",
                "packages/web/tsconfig.json",
                "packages/webhook-publisher/tsconfig.json",
                "plugins/bigquery/tsconfig.json",
                "plugins/chat/tsconfig.json",
                "plugins/clickhouse/tsconfig.json",
                "plugins/duckdb/tsconfig.json",
                "plugins/elasticsearch/tsconfig.json",
                "plugins/email-digest/tsconfig.json",
                "plugins/email/tsconfig.json",
                "plugins/jira/tsconfig.json",
                "plugins/mcp/tsconfig.json",
                "plugins/mysql/tsconfig.json",
                "plugins/obsidian-reader/tsconfig.json",
                "plugins/obsidian/tsconfig.json",
                "plugins/salesforce/tsconfig.json",
                "plugins/snowflake/tsconfig.json",
                "plugins/teams/tsconfig.json",
                "plugins/twenty/tsconfig.json",
                "plugins/webhook-action/tsconfig.json",
                "plugins/webhook/tsconfig.json",
                "plugins/yaml-context/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "apps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "apps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 438644,
              "source_files_sampled": 3784,
              "oversized_source_files": 74
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "74/3784 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 3784,
                      "oversized": 74
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "apps/docs/openapi.json"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "apps/docs/openapi.json",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "apps/docs/openapi.json"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T21:03:36.517084Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/AtlasDevHQ/atlas.svg",
  "full_name": "AtlasDevHQ/atlas",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.