公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 15:32 UTC

Emasoft / AgentlensPro

AgentlensPro — professional AI-agent observability: OTEL + local-log ingestion, burn forensics, cost analytics, burn-gate hooks. CLI + server + skills.

TypeScriptMIT★ 2 星标⑂ 0 复刻始于 2026年7月在 GitHub 上查看 ↗

Emasoft/AgentlensPro 的健康指数为 100 分中的 54 分,处于「中等」区间。 其得分最高的类别是Vitality(72/100),最低的是Sustainability & Governance(43/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。

54
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

54
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Emanuele Sabetta个人账户
168 关注者88 个公开仓库始于 2011年4月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npmagentlenspro2.10.12,631165 天前aiagentopentelemetrytelemetryobservabilitycopilotclaudetracing

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

72良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
6.2/36提交节奏 — 52 周中有 9 周有提交
18/18提交量 — 最近一年 897 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year897
human_commit_share1
days_since_last_push5
active_weeks_last_year9

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 16 个发布版本
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 0.7 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count16
latest_release_tagv2.10.1
releases_from_tags
days_since_latest_release5
mean_days_between_releases0.7

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

44存在风险 · 占总体的 18%
评分方式
0/60星标 — 2 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

85优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
45.6/80月度下载量 — npm 合计每月 2,631 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesagentlenspro
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,631
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

43存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
9.2/22.5提交分布 — 头号贡献者编写了 59% 的提交
2.7/13.5贡献者广度 — 2 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled2
top_contributor_share0.591
评分方式
0/46.8议题解决 — 0% 的议题已关闭
0/38.3PR 接受 — 已裁定的 PR 中 0/1 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues4
closed_issues0
issue_closed_ratio0
closed_unmerged_prs1
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
16/25所有者影响力 — Emasoft 有 168 位关注者
25/25既往记录 — 88 个公开仓库,账户约 15 年
所用输入
followers168
owner_typeUser
is_verified
owner_loginEmasoft
public_repos88
account_age_days5,585
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 16 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesagentlenspro
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

64中等 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.mjs
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

40存在风险
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

47存在风险 · 占总体的 16%

安全态势

34存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3/7.5Vulnerabilities — 6 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.4
已排除计分(无数据或不适用):ci_tests。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories8
affected_packages7
assessed_packages419
unassessed_packages0
affected_by_severityhigh 4, moderate 2, low 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 419 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

68中等 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md, walkthrough/agents.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesCLAUDE.md, walkthrough/agents.md
agent_instruction_max_bytes13,162
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.mjs
11/11静态类型检查 — media/tsconfig.json, standalone/tsconfig.json, tsconfig.json
10/10可复现环境 — Dockerfile, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
7/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
所用输入
has_nix
has_tests
lockfilespnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsmedia/tsconfig.json, standalone/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
54/55可控的文件大小 — 采样的 320 个源文件中有 6 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes225,891
source_files_sampled320
oversized_source_files6
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_files

关键数据

2GitHub 星标
2贡献者
897最近 12 个月提交数
5距最近推送天数
16发布版本数
1巴士系数(bus factor)
4开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index npm:agentlenspro@2.10.1; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 3.4 / 10
3.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 15:32 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
4Vulnerabilities6 existing vulnerabilities detected
直接依赖 7
注册表软件包版本约束清单文件
npm@duckdb/node-api1.5.4-r.1package.json
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@preact/signals^2.9.0package.json
npmclsx^2.1.1package.json
npmfflate^0.8.3package.json
npmpreact^10.29.1package.json
npmsql.js^1.14.1package.json
全部依赖 419

来自 GitHub 依赖图的完整解析依赖集合:7 个直接依赖与 412 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@duckdb/node-api1.5.4-r.1直接
npm@modelcontextprotocol/sdk1.29.0直接
npm@preact/signals2.9.0直接
npmclsx2.1.1直接
npmfflate0.8.3直接
npmpreact10.29.1直接
npmsql.js1.14.1直接
npm@duckdb/node-bindings1.5.4-r.1间接
npm@duckdb/node-bindings-darwin-arm641.5.4-r.1间接
npm@duckdb/node-bindings-darwin-x641.5.4-r.1间接
npm@duckdb/node-bindings-linux-arm641.5.4-r.1间接
npm@duckdb/node-bindings-linux-arm64-musl1.5.4-r.1间接
npm@duckdb/node-bindings-linux-x641.5.4-r.1间接
npm@duckdb/node-bindings-linux-x64-musl1.5.4-r.1间接
npm@duckdb/node-bindings-win32-arm641.5.4-r.1间接
npm@duckdb/node-bindings-win32-x641.5.4-r.1间接
npm@esbuild/aix-ppc640.28.1间接
npm@esbuild/android-arm0.28.1间接
npm@esbuild/android-arm640.28.1间接
npm@esbuild/android-x640.28.1间接
npm@esbuild/darwin-arm640.28.1间接
npm@esbuild/darwin-x640.28.1间接
npm@esbuild/freebsd-arm640.28.1间接
npm@esbuild/freebsd-x640.28.1间接
npm@esbuild/linux-arm0.28.1间接
npm@esbuild/linux-arm640.28.1间接
npm@esbuild/linux-ia320.28.1间接
npm@esbuild/linux-loong640.28.1间接
npm@esbuild/linux-mips64el0.28.1间接
npm@esbuild/linux-ppc640.28.1间接
npm@esbuild/linux-riscv640.28.1间接
npm@esbuild/linux-s390x0.28.1间接
npm@esbuild/linux-x640.28.1间接
npm@esbuild/netbsd-arm640.28.1间接
npm@esbuild/netbsd-x640.28.1间接
npm@esbuild/openbsd-arm640.28.1间接
npm@esbuild/openbsd-x640.28.1间接
npm@esbuild/openharmony-arm640.28.1间接
npm@esbuild/sunos-x640.28.1间接
npm@esbuild/win32-arm640.28.1间接
npm@esbuild/win32-ia320.28.1间接
npm@esbuild/win32-x640.28.1间接
npm@eslint-community/eslint-utils4.9.1间接
npm@eslint-community/regexpp4.12.2间接
npm@eslint/config-array0.21.2间接
npm@eslint/config-helpers0.4.2间接
npm@eslint/core0.17.0间接
npm@eslint/eslintrc3.3.5间接
npm@eslint/js9.39.4间接
npm@eslint/object-schema2.1.7间接
npm@eslint/plugin-kit0.4.1间接
npm@hono/node-server1.19.14间接
npm@humanfs/core0.19.2间接
npm@humanfs/node0.16.8间接
npm@humanfs/types0.15.0间接
npm@humanwhocodes/module-importer1.0.1间接
npm@humanwhocodes/retry0.4.3间接
npm@isaacs/cliui8.0.2间接
npm@pkgjs/parseargs0.11.0间接
npm@preact/signals-core1.14.2间接
npm@puppeteer/browsers3.0.6间接
npm@types/estree1.0.9间接
npm@types/json-schema7.0.15间接
npm@types/mocha10.0.10间接
npm@types/node22.19.18间接
npm@typescript-eslint/eslint-plugin8.59.2间接
npm@typescript-eslint/parser8.59.2间接
npm@typescript-eslint/project-service8.59.2间接
npm@typescript-eslint/scope-manager8.59.2间接
npm@typescript-eslint/tsconfig-utils8.59.2间接
npm@typescript-eslint/type-utils8.59.2间接
npm@typescript-eslint/types8.59.2间接
npm@typescript-eslint/typescript-estree8.59.2间接
npm@typescript-eslint/utils8.59.2间接
npm@typescript-eslint/visitor-keys8.59.2间接
npmaccepts2.0.0间接
npmacorn8.16.0间接
npmacorn-jsx5.3.2间接
npmajv6.15.0间接
npmajv8.20.0间接
npmajv-formats3.0.1间接
npmansi-regex5.0.1间接
npmansi-regex6.2.2间接
npmansi-styles3.2.1间接
npmansi-styles4.3.0间接
npmansi-styles6.2.3间接
npmargparse2.0.1间接
npmarray-buffer-byte-length1.0.2间接
npmarraybuffer.prototype.slice1.0.4间接
npmasync-function1.0.0间接
npmavailable-typed-arrays1.0.7间接
npmbalanced-match1.0.2间接
npmbalanced-match4.0.4间接
npmbody-parser2.2.2间接
npmbrace-expansion1.1.14间接
npmbrace-expansion2.1.0间接
npmbrace-expansion5.0.6间接
npmbrowser-stdout1.3.1间接
npmbytes3.1.2间接
npmcall-bind1.0.9间接
npmcall-bind-apply-helpers1.0.2间接
npmcall-bound1.0.4间接
npmcallsites3.1.0间接
npmcamelcase6.3.0间接
npmchalk2.4.2间接
npmchalk4.1.2间接
npmchokidar4.0.3间接
npmchromium-bidi16.0.1间接
npmcliui8.0.1间接
npmcliui9.0.1间接
npmcolor-convert1.9.3间接
npmcolor-convert2.0.1间接
npmcolor-name1.1.3间接
npmcolor-name1.1.4间接
npmconcat-map0.0.1间接
npmcontent-disposition1.1.0间接
npmcontent-type1.0.5间接
npmcontent-type2.0.0间接
npmcookie0.7.2间接
npmcookie-signature1.2.2间接
npmcors2.8.6间接
npmcross-spawn6.0.6间接
npmcross-spawn7.0.6间接
npmdata-view-buffer1.0.2间接
npmdata-view-byte-length1.0.2间接
npmdata-view-byte-offset1.0.1间接
npmdebug4.4.3间接
npmdecamelize4.0.0间接
npmdeep-is0.1.4间接
npmdefine-data-property1.1.4间接
npmdefine-properties1.2.1间接
npmdepd2.0.0间接
npmdetect-libc2.1.2间接
npmdevtools-protocol0.0.1638949间接
npmdiff7.0.0间接
npmdunder-proto1.0.1间接
npmeastasianwidth0.2.0间接
npmee-first1.1.1间接
npmemoji-regex10.6.0间接
npmemoji-regex8.0.0间接
npmemoji-regex9.2.2间接
npmencodeurl2.0.0间接
npmerror-ex1.3.4间接
npmes-abstract1.24.2间接
npmes-define-property1.0.1间接
npmes-errors1.3.0间接
npmes-object-atoms1.1.1间接
npmes-set-tostringtag2.1.0间接
npmes-to-primitive1.3.0间接
npmesbuild0.28.1间接
npmescalade3.2.0间接
npmescape-html1.0.3间接
npmescape-string-regexp1.0.5间接
npmescape-string-regexp4.0.0间接
npmeslint9.39.4间接
npmeslint-scope8.4.0间接
npmeslint-visitor-keys3.4.3间接
npmeslint-visitor-keys4.2.1间接
npmeslint-visitor-keys5.0.1间接
npmespree10.4.0间接
npmesquery1.7.0间接
npmesrecurse4.3.0间接
npmestraverse5.3.0间接
npmesutils2.0.3间接
npmetag1.8.1间接
npmeventsource3.0.7间接
npmeventsource-parser3.1.0间接
npmexpress5.2.1间接
npmexpress-rate-limit8.5.2间接
npmfast-deep-equal3.1.3间接
npmfast-json-stable-stringify2.1.0间接
npmfast-levenshtein2.0.6间接
npmfast-uri3.1.2间接
npmfdir6.5.0间接
npmfile-entry-cache8.0.0间接
npmfinalhandler2.1.1间接
npmfind-up5.0.0间接
npmflat5.0.2间接
npmflat-cache4.0.1间接
npmflatted3.4.2间接
npmfor-each0.3.5间接
npmforeground-child3.3.1间接
npmforwarded0.2.0间接
npmfresh2.0.0间接
npmfsevents2.3.2间接
npmfunction-bind1.1.2间接
npmfunction.prototype.name1.1.8间接
npmfunctions-have-names1.2.3间接
npmgenerator-function2.0.1间接
npmget-caller-file2.0.5间接
npmget-east-asian-width1.6.0间接
npmget-intrinsic1.3.0间接
npmget-proto1.0.1间接
npmget-symbol-description1.1.0间接
npmglob10.5.0间接
npmglob-parent6.0.2间接
npmglobals14.0.0间接
npmglobalthis1.0.4间接
npmgopd1.2.0间接
npmgraceful-fs4.2.11间接
npmhas-bigints1.1.0间接
npmhas-flag3.0.0间接
npmhas-flag4.0.0间接
npmhas-property-descriptors1.0.2间接
npmhas-proto1.2.0间接
npmhas-symbols1.1.0间接
npmhas-tostringtag1.0.2间接
npmhasown2.0.3间接
npmhe1.2.0间接
npmhono4.12.27间接
npmhosted-git-info2.8.9间接
npmhttp-errors2.0.1间接
npmiconv-lite0.7.2间接
npmignore5.3.2间接
npmignore7.0.5间接
npmimport-fresh3.3.1间接
npmimurmurhash0.1.4间接
npminherits2.0.4间接
npminternal-slot1.1.0间接
npmip-address10.2.0间接
npmipaddr.js1.9.1间接
npmis-array-buffer3.0.5间接
npmis-arrayish0.2.1间接
npmis-async-function2.1.1间接
npmis-bigint1.1.0间接
npmis-boolean-object1.2.2间接
npmis-callable1.2.7间接
npmis-core-module2.16.2间接
npmis-data-view1.0.2间接
npmis-date-object1.1.0间接
npmis-extglob2.1.1间接
npmis-finalizationregistry1.1.1间接
npmis-fullwidth-code-point3.0.0间接
npmis-generator-function1.1.2间接
npmis-glob4.0.3间接
npmis-map2.0.3间接
npmis-negative-zero2.0.3间接
npmis-number-object1.1.1间接
npmis-path-inside3.0.3间接
npmis-plain-obj2.1.0间接
npmis-promise4.0.0间接
npmis-regex1.2.1间接
npmis-set2.0.3间接
npmis-shared-array-buffer1.0.4间接
npmis-string1.1.1间接
npmis-symbol1.1.1间接
npmis-typed-array1.1.15间接
npmis-unicode-supported0.1.0间接
npmis-weakmap2.0.2间接
npmis-weakref1.1.1间接
npmis-weakset2.0.4间接
npmisarray2.0.5间接
npmisexe2.0.0间接
npmjackspeak3.4.3间接
npmjose6.2.3间接
npmjs-yaml4.3.0间接
npmjson-buffer3.0.1间接
npmjson-parse-better-errors1.0.2间接
npmjson-schema-traverse0.4.1间接
npmjson-schema-traverse1.0.0间接
npmjson-schema-typed8.0.2间接
npmjson-stable-stringify-without-jsonify1.0.1间接
npmkeyv4.5.4间接
npmlevn0.4.1间接
npmload-json-file4.0.0间接
npmlocate-path6.0.0间接
npmlodash.merge4.6.2间接
npmlog-symbols4.1.0间接
npmlru-cache10.4.3间接
npmmath-intrinsics1.1.0间接
npmmedia-typer1.1.0间接
npmmemorystream0.3.1间接
npmmerge-descriptors2.0.0间接
npmmime-db1.54.0间接
npmmime-types3.0.2间接
npmminimatch10.2.5间接
npmminimatch3.1.5间接
npmminimatch9.0.9间接
npmminipass7.1.3间接
npmmitt3.0.1间接
npmmocha11.7.6间接
npmmodern-tar0.7.6间接
npmms2.1.3间接
npmnatural-compare1.4.0间接
npmnegotiator1.0.0间接
npmnice-try1.0.5间接
npmnormalize-package-data2.5.0间接
npmnpm-run-all4.1.5间接
npmobject-assign4.1.1间接
npmobject-inspect1.13.4间接
npmobject-keys1.1.1间接
npmobject.assign4.1.7间接
npmon-finished2.4.1间接
npmonce1.4.0间接
npmoptionator0.9.4间接
npmown-keys1.0.1间接
npmp-limit3.1.0间接
npmp-locate5.0.0间接
npmpackage-json-from-dist1.0.1间接
npmparent-module1.0.1间接
npmparse-json4.0.0间接
npmparseurl1.3.3间接
npmpath-exists4.0.0间接
npmpath-key2.0.1间接
npmpath-key3.1.1间接
npmpath-parse1.0.7间接
npmpath-scurry1.11.1间接
npmpath-to-regexp8.4.2间接
npmpath-type3.0.0间接
npmpicocolors1.1.1间接
npmpicomatch4.0.4间接
npmpidtree0.3.1间接
npmpify3.0.0间接
npmpkce-challenge5.0.1间接
npmplaywright1.60.0间接
npmplaywright-core1.60.0间接
npmpossible-typed-array-names1.1.0间接
npmprelude-ls1.2.1间接
npmproxy-addr2.0.7间接
npmpunycode2.3.1间接
npmpuppeteer-core25.3.0间接
npmqs6.15.2间接
npmrange-parser1.2.1间接
npmraw-body3.0.2间接
npmread-pkg3.0.0间接
npmreaddirp4.1.2间接
npmreflect.getprototypeof1.0.10间接
npmregexp.prototype.flags1.5.4间接
npmrequire-directory2.1.1间接
npmrequire-from-string2.0.2间接
npmresolve1.22.12间接
npmresolve-from4.0.0间接
npmrouter2.2.0间接
npmsafe-array-concat1.1.4间接
npmsafe-push-apply1.0.0间接
npmsafe-regex-test1.1.0间接
npmsafer-buffer2.1.2间接
npmsemver5.7.2间接
npmsemver7.8.0间接
npmsend1.2.1间接
npmserialize-javascript7.0.7间接
npmserve-static2.2.1间接
npmset-function-length1.2.2间接
npmset-function-name2.0.2间接
npmset-proto1.0.0间接
npmsetprototypeof1.2.0间接
npmshebang-command1.2.0间接
npmshebang-command2.0.0间接
npmshebang-regex1.0.0间接
npmshebang-regex3.0.0间接
npmshell-quote1.9.0间接
npmside-channel1.1.0间接
npmside-channel-list1.0.1间接
npmside-channel-map1.0.1间接
npmside-channel-weakmap1.0.2间接
npmsignal-exit4.1.0间接
npmspdx-correct3.2.0间接
npmspdx-exceptions2.5.0间接
npmspdx-expression-parse3.0.1间接
npmspdx-license-ids3.0.23间接
npmstatuses2.0.2间接
npmstop-iteration-iterator1.1.0间接
npmstring-width4.2.3间接
npmstring-width5.1.2间接
npmstring-width7.2.0间接
npmstring.prototype.padend3.1.6间接
npmstring.prototype.trim1.2.10间接
npmstring.prototype.trimend1.0.9间接
npmstring.prototype.trimstart1.0.8间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.2.0间接
npmstrip-bom3.0.0间接
npmstrip-json-comments3.1.1间接
npmsupports-color5.5.0间接
npmsupports-color7.2.0间接
npmsupports-color8.1.1间接
npmsupports-preserve-symlinks-flag1.0.0间接
npmtinyglobby0.2.16间接
npmtoidentifier1.0.1间接
npmts-api-utils2.5.0间接
npmtype-check0.4.0间接
npmtype-is2.1.0间接
npmtyped-array-buffer1.0.3间接
npmtyped-array-byte-length1.0.3间接
npmtyped-array-byte-offset1.0.4间接
npmtyped-array-length1.0.7间接
npmtyped-query-selector2.12.2间接
npmtypescript5.9.3间接
npmtypescript-eslint8.59.2间接
npmunbox-primitive1.1.0间接
npmundici-types6.21.0间接
npmunpipe1.0.0间接
npmuri-js4.4.1间接
npmvalidate-npm-package-license3.0.4间接
npmvary1.1.2间接
npmwebdriver-bidi-protocol0.4.2间接
npmwhich1.3.1间接
npmwhich2.0.2间接
npmwhich-boxed-primitive1.1.1间接
npmwhich-builtin-type1.2.1间接
npmwhich-collection1.0.2间接
npmwhich-typed-array1.1.20间接
npmword-wrap1.2.5间接
npmworkerpool9.3.4间接
npmwrap-ansi7.0.0间接
npmwrap-ansi8.1.0间接
npmwrap-ansi9.0.2间接
npmwrappy1.0.2间接
npmws8.21.0间接
npmy18n5.0.8间接
npmyargs17.7.3间接
npmyargs18.0.0间接
npmyargs-parser21.1.1间接
npmyargs-parser22.0.0间接
npmyargs-unparser2.0.0间接
npmyocto-queue0.1.0间接
npmzod3.25.76间接
npmzod4.4.3间接
npmzod-to-json-schema3.25.2间接
依赖安全公告 7

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 419 个包,其中也包含从不交付的开发与测试版本固定:7 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
brace-expansion1.1.14间接15.0.7
brace-expansion2.1.0间接15.0.7
brace-expansion5.0.6间接15.0.7
fast-uri3.1.2间接24.1.1
@hono/node-server1.19.14间接12.0.5
diff7.0.0间接18.0.3
body-parser2.2.2间接12.3.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 17951,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "CSS": 32134,
        "Shell": 7174,
        "Python": 21359,
        "Dockerfile": 3316,
        "JavaScript": 21423,
        "TypeScript": 3946584
      },
      "pushed_at": "2026-07-17T13:35:11Z",
      "created_at": "2026-07-10T15:18:16Z",
      "owner_type": "User",
      "updated_at": "2026-07-17T13:36:17Z",
      "description": "AgentlensPro — professional AI-agent observability: OTEL + local-log ingestion, burn forensics, cost analytics, burn-gate hooks. CLI + server + skills.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://twitter.com/fmuaddib/",
      "name": "Emanuele Sabetta",
      "type": "User",
      "login": "Emasoft",
      "company": null,
      "location": "Rome, Italy",
      "followers": 168,
      "avatar_url": "https://avatars.githubusercontent.com/u/713559?v=4",
      "created_at": "2011-04-06T17:17:14Z",
      "is_verified": null,
      "public_repos": 88,
      "account_age_days": 5585
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.10.1",
          "kind": "patch",
          "published_at": "2026-07-17T13:32:37Z"
        },
        {
          "tag": "v2.10.0",
          "kind": "minor",
          "published_at": "2026-07-17T07:03:49Z"
        },
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-07-17T04:44:26Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-07-16T14:04:57Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-07-13T03:22:02Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2026-07-12T22:58:11Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-12T07:07:02Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-11T15:46:57Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-11T15:35:51Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2026-07-11T09:00:35Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-07-11T08:51:04Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-07-11T08:34:21Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T06:15:38Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-07-11T03:16:56Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-07-11T02:30:03Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-10T20:29:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ae5022e8615cf82990521a5382131f8070bf8546",
          "body": "…enance verified)",
          "is_bot": false,
          "headline": "docs(trdd): F1VX3M7C published in v2.10.1 (OIDC run 29584261167, prov…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T13:35:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa76159857f9ef75ed688be6c3405b9553109b62",
          "body": "….10.1\n\n2.10.1 bundles three TRDDs (WYC4KB50 embed hardening, F1VX3M7C fail-closed boot, and\n06Q5AXYN global time-window). The time-window scoping + historical collector banner are\nuser-facing and must be in the release notes.",
          "is_bot": false,
          "headline": "docs(changelog): document the 06Q5AXYN time-window work shipping in 2…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T13:30:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d17495e35f9d4e8160419bec9415a7148be108b",
          "body": "…s-up moot\n\nCross-reference the reversal so the board is coherent: #1's soft-fail → fail-closed\nrefuse-to-boot; the queued #4 §B1 heads-up is no longer needed.",
          "is_bot": false,
          "headline": "docs(trdd): WYC4KB50 STATE — finding #1 reversed by F1VX3M7C, #4 head…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:25:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "635158ea978030b1f2d7f561856c9e51c63a4212",
          "body": "…y (TRDD-F1VX3M7C)\n\nMemory security-model layer 5 corrected soft-fail→fail-closed; [^3] soft-fail lesson\ndemoted to superseded, [^4] added with the WHY (owner ruled security>availability;\ncrash-loop [^3] warned of is mitigated via supervisor-terminal exit 78, not avoided).\nTRDD marked complete: gate green, live-proof of refuse-to-boot on corrupt + wider-than-\n0600 keys, deployed pid 2372. #4 heads-up no longer needed (thread accurate again); tag\nv2.10.1 stays user-gated.",
          "is_bot": false,
          "headline": "docs(memory+trdd): F1VX3M7C fail-closed embed-key boot SHIPPED locall…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:24:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b87c4120791084b72a86d7f341fa4488a13d65ae",
          "body": "…terminal (TRDD-F1VX3M7C)\n\nFactor the supervisor's 'don't respawn a deliberate config refusal' decision out of the\nspawn closure into a pure, exported isTerminalExit(code) so the policy is unit-testable\nwithout spawning a process (the live terminal branch calls process.exit). 5 tests pin:\n78 terminal; 0/1/134/null all respawn-eligible crashes.",
          "is_bot": false,
          "headline": "test(embed): extract isTerminalExit predicate + pin EX_CONFIG(78)-is-…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:18:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca67c6fefb1d6dee979b3bd8a9601cdcf5a0cfc8",
          "body": "…RDD-F1VX3M7C)\n\nA bad/exposed embed-key refuses to boot (EX_CONFIG 78, supervisor-terminal) — matches\nthe public AgentlensPro#4 contract, so no consumer heads-up is needed. Reverses the\nsoft-fail wording WYC4KB50 introduced.",
          "is_bot": false,
          "headline": "docs(embed): fail-closed boot wording in CHANGELOG 2.10.1 + README (T…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:15:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a443caa2859f649b72ba3769dd20eea56f6ecf0",
          "body": "…key (TRDD-F1VX3M7C)\n\nReverses WYC4KB50 #1's soft-fail per the owner's directive (\"go with the more secure\nversion\"). A corrupt or wider-than-0600 ~/.agentlens/embed-key now refuses to boot\n(exit EX_CONFIG 78) instead of disabling the feature and running on — a shared HMAC\nsecret other local account\n[…]\nevive crash loop; this also closes a latent DISABLED-mid-supervision\nrespawn-loop. ensureEmbedKey's throw contract is unchanged; only the boot-site response\nflips. Bundle rebuilt in the deploy commit.",
          "is_bot": false,
          "headline": "fix(embed): fail-closed boot — refuse to boot on a bad/exposed embed-…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:14:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd8320cc9d0ac174f8d71fe87769e4daac048e5d",
          "body": "…losed boot (user directive)\n\nReverses only WYC4KB50 finding #1's boot-site softening: a bad/exposed embed-key\nrefuses to boot (fail-closed) instead of disabling the feature and running. Adds the\nmandatory derived task — the supervisor treats EX_CONFIG(78) as terminal — so the\nreversal does not reintroduce the documented hook-revive crash loop. Keeps all 12\nother WYC4KB50 hardenings.",
          "is_bot": false,
          "headline": "docs(trdd): add TRDD-F1VX3M7C — reverse embed-key soft-fail to fail-c…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T12:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55c4654db251a144aebaa50b4559fdd18181794b",
          "body": "…^2] lesson\n\nAdd Cost() to the dead top-level-export inventory (alongside Traces()/Flow()):\nno 'cost' tab in App.tsx TABS, esbuild tree-shakes it; the 30-day/lifetime cost\nchart it wraps renders nowhere, only fmtUsd/CostBarChart/CostSection are live.\nRecord Alerts/Automation/CollectorGapBanner rende\n[…]\nPhase 2 + a reroute) — both inert —\nbecause the work trusted a file inventory and did not recall this page first.\n[^2] demotes that to a guardrail: map TABS/ActivePanel before editing a tab component.",
          "is_bot": false,
          "headline": "docs(memory): dashboard-tree-render-topology — Cost() is dead too + […",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T10:39:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19907551dd86fd328cea965a340e38bfe1374507",
          "body": "…mponents (Phase 2 + Flow reroute inert); core windowing delivered via Phase 1 rangedSessions + live reroutes + Phase 4 banner",
          "is_bot": false,
          "headline": "docs(trdd): 06Q5AXYN live-tree correction — Cost()/Flow() are dead co…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T10:21:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c2a757df0d76d18370de8cf6000471f4908bafe",
          "body": "…st-tense + windowed (TRDD-06Q5AXYN)\n\ncomputeCollectorGaps only ever emits PAST windows (a gap is bounded by the next run's start),\nbut the banner headline was present-tense 'Collector offline', so a server restart made a fresh\ngap read as 'offline now' — the iframe false alarm. Now: headline is pas\n[…]\nl, and\nthe gap list is scoped to the active time window (only gaps intersecting it; 'All' shows every\ngap). Live-verified: banner renders 'Collector was offline — telemetry lost during these windows'.",
          "is_bot": false,
          "headline": "feat(dashboard): global time-window Phase 4 — collector-gap banner pa…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T10:21:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f9b2f53bf5bb58eb68551fc049d0740d6adad04",
          "body": "…he picker (TRDD-06Q5AXYN)\n\nThe Cost tab's 30-day chart + lifetime tiles read the independent dailyStats/lifetimeStats\nfeeds (lifetime, per-day bucketed), so a bounded window still showed 30-day/lifetime numbers.\nNow: preset 'all' keeps the lifetime chart+tiles; a bounded preset drops the per-day ba\n[…]\nready-window-scoped priced\nsession set (sessions/tokens/cost/date-range). Also removes a dead no-op filteredStats ternary.\nburnRateData/serverBurnStatus stay live 'now' metrics (documented exemption).",
          "is_bot": false,
          "headline": "feat(dashboard): global time-window Phase 2 — Cost aggregates honor t…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T10:08:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0d0eaf49487b946181d595105ce41c7c4c397f3",
          "body": "…ty + route 4 un-scoped surfaces (TRDD-06Q5AXYN)\n\nThe time-range picker renders on every tab (implying global scope) but only surfaces that\nconsume filteredSessions honored it; History/Flow/Alerts/Automation read raw sessionSummary/\ndisplaySessions and ignored the window, so a 15m filter still surfa\n[…]\nsions; Alerts via buildDisplaySummary's\n  default switched to the windowed list (only Alerts uses the default — Sessions/Insights\n  pass explicit overrides), so every alert evaluation is windowed too.",
          "is_bot": false,
          "headline": "feat(dashboard): global time-window Phase 1 — sessionInWindow authori…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T10:03:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce301da68b172c2f7955ec0223dc63c6eaf24c2c",
          "body": "… stat, chart",
          "is_bot": false,
          "headline": "docs(trdd): add TRDD-06Q5AXYN — global time-window scopes every list,…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T09:54:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f788ce52762ee0f25ba613e3303022968514221b",
          "body": "…on, security-model layer 5 correction\n\nCloses the code-review remediation. TRDD STATE → SHIPPED (all 13, live-proven).\nSecurity-model layer 5 now records that an unusable embed-key DISABLES the feature\n(fail-closed) instead of crashing the server, and lesson [^3]\nATOM-OPTIONAL-FEATURE-SOFT-FAIL captures the WHY — an opt-in feature's boot\ndependency must not throw at module load (it took OTLP/hooks/CLI down and\nhook-revive crash-looped). Supersedes the earlier refuse-to-boot fact.",
          "is_bot": false,
          "headline": "docs(memory+trdd): WYC4KB50 SHIPPED — soft-fail-optional-feature less…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:52:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43f7a361568bfdbe51c90c6bb409f1ed0d5afa9c",
          "body": "…recipe; bump 2.10.1 (TRDD-WYC4KB50)\n\nPhase 4 of the code-review remediation — docs to match the Phase 1-2 behavior\nchange, plus the two documented non-goals and the lost recipe.\n\n- #1 README embed-key wording: 'refuses to boot on a corrupt/wider-than-0600 key'\n  → the embed feature disables itself \n[…]\ne the portability fix 2088d7e — no username is assumed).\n- CHANGELOG [2.10.1] + package.json bump (user-facing behavior change).\n\nNo functional code in this phase (serverControl edit is comment-only).",
          "is_bot": false,
          "headline": "docs(embed): soft-fail wording, MCP/Docker non-goals, manual-install …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:47:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e97df41e031d7a48bbc29c1769b44c34848dadb",
          "body": "…nfig affordance (TRDD-WYC4KB50)\n\nPhase 3 of the code-review remediation.\n\n- #6 one source of truth for the restricted-viewer tab policy: state.ts now\n  exports RESTRICTED_BLOCKED_TABS + isRestrictedBlockedTab(id), and the three\n  enforcement sites use it — the tab-bar filter (App.tsx), the host-mes\n[…]\naned\npresentSources/baseSessions pair and the now-unused rangedSessions import in\nApp.tsx — a 'sources pills' computation whose only consumer was removed earlier.\n\ntsc x2 + lint + check-mirrors clean.",
          "is_bot": false,
          "headline": "fix(dashboard): centralize restricted-tab policy; hide dead alerts-co…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:45:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1d923eeb74f00760fc429213685da0a6cfac4c2",
          "body": "…dmission-exempt embed-status (TRDD-WYC4KB50)\n\nPhase 2 of the code-review remediation.\n\n- #1 EMBED_KEY is now Buffer|null: ensureEmbedKey is wrapped in try/catch at\n  boot. An unusable key (corrupt hex / wider-than-0600) logs loudly and leaves\n  EMBED_KEY null — the viewer-role gate then 403s any PR\n[…]\nadmission control.\n- #8 documented as a non-goal: the viewer-role gate is UI-server-only; the MCP\n  port is loopback + origin-checked, server-to-server, never proxied to viewers.\n\ntsc x2 + lint clean.",
          "is_bot": false,
          "headline": "fix(embed): server soft-fails a bad key instead of crashing; Vary + a…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:41:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29ca817f2ff3be9f76cf19eed7463e1d5ae53614",
          "body": "…tomic-write reuse, null-key policy (TRDD-WYC4KB50)\n\nPhase 1 of the code-review remediation. Four changes, all with tests:\n\n- #2 the POSIX 0600-mode check is gated behind process.platform!=='win32' —\n  Node emulates st_mode on Windows (a 0600-created file reads back 0666), so\n  the wider-than-0600 t\n[…]\n soft-fail that produces the null key lands in Phase 2.\n\n+3 tests (non-object, comma-joined-coalesced #10, null-key) and the wide-mode\ntest now skips on win32. Suite 1355 passing, tsc x2 + lint clean.",
          "is_bot": false,
          "headline": "fix(embed): verifier hardening — win32 mode-gate, non-object guard, a…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:39:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d93c51900920d18170d09124101f6d17bbee0fe",
          "body": "…dings)\n\nTracks remediation of the /code-review xhigh on 798c7bc..HEAD (viewer-role\nassertion 1ZH1D5EG + 2.10.0 + portability). 13 findings, proportionate treatment:\ncode fixes for the correctness/robustness ones, documented non-goals for the\nspeculative-deployment ones (per the project's reactive-only security posture).",
          "is_bot": false,
          "headline": "docs(trdd): add TRDD-WYC4KB50 — xhigh code-review remediation (13 fin…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T08:39:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe195d380c1b29a0a1384b51e88cce37d94dfd61",
          "body": "…-leak detector matched its own anti-pattern quote\n\nThe janitor's memory-scope-leak detector flags /Users/<seg>/ shapes in PROJECT\nmemory unless <seg> is a generic account; the lesson ABOUT the /Users/ anti-\npattern quoted '/Users/@USER@/' verbatim and got flagged as a leak (a quoted\nexemplar, not private data — no username anywhere). Rephrased to keep both\nliterals without forming the /Users/<seg>/ shape, so the detector re-run\nclears instead of re-firing every sweep.",
          "is_bot": false,
          "headline": "docs(memory): spell the [^12] exemplar paths pattern-safe — the scope…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T07:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a064c0d6e50d37f0b30f3b1fe0eba5a45689c0b9",
          "body": "… 7/7 interop vs live 2.10.0, vector pinned in both CIs)",
          "is_bot": false,
          "headline": "docs(trdd): 1ZH1D5EG — consumer closed the loop (ai-maestro f7104bc9,…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T07:35:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2088d7ec07074f29824b8b5bab9c7a2f1ca99590",
          "body": "…ame or home layout\n\nOwner directive: AgentlensPro/ai-maestro can be installed by anyone — never\nassume a specific user. The stale scripts/agentlens.plist.template hardcoded\n/Users/@USER@/… (breaks custom/network homes, non-/Users layouts) and had\nalready drifted from the EMBEDDED plist daemonInstal\n[…]\ne one source of truth and self-installs from any npm layout. Also\ngenericized the one test fixture carrying the dev machine's real username.\nMemory lesson ATOM-NO-USERNAME-ASSUMPTION records the rule.",
          "is_bot": false,
          "headline": "fix(portability): no shipped surface may assume the installer's usern…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T07:13:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4406ec362304a5ffb054bb04ec75c51e55564693",
          "body": "…ro#4 contract)\n\nCut immediately after the feature because the ai-maestro Claude's proxy work\nwaits on an npm floor it can pin (its dependency contract pins released\nversions, not main) — the gate is already live-proven on the running server.",
          "is_bot": false,
          "headline": "chore(release): 2.10.0 — signed viewer-role assertion (the AgentlensP…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T07:02:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07587f340c99908e2c5548ca07dd12844b7eda79",
          "body": "…gate layers, fail-closed lesson\n\nLayers 4 (frame-ancestors, FMIZO8Y4) and 5 (X-Agentlens-Viewer role gate,\n1ZH1D5EG) join the page that owns the server's browser-facing threat model;\nlesson ATOM-FAIL-CLOSED-NOT-DOWNGRADE records why an unverifiable assertion\nmust 403 rather than fall back to the (more-permissive) standalone default.",
          "is_bot": false,
          "headline": "docs(memory): server security model — framing contract + viewer-role …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T06:08:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "553e258a2c0211d9e381e9978ad24350e29ab1c3",
          "body": "…oven (TRDD-1ZH1D5EG, phase 4)\n\nVIEWER_HEADER becomes ONE exported constant (server + contract tests import it\nso a rename cannot half-land); the aimaestro contract file pins the header name\nand the §B5 decision-table verdicts with BREAK messages routing authors to #4;\nREADME documents the full proxy-facing contract; CHANGELOG opens the next\n[Unreleased]. Live-verified 9/9 against the running server with real signed\nassertions (standalone/user/maestro/garbage × GET/POST/hook-config/meta).",
          "is_bot": false,
          "headline": "docs+contract(embed): viewer-role surface pinned, documented, live-pr…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T05:15:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63e9ed130b797464de7c94918ead89af1037976b",
          "body": "…ry entry point (TRDD-1ZH1D5EG, phase 3)\n\nThe server injects <meta name=agentlens-viewer content=restricted> when the\nsigned assertion says role:user; the webview reads it ONCE at boot (a constant,\nnot a signal — the verdict is per-document and cannot change within a page\nlife). Four entry points ga\n[…]\nrands\nthe viewer on a view whose only action 403s), and the host switchTab message\n(alerts/automation/settings-automation/import). UI-only convenience — the\nserver method gate remains the enforcement.",
          "is_bot": false,
          "headline": "feat(dashboard): restricted-viewer mode — settings chrome gone at eve…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T05:10:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12479241b586ef60494616ac2d2430243563c44b",
          "body": "…s, invalid≠restricted, embed-status probe (TRDD-1ZH1D5EG, phase 2)\n\nThe ai-maestro Claude posted the complete spec + a runnable test vector after\nphase 1 landed; three deltas adopted: (1) v:1 contract version, unknown v\nrejected; (2) an unverifiable header is 'invalid' → 403 EVERYTHING, distinct\nfr\n[…]\nGET /api/hook-config also 403'd for restricted (the one read that\nleaks the settings the panel shows), GET /api/embed-status added so ai-maestro\ncan PROVE the gate is live instead of assuming (#4 Q9).",
          "is_bot": false,
          "headline": "feat(embed): viewer-role gate wired per the full #4 spec — v1 payload…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T05:08:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef9b2b62042579bc554b065a56149afdbfbb52fc",
          "body": "…#4 contract core (TRDD-1ZH1D5EG, phase 1)\n\nai-maestro's proxy stamps X-Agentlens-Viewer per request so the settings panel\ncan be MAESTRO-only (owner directive). Verifier is fail-restricted by design:\na PRESENT header can only grant maestro or restricted — every failure mode\n(bad sig, expired, malfo\n[…]\n ~/.agentlens/embed-key (corrupt file throws — regenerating silently\nwould desync ai-maestro's copy). Also files TRDD-KDGJ0R38 (basePath, backburner)\n— their named need that removes their CSP rewrite.",
          "is_bot": false,
          "headline": "feat(embed): signed viewer-role assertion verifier — the AgentlensPro…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T05:01:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "798c7bcd6a2864101ca9cb057f43fee9a3ed3b65",
          "body": "…he-health contract lock\n\nMinor bump: three additive features since 2.8.0 (the ai-maestro iframe embed\ncontract TRDD-FMIZO8Y4, the transcript-SQL engine TRDD-YJQXLHPA, the pinned\ncache-health CLI contract from AgentlensPro#3) plus the store object cache\n(TRDD-802FP7ZL). Cutting now because the ai-maestro embed integration consumes\nthis surface — the npm tarball must carry what main@8b4a464 already proves live.",
          "is_bot": false,
          "headline": "chore(release): 2.9.0 — embeddable dashboard, run_transcript_sql, cac…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T04:42:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b4a4645bd04b7af6bded770177e985500fea451",
          "body": "…estors contract + embed/deep-link params (TRDD-FMIZO8Y4)\n\nUSER directive: \"prepare the dashboard to be loaded directly into ai-maestro as an\niframe or something better\". The something-better is making the iframe CONTRACT-grade\ninstead of permission-by-omission:\n\n- standalone/server.ts: the HTML res\n[…]\nx2 0, lint 0, mirrors OK, 6/6 new\ntests; deployed pid 20191. A theme param was deliberately dropped: the webview has no\ntheme mechanism to wire (recorded in the TRDD so it is not re-proposed blindly).",
          "is_bot": false,
          "headline": "feat(dashboard): embeddable in the ai-maestro UI — loopback frame-anc…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-17T04:22:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1217558accd8e073c9a7e9764a6aeda9a50fc5cb",
          "body": "…OM-THREE-SQL-ENGINES) + raw-NUL-makes-source-binary (ATOM-RAW-NUL-BINARY)\n\nCaptured from tonight's work while the WHY is still first-hand:\n- [^10] the corpus-mining shortlist put DuckDB pragmas on run_diagnostics_sql (a\n  sql.js/SQLite snapshot whose gate rejects PRAGMA) and proposed backing up a c\n[…]\nkTimeline.ts binary to grep/file/diff\n  (grep -n returned NOTHING on a 1371-line module) — spell NUL as the escape; the\n  symptom to recall by is \"grep finds nothing in a file that obviously matches\".",
          "is_bot": false,
          "headline": "docs(memory): ops-lessons +2 — the three-SQL-engines routing trap (AT…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T21:49:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f256216394f286a074105c9e6af5e11d2b31f7f9",
          "body": "…end-to-end (TRDD-YJQXLHPA, phases 2-3)\n\nTOOLS entry + dispatch case for the phase-1 engine (CLI comes free from the schema),\nCHANGELOG entry, diagnostics-skill cheat-sheet row, TRDD -> ai_review.\n\nLive-verified on the real corpus post-deploy: no-arg lists the 4 presets;\nusage_by_model over a 6h window aggregated 7 models. Gate: 1328 passing / 0 failing,\ntsc both runtimes 0, lint 0 errors; bundle symbol grep 2 hits; server pid 37329.",
          "is_bot": false,
          "headline": "feat(mcp): run_transcript_sql tool — the transcript-SQL engine wired …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T21:27:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a6ec2b7194106b940997333ea52462b7901c669",
          "body": "…ssion .jsonl corpus (TRDD-YJQXLHPA, phase 1)\n\nThe last DuckDB-corpus shortlist item: ad-hoc cost/cause/content questions answered by\nSQL over the transcripts directly, instead of a hand-written drill handler per question.\n\n- src/transcriptSql.ts: files pre-filtered in JS (sessionId fast path, else \n[…]\nncl. subagent transcripts, mtime\n  windowing, gate rejection, cap reporting, truncated-last-line live files, JSON-safe\n  rows).\n\nGate: tsc both runtimes 0; new suite 12/12. Phase 2 wires the MCP tool.",
          "is_bot": false,
          "headline": "feat(transcripts): transcript-SQL engine — bounded DuckDB over the se…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T21:23:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6fb1b4294529a54f93636405eafa03e8d8c0004",
          "body": "…s report corrected",
          "is_bot": false,
          "headline": "docs(trdd): 802FP7ZL shipped (1c378c9) — column → ai_review; synthesi…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:58:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c378c9dccf1aef88b5353995a492cb44ef65ab5",
          "body": "…twice no-op contract (TRDD-802FP7ZL)\n\nTwo quick wins adopted from the DuckDB-skills corpus mining, each verified against\nthe actual code before landing (the mining's other two store items were premise-wrong\nand are recorded as corrections in the TRDD: run_diagnostics_sql presets execute on\nthe sql.\n[…]\nrn);\n  (2) current_setting('enable_object_cache') is true on an opened store (TDD: red\n  before the db.ts line, green after).\n\nGate: tsc both runtimes 0; suite 1316 passing / 0 failing; lint 0 errors.",
          "is_bot": false,
          "headline": "perf(store): enable the parquet object cache + pin the migration run-…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:57:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb1530b9bcd655f410d01dd39b7aa8b8ac1d063b",
          "body": "…gration run-twice test); items 2/4 re-scoped out with code-verified corrections",
          "is_bot": false,
          "headline": "docs: add TRDD-802FP7ZL — DuckDB corpus quick wins (object cache + mi…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7db9b6c3e829203d8633e199acf120fb0d6b0de",
          "body": "…, last open #3 question answered",
          "is_bot": false,
          "headline": "docs(trdd): 5F3SE1JM Phase 3 — cache-health contract locked (2343ab0)…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:47:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c294238783d7ed4da3e0a028148b69991bc8ef5f",
          "body": "…ytes made cacheBreakTimeline.ts binary\n\nfile(1) classified the source as 'data' and grep/diff treated it as binary (grep -n\nreturned nothing on a 1371-line module — discovered while enumerating the contract\nshapes for AgentlensPro#3). Cause: three raw 0x00 bytes used as unambiguous separators\n(the \n[…]\nthe source encoding\nchanged — and left a comment at the fingerprint site so the escape is never\n'simplified' back to a raw byte.\n\nGate: tsc 0; cacheBreakTimeline + full suite 1314 passing / 0 failing.",
          "is_bot": false,
          "headline": "fix(hygiene): spell the NUL separators as U+0000 escapes — raw 0x00 b…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:47:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2343ab0d9f16f18c8ae34a5472a9668b1f4200a8",
          "body": "…ored janitor consumes (AgentlensPro#3)\n\nai-maestro asked (twice, on #3) whether check_cache_expiry / get_cache_break_report /\nget_cache_break_gap_report / get_cache_break_timeline are stable in 2.8.0 — the tailored\njanitor consumes them to prevent cache-miss/expiration. Naming a surface without pin\n[…]\nwhich fields are 2.8.0-stable vs post-2.8.0 additive\n  (coverage/note/scanStoppedEarly/scanNote from 4b4dc8f).\n\nGate: tsc both runtimes 0; suite 1314 passing / 0 failing; lint 0 errors.\nTRDD-5F3SE1JM.",
          "is_bot": false,
          "headline": "test(contract): lock the cache-health tool shapes the ai-maestro tail…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T18:46:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be85671f3bbcfce70d194de8019ad739162fd46a",
          "body": "…+ the one-resolver converge rule (ATOM-ONE-RESOLVER)\n\nWHY: both lessons are this week's hard-won recurrence guards. [^8]: no handler\nmay run unbounded synchronous O(corpus) work (microtask-vs-macrotask yield is\nthe load-bearing distinction; scanWithBudget is the pattern, watchdog the\nbackstop, star\n[…]\non-boot makes any writer disagreement drift permanently toward the\nboot's answer (the spool→SSD re-pointing defect, 4efe0f5). Description gained\nthe matching symptom phrases so both recall by symptom.",
          "is_bot": false,
          "headline": "docs(memory): ops-lessons — the wedge-class bound (ATOM-WEDGE-BOUND) …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T17:38:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2871afbab085f02b9b29f121255f72288dbb5b99",
          "body": "… (board sorts on updated)",
          "is_bot": false,
          "headline": "docs(trdd): bump updated timestamps missed by a failed sed in 428c9c0…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T15:44:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "428c9c0902329dcc1fb4a9a8f301ad8b7a140d49",
          "body": "…ctive; K3WDPR7M Phase-3 'not built' misstatement corrected\n\nWHY: the user reported 'no otel logs' as breakage — correct per their standing\ndirective; capture-off-by-default is the right product default but the wrong\nlocal state. Recorded the activation, the converge defect it exposed (4efe0f5),\nand corrected my own same-day reconciliation error (the spool IS built — the\ncode disproved the stale STATE block I trusted; verify against code, not\ncards).",
          "is_bot": false,
          "headline": "docs(trdd+changelog): capture re-enabled per user data-retention dire…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T15:44:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4efe0f5bcd4852fc395b711372e0a99049adc6ef",
          "body": "…onger re-points capture at the SSD (TRDD-BKF5NZD3 × K3WDPR7M)\n\nWHY: two writers computed the OTEL_LOG_RAW_API_BODIES value independently. The\nCLI capture-on flow wired the RAM-disk spool (file:/Volumes/AgentLensSpool/…),\nthen the server-boot converge — whose bodiesDir default was hard-coded to the\n\n[…]\nncl. the exact server-boot shape (spool-blind ensure must\n  write the spool value). Gate 1307/0, tsc 0, lint 0. Live-proven: post-restart\n  converge now holds file:/Volumes/AgentLensSpool/otel-bodies.",
          "is_bot": false,
          "headline": "fix(telemetry): one bodies-dir resolution — spool-blind converge no l…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T15:43:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0cf9f5c7d06d81269046839eabf7e3e137589d7",
          "body": "…WDPR7M phases re-scoped against measured reality\n\nWHY: three claims in these cards' STATE blocks were falsified or resolved by\nlater work, so the board over-reported open engineering. 4CH9QLAH: every\nsub-phase merged + shipped in v2.8.0, /api/branch-dump live in the bundle\n(grep-verified). K3WDPR7M\n[…]\n, so the spool is conditional-on-capture-on work, not urgent; Phase\n4's burn half already landed (9985c34), leaving only dead-path forensics\nchores. The genuinely-open list is now explicit and ranked.",
          "is_bot": false,
          "headline": "docs(trdd): board reconciliation — 4CH9QLAH shipped (→ ai_review); K3…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T15:25:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97dcc12a5ab29d3d769f4781a44fe3599062b40c",
          "body": "…ied shipped, columns → ai_review\n\nWHY: both cards' STATE blocks predated their own fixes landing, so the board\nshowed open work that was already merged + live. 4AFOFVFD: the deferred-findings\nbranch is fully merged into main (verified: main..branch empty), S3-F3b tracked\nin TRDD-DYG4ZTXW (complete)\n[…]\nBODIES key across\nmultiple boots, knob shows off(default). The board must be an accurate live\nindex (design/ zones rule), so stale-open cards are corrected the moment\nverification proves them shipped.",
          "is_bot": false,
          "headline": "docs(trdd): disposition 2 stale dev cards — 4AFOFVFD + BKF5NZD3 verif…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T15:21:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8bb7913e095e31c75cf45f2b971304658422e656",
          "body": "…ep + tool-duration logging (4b4dc8f), column → ai_review\n\nWHY: the STATE block is the authoritative resume record; the two 'STILL OPEN'\ndeliverables landed in 4b4dc8f (bounded check_cache_expiry/cache-break scans via\nthe shared scanWithBudget primitive + per-tool start/done logging as the\nwedge-namer), so the card leaves dev. Audited-clean handlers are listed so the\nsweep's negative results are recorded, not just its fixes.",
          "is_bot": false,
          "headline": "docs(trdd+changelog): X2E6OSWK all deliverables shipped — sibling swe…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T14:26:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b4dc8ffdbbde3c0e52aef4bb46dd1a986d8e5e2",
          "body": "…uration logging (TRDD-X2E6OSWK)\n\nWHY: the 2026-07-16 wedge class is 'unbounded synchronous O(corpus) work inline in\none request'. get_cost_by_cause was bounded in 956c006; this closes the remaining\ninstances and makes any future wedge name itself.\n\n- scanWithBudget: the ONE bounded-scan primitive (\n[…]\nTests: 3 new (probe cap + precision ranking; budget stop with honest coverage,\nnewest-first; complete-coverage label). Suite 1303 passing / 0 failing; tsc 0;\nlint 0. Deployed pid 85113, live-verified.",
          "is_bot": false,
          "headline": "fix(server): bound check_cache_expiry + cache-break scans; per-tool d…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T14:24:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d76ec12751726ab4e8074b4201ba614ed4ff5318",
          "body": "…edge fixes, watchdog, and contract locks",
          "is_bot": false,
          "headline": "docs(changelog): fold Unreleased into 2.8.0 — the release ships the w…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T14:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c5fae38304136af1e6071ba7ad0ca71dbf049b8",
          "body": "…op live (4949af7)",
          "is_bot": false,
          "headline": "docs(trdd+changelog): X2E6OSWK watchdog shipped — availability backst…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:49:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4949af70645fa82ad48efc78f491cd9fe2428542",
          "body": "…s and respawns a starved server (TRDD-X2E6OSWK)\n\nWHY: twice a drill handler starved the event loop into a permanent wedge\nwhere every request hung and SIGTERM was ignored — machine-wide\nobservability dead until a human SIGKILLed the process hours later.\nPer-handler bounding is the primary defense; \n[…]\n starves its loop:\nSIGKILL observed + detached respawn marker written; healthy-loop and\ngrace-window tests prove the guards. AGENTLENS_WATCHDOG=off /\n_STALL_S envs. Suite 1300/0, tsc 0, lint 0 errors.",
          "is_bot": false,
          "headline": "feat(server): event-loop watchdog + self-heal — worker thread SIGKILL…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:48:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06677ded0b641d61fe71609eb2faf9e5d562b474",
          "body": null,
          "is_bot": false,
          "headline": "docs(trdd): X2E6OSWK append implementation commits 956c006 + 3a8fe7c",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:39:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1bdcb6535ab25b32938a13f943f71447b4de914",
          "body": "…-proven 0→5974\n\nWHY: record the confirmed failure shape (50 synchronous transcript\nreparses inline in one request) and the two shipped fixes with live\nproofs; remaining deliverables (watchdog, per-request logging, sweep of\nsibling drill handlers) keep the card in dev.",
          "is_bot": false,
          "headline": "docs(trdd+changelog): X2E6OSWK culprit named + bounded, pool fix live…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:39:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a8fe7c22deaf0e10dfb150935d7807c70eac0ec",
          "body": "… startTime (TRDD-X2E6OSWK follow-up)\n\nWHY: on a busy fleet the 50 newest-STARTED cards are ephemeral subagent/\nheartbeat sessions with no attribution, so the machine-wide leaderboard\nread 0 attributed calls while the active flagship session (started 6 days\nago, rank #446 by startTime, 1155 attribut\n[…]\nof\nthe window filter itself. Window + ranking now use lastActivityMs (falls\nback to startTime for cards without activity, so prior semantics hold for\nidle corpora). Suite 1297/0, tsc 0, lint 0 errors.",
          "is_bot": false,
          "headline": "fix(server): cost-by-cause pool ranks + windows by last ACTIVITY, not…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:37:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "956c0063824f7fe451a4fa25d92ddde62be92f0d",
          "body": "…er session + 20s time budget (TRDD-X2E6OSWK)\n\nWHY: the leaderboard scan flatMapped up to 50 sessions' timelines inline,\nand after a server restart EVERY disk-restored card is timeline-stripped,\nso each asTimeline call reparsed a whole multi-MB JSONL transcript\nSYNCHRONOUSLY — minutes of unyielding \n[…]\ndEarly + a note\nthat reparsed timelines are cached, so a retry widens coverage). Never\nrejoin this loop into a flatMap. Tests: yield-interleave proof + budget\nstop; suite 1296/0, tsc 0, lint 0 errors.",
          "is_bot": false,
          "headline": "fix(server): bound the get_cost_by_cause cross-session scan — yield p…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:33:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9649ed855520b72d683b861ec913ab72f385ba35",
          "body": "… O(corpus) handler, not the fixed rebuild storm\n\nWHY: the 14:10 'fixed + live-proven' addendum was premature — pid 54681 hit\n104.5% CPU / 3.0GB RSS with every request hanging and SIGTERM ignored.\nNative sample (preserved in reports/cpu-profile/) shows an HTTP-request\nPromise handler running a giant\n[…]\nd. Column back to dev; NEXT ACTION: name the culprit with a\nV8-level profile, then bound per-request work + add an event-loop\nwatchdog/self-heal; Rust reserved for measured hot kernels, not a rewrite.",
          "is_bot": false,
          "headline": "docs(trdd): REOPEN X2E6OSWK — wedge recurred at 3h34m; request-driven…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T13:25:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15af12c8454ed0a96b120973b6cb1a9fc1bd37dc",
          "body": "…rmed, contracts locked both ways\n\nWHY: ai-maestro answered (#70 + reciprocal AgentlensPro#3) — official\ndependency, npm floor >=2.8.0, their installer landed. Phase 2 shipped\n(098b458): 6 more tools contract-locked with corrected field names, R16\ntoken-material confirm answered with code evidence. Only the owner-gated\nv2.8.0 publish remains for end-to-end go-live.",
          "is_bot": false,
          "headline": "docs(trdd): 5F3SE1JM alignment COMPLETE — ai-maestro dependency confi…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T12:41:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "098b458286a3519ff08937787af720f2966496e5",
          "body": "…ted names (AgentlensPro#3)\n\nWHY: ai-maestro shipped AgentlensPro as an official dependency (their\n5d889dc5, floor >=2.8.0) and named 6 more tools its chat-history enrichment\nwill consume — but guessed several field names that do not exist (cost,\ncache_read, billingMode, fiveHour/sevenDay). This sui\n[…]\nns/blocks), so a\nreshape fails CI and routes the author to issue #3 first. Also exports\nhandleGetContextGrowth for contract testability (one-word change +\ncomment). Gate: 1294/0, tsc 0, lint 0 errors.",
          "is_bot": false,
          "headline": "test(contract): lock the ai-maestro consumed CLI fields — with correc…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T12:40:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cfb22aec4c6fc63f21a88ef76fe64602585080a8",
          "body": "WHY: X2E6OSWK's STATE predated its own fix (3b1520a, 07-14: cpu-prof\nrefuted the 4s-tick hypothesis; real causes were the 1s uncached dashboard\nrebuild, the 5s full readdir scan, and the per-append scratch walk —\nmeasured 17.1%→3.0% CPU, regression-pinned by derivedCache.test.ts) —\naddendum records the shipped truth. AMEA4O4Z and OCNHOHE9 STATEs already\nsaid implemented+live-verified; frontmatter caught up (STATE wins).",
          "is_bot": false,
          "headline": "docs(trdd): X2E6OSWK fixed-state addendum + 3 stale columns → ai_review",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T12:11:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d575e76f8572202682bf06dd0628354b756e9a91",
          "body": "…pendency\n\nWHY: user directive 2026-07-16 to align with the ai-maestro Claude and ship\nas a dependency. Phase 1 done: janitor contract locked (d1a3074 + issue #2\nanswered), coordination filed as ai-maestro#70 with the 5 contract-shaping\nquestions. Phase 2 blocked on their answers — each named field joins the\ncontract test.",
          "is_bot": false,
          "headline": "docs(trdd): add TRDD-5F3SE1JM — ship AgentlensPro as an ai-maestro de…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T10:44:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1a3074e17e479bc0f1baf7e9a7c80a3bc3df85d",
          "body": "…lensPro#2)\n\nWHY: the janitor consumes a narrow slice of get_account_status /\nget_burn_status / investigate_burn JSON as fail-open enrichment; a silent\nrename would degrade it with no error on either side. This suite pins the\nexact consumed paths (cacheTtl.minutes; global.costPerHour, activeSessions\n[…]\nareOfWindow,\nconfidence}, attribution[].workspace) via the REAL payload builders, so a\nreshape fails CI here and the assertion message routes the author to post\na heads-up on issue #2 before shipping.",
          "is_bot": false,
          "headline": "test(contract): lock the ai-maestro-janitor CLI field contract (Agent…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T10:41:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9adb29a790e246d16a49ea50039e2cecf00e43f3",
          "body": "… FP class (janitor#99)\n\nWHY: ofetch (unjs), gaxios (Google), color (Qix-), preact (our own dashboard\nframework) are all famous legitimate packages; every flagged lockfile lives\nin the gitignored downloads_dev/ mining corpus, not this project's dependency\ntree. Identical detector failure class alrea\n[…]\naestro-janitor#99 (edit-distance without popularity allowlist +\ngitignored-corpus blindness) — refusals recorded with Approval logs, files\nmoved to design/refused/ per the never-approved lineage rule.",
          "is_bot": false,
          "headline": "docs(trdd): refuse 4 more janitor typosquat proposals — same verified…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T10:35:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb7de183adb5c0320baff1ce3ecbd0f2b80b7b39",
          "body": "…o STATE\n\nWHY: the STATE block has said 'DONE + verified' since 2026-07-11 and the\nMCP-endpoint sibling was closed 2026-07-16 (ccce421), but the column field\nwas never advanced. STATE wins over stale frontmatter — mechanical fix.",
          "is_bot": false,
          "headline": "docs(trdd): F6BM1BDI column dev → ai_review — frontmatter caught up t…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a769b63c1d5c764a6f94f767daa72841a3533d",
          "body": "…, column → ai_review\n\nWHY: the STATE addendum claimed window-capacity auto-calibration (item 2)\nand two backburner children (items 9, 13) were still open. Re-verification\nagainst the live tool surface + git shows all three ALREADY SHIPPED:\n- item 2: BURNWDGT P5 (8b9da82) — live-fired 2026-07-13, ge\n[…]\nsolved by decision (KVDT1XMS WSL2-only gate — native win32\nis a declared non-goal), so no fixes child is needed. Every coverage row\nis now covered/shipped/resolved; the umbrella advances to ai_review.",
          "is_bot": false,
          "headline": "docs(trdd): O981ZJKV fully dispositioned — stale open-items corrected…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:52:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8c04d31980bca3f143efb76559d248347b83549",
          "body": "…feed restored (TRDD-5GFSFX0Q)\n\nLive-proven: get_cost_by_cause 0 → 957 attributed calls; suite 1285/0.",
          "is_bot": false,
          "headline": "Merge branch 'fix/by-cause-attribution-feed' — per-cause attribution …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bc2c4b2a4d38689d8271932d05d15c630d6da70",
          "body": "…card (TRDD-5GFSFX0Q)\n\nWhy: the Phase B log-wins merge (token-feed fix, TRDD-O981ZJKV) dropped\nthe colliding OTEL card WHOLESALE. Correct for token totals (OTEL is a\nmeasured lossy lower bound) — but the OTEL card's api_request timeline\nentries are the ONLY per-call attribution ground truth (exact c\n[…]\nine\ncarries BOTH transcript entries and the attributed api_request). Suite\n1285/0. Live proof: get_cost_by_cause on the fixing session 0 → 957\nattributed calls with real per-skill/per-agent cost rows.",
          "is_bot": false,
          "headline": "fix(attribution): graft OTEL api_request entries onto the served log …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:43:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "702bb4a772605126b9a9b860155c4a870c8ec3c9",
          "body": "…tup probe, recent-sessions ranking, hardening)\n\n60 commits, reviewed (ai_review sweep: externalizer ensemble + manual\nverification of every candidate, 4 real defects fixed), 1280/1280 tests,\ndeployed + live-verified. History preserved per convention: --no-ff,\nnever squash.",
          "is_bot": false,
          "headline": "Merge branch 'feat/cache-expiry-probe' — 2.8.0 (transcript reader, se…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:27:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a34a408db593ba4dec515ac16ade43f2c948513",
          "body": "…ssions ranking, provenance + MCP hardening\n\nWhy: closes the reviewed 59-commit branch as one releasable unit\n(get_conversation + dashboard Transcript tab, card title/entrypoint,\nsetup environment probe with the WSL2-only Windows gate, last-activity\nrecent-sessions ranking, release provenance + MCP \n[…]\nd: externalizer ensemble sweep + manual verification, 1280 tests\ngreen, live-verified. Tag v2.8.0 is NOT created here — tagging/pushing\ntriggers the npm+docker publish and waits for explicit approval.",
          "is_bot": false,
          "headline": "chore(release): 2.8.0 — transcript reader, setup env probe, recent-se…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:27:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccce4213a21dc9bdcdf9a45d078c853825fc6dd2",
          "body": "…ening, scan-gate inode check (TRDD-F6BM1BDI sibling)\n\nBranch ai_review sweep (externalizer ensemble + manual verification of\nevery candidate). Real defects fixed:\n\n1. MCP endpoint (src/mcpServer.ts):\n   - body buffering was UNCAPPED (raw += chunk) — the one POST body on\n     the machine without a c\n[…]\ne\nre-parse + negative control), +5 MCP cases in the real-boot CORS suite.\nGate: tsc 0 errors, lint 0 errors, check-mirrors OK, 1280 passing /\n0 failing. Deployed: esbuild + server restart (pid 85128).",
          "is_bot": false,
          "headline": "sec(mcp)+fix(logReader): review-sweep remediation — MCP endpoint hard…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:20:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a085fc94dd6aec2297154b81d5463fd35485e5c",
          "body": "… (janitor#99)\n\nWhy: USER delegated the disposition ('evaluate the proposals of the\njanitor yourself and decide wisely. you have my trust. but coordinate\nwith it via github issues.'). Each claim was verified on disk before\ndeciding:\n- MAFCVI5T: id-token: write is already job-scoped; workflow-level i\n[…]\nd upstream as\nhttps://github.com/Emasoft/ai-maestro-janitor/issues/99 (4 FP classes\n+ repo-trust-score corollary). Never-approved proposals land in\ndesign/refused/ per the approval-tiers lineage rule.",
          "is_bot": false,
          "headline": "docs(trdd): refuse all 6 janitor proposals — verified false positives…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T09:01:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b5be740b29a2c2d0c46bbaa97de16768fae2dc0",
          "body": "…up probe\n\nWhy: the fix-all work order (TRDD-OMMPS5TF, TRDD-KVDT1XMS) produced\nnon-derivable operational knowledge that must outlive this session:\n- publish-pipeline page: SBOM+SHA256SUMS release assets, workflow\n  hardening laws (SHA-pin all, persist-credentials:false, no dep cache\n  in release pat\n[…]\nent probe (WSL-only\n  Windows gate, engines.node floor, duckdb FAIL vs sql.js warn) and the\n  plain-require.resolve lesson (runtime deps are the installed\n  package's own, not an injected repoRoot's).",
          "is_bot": false,
          "headline": "docs(memory): capture work-order lessons — provenance hardening + set…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T05:05:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15ac7d05482581f319a6b6629b16ed0974ba4b5a",
          "body": "…files\n\nThe janitor dirty-tree detector fired for an hour on 4 untracked\nartifacts (.tldr/ index caches at two levels, the tldr local config,\na stale vim .swp) — all machine-local and regenerable, none commit-able.\nIgnoring them makes the detector meaningful again: a dirty tree now\nmeans real uncommitted work.",
          "is_bot": false,
          "headline": "chore(gitignore): ignore tldr index caches, .tldrignore, editor swap …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T02:07:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c39be3a7010032c2f8d7726fdc3208fa2c70b21",
          "body": "…OT approvals)\n\nThe janitor wrote its security-proposal TRDDs (WFSEC-003, AICTX-001,\n4x DEP-003 typosquat lookalikes) into design/proposals/ awaiting the\nuser's decision; design/ must be git-tracked per the TRDD rules, and\ntracking the queue is what makes the proposals auditable. Disposition\nstays with the USER via /janitor-support-open-ticket.",
          "is_bot": false,
          "headline": "docs(trdd): track the janitor's 6 proposal tickets (queue records — N…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:38:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b67605a4e789b3b4c938dcf92cc2ddff6639edd6",
          "body": "…gated, live-verified)",
          "is_bot": false,
          "headline": "docs(trdd): OMMPS5TF + RS3NGN53 + KVDT1XMS → ai_review (implemented, …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:37:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f829d475593ae705ba716e7c900ef7f404dda36",
          "body": "…e/entrypoint rows (TRDD-KVDT1XMS, TRDD-RS3NGN53)\n\nUSAGE and the agentlenspro-diagnostics skill now document the setup\nenvironment probe and the platform support matrix (macOS + Linux;\nWindows via WSL2 only); README gains the platform line + probe summary.\nget_recent_sessions rows also carry the car\n[…]\nint (the\nskill's cheat-sheet claims it, so the handler must serve it — never\ndocument what is not implemented), covered by a passthrough test.\nCHANGELOG entries for all three TRDDs of this work order.",
          "is_bot": false,
          "headline": "docs(cli+skill): setup probe + platform matrix + recent-sessions titl…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:37:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cbb484ecaf3e91c02bd922a78a12df014ea15cf8",
          "body": "…ndows-is-WSL-only gate (TRDD-KVDT1XMS)\n\nNew read-only FIRST step in the setup pipeline: gathers real facts\n(platform/arch, WSL marker via the ONE /proc/version reader in\nenvironment/runtime, Node version vs the package.json engines floor,\nruntime-dep resolvability, foreign-process-on-OTLP-port heur\n[…]\n Dep resolution uses plain\nrequire.resolve (the installed package's own context) — resolving from\nthe injectable repoRoot made the bogus-root fixture fail here instead\nof at the skill step it targets.",
          "is_bot": false,
          "headline": "feat(setup): environment probe — heuristic incompatibility checks, Wi…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:32:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "158496a45dc7dc6712addee5de916402cba8f0c4",
          "body": "…tive flag (TRDD-RS3NGN53)\n\n'Recent' meant recently STARTED, so a long-running session emitting spans\nNOW ranked below fresh idle sessions and fell off the top-10 entirely\n(live-confirmed: 4 actively-emitting sessions absent from the default\nlisting — the tool was blind to exactly the sessions the u\n[…]\n\nthis is the one place the ordering semantics matter), add lastActive to\nevery row, and active:true (absent when idle, never false) within a\n5-minute window bounded by the OTEL span heartbeat cadence.",
          "is_bot": false,
          "headline": "fix(diagnostics): get_recent_sessions ranks by last activity, adds ac…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:27:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cc75745bc14b8c8dab584ec5d57b776de5b28fc",
          "body": "…PS5TF)\n\nAdds what the janitor provenance-audit found missing: SHA256SUMS.txt +\nSPDX SBOM (anchore/sbom-action, SHA-pinned) attached to every GitHub\nRelease, and provenance mode=max + sbom:true on the docker image so the\nmanifest carries both attestations. Also closes the zizmor findings: ALL\nfirst-\n[…]\nwas a false positive —\nalready job-scoped, documented in the TRDD. zizmor: 0 high/med/low;\nactionlint clean. The OIDC auth surface is untouched (no registry-url,\nno token, filename stays publish.yml).",
          "is_bot": false,
          "headline": "sec(workflows): release provenance + supply-chain hardening (TRDD-OMM…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:25:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c637050961b1938baebac6ec560bc6108e0f4e65",
          "body": "…order (provenance, recent-sessions ranking, setup env probe)",
          "is_bot": false,
          "headline": "docs: add TRDD-OMMPS5TF, TRDD-RS3NGN53, TRDD-KVDT1XMS — fix-all work …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T01:19:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea2f0bd3eec4b9b658f98dd5315978de5d0b84df",
          "body": "…e (TRDD-B22NYTOY P4)\n\nCard enrichment: the Claude log parser harvests the transcript's ai-title\nrecords (latest wins — CC regenerates the title as the session evolves) and\nthe top-level entrypoint field (first wins — constant within a session) into\nSessionSummaryCard.title/.entrypoint; the Sessions\n[…]\n a fresh renderer task and does (response in 504ms).\n\nSuite 1259 green including the browser tests; live-verified: this session's\ncard serves title 'conversation-transcript-viewer' + entrypoint 'cli'.",
          "is_bot": false,
          "headline": "feat(cards): ai-title/entrypoint enrichment + Transcript browser smok…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:59:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27fb100d0871d8b4ddefe1379eb43458c8e0d0c5",
          "body": null,
          "is_bot": false,
          "headline": "docs(trdd): B22NYTOY — P3 done (Transcript sub-tab live), STATE → P4",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:29:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31ab64fe041a989135e65b6106d7b4fd5599cf06",
          "body": "…B22NYTOY P3)\n\nNew TranscriptView renders the Conversation payload as a readable narrative: role-colored turns\n(user amber / assistant blue / subagent violet / system dim), verbatim user+assistant text open by\ndefault, thinking/tool-in/tool-out/attachments collapsed to one-line summaries that expand\n[…]\n shim, because the standalone\nserver is the only runtime since the extension host was removed (2 fewer wiring files than\nplanned). Types + mirrors + esbuild green; endpoint live-verified (3132 turns).",
          "is_bot": false,
          "headline": "feat(dashboard): Transcript sub-tab — chat-reader session view (TRDD-…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:28:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6aa5b11fc6f2b36042d875ea40913de5112f08de",
          "body": "… /api/conversation (TRDD-B22NYTOY P2)\n\nMCP tool with the progressive drill-down contract (same bounding strategy as get_context_history —\nthe no-arg shape ships per-turn SUMMARIES with previews and tool lists, full verbatim text only for\n--turn N or a range hard-capped at 20 turns; leanify still ca\n[…]\nrd,\nsame nearest-logged-ancestor fallback as /api/history) so P3's dashboard view shares the ONE builder.\n\nLive-verified on this session: 3119 turns, 5 compactions, verbatim first prompt over the CLI.",
          "is_bot": false,
          "headline": "feat(diagnostics): get_conversation — narrative session reader tool +…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:25:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4d7bfa60a2683bfa383461bb60dde18c5909dd8",
          "body": "…OY P1)\n\nbuildConversationFromFile/buildConversation reconstruct a session as a readable conversation from\nits .jsonl: VERBATIM ordered blocks (user prompt -> assistant thinking -> text -> tool calls with\noutputs paired by tool_use_id), assistant streaming chunks merged by message.id, resume-duplica\n[…]\nsubtle logic is how the two OTLP paths drifted before.\n\nSuite 1251 green (+15 fixture tests). Real-world: 15,304-line live transcript parsed in 190ms,\n3092 turns, both compactions exact, 0 truncation.",
          "is_bot": false,
          "headline": "feat(conversation): narrative per-turn transcript parser (TRDD-B22NYT…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:20:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2bf7d138c3e7b159551347b4cc70065b3177c2e2",
          "body": "…-turn session reader)",
          "is_bot": false,
          "headline": "docs: add TRDD-B22NYTOY — conversation transcript view (narrative per…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-16T00:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b279ac7ce212b2740035b3d76f013a69e3ae483",
          "body": "… drop (TRDD-AMEA4O4Z)\n\nThe rich-event gate converted only api_request/compaction/api_error/api_retries_exhausted +\ntool_result into spans and DISCARDED everything else after counting it — user_prompt,\nassistant_response, tool_decision, hook_execution_*, mcp_server_connection, plugin_loaded,\nhook_re\n[…]\ned once before.\nSink failures warn once per boot per message and never reject the OTLP payload (that would lose\nthe spans too). Suite 1236 green; live-verified: 9 events captured within 20s of deploy.",
          "is_bot": false,
          "headline": "feat(otlp): log-event sink — persist gated-out OTEL log events, never…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T22:36:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8ba8bb553288d1768f95a82ce3a26741791b30f",
          "body": "…events",
          "is_bot": false,
          "headline": "docs: add TRDD-AMEA4O4Z — log-event sink, persist gated-out OTEL log …",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T22:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efd6667329962b0da64e73992002563d54a0cf27",
          "body": "…8355/78355 proven, 0 lost)",
          "is_bot": false,
          "headline": "docs(trdd): K3WDPR7M — wad verify+reclaim DONE (15.78 GB reclaimed, 7…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T19:52:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92d5321b6137b89c083a427c7e113033ca716c82",
          "body": "… proxy, cost-first fill\n\n/code-review high --fix on the session's new diagnostic modules. The code\nis TDD-covered (1228 tests, incl. adversarial), so findings were cleanup +\ntwo consistency fixes, no correctness bugs:\n\n- reuse: weighted() and fmtTok() were byte-identical in accountBurners.ts\n  and \n[…]\nt (token fallback only when no cost cap), so\n  the two tools' 'how full is the window' agree. Live: 5h now 36%% (cost)\n  vs the old 85%% (tokens).\n\n1228 tests green, deployed pid 33963, live-verified.",
          "is_bot": false,
          "headline": "refactor(diagnostics): code-review fixes — DRY helpers, deterministic…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T16:57:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb316688642a5be9d80b14870e02d58a70925090",
          "body": "…nt_burners --interval (TRDD-8ZMZ4I6B, TRDD-1XM0YSWQ)\n\nget_window_eta projects time-to-exhaustion on COST, not tokens (Anthropic\nmeters the windows by cost; cache-read weighted ~0.1x). Rate is the\naccount's own $/min (per-account limits), capacity is its observed\ncalibration else a same-plan proxy e\n[…]\nins --interval last|current|<ISO-date> (replaces\nuntil_iso; no legacy). Extracted eventsForAccountInWindow as the ONE shared\naccount-attribution rule so the ETA and the burners tables cannot disagree.",
          "is_bot": false,
          "headline": "feat(diagnostics): get_window_eta (cost-based window ETA) + get_accou…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T11:30:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2a00c2e2146a2431408559e1617a66c048f3231",
          "body": "…t rollup, exhausted-window marker (TRDD-1XM0YSWQ)\n\nUSER follow-up: group by project/agent ACROSS sessions (a restarted agent\nis still one culprit) with explicit cache-created and cache-read columns,\nshow both windows as two tables, and mark which one forced the rotation.\nThe exhaustion marker compa\n[…]\nemoved — the 5h/7d pair IS the question; one version of\nthe interface only.\n\nLive: fmuaddib's 5h window at 85%% vs 7d at 53%% of the Max-20x proxy\ncapacity at rotation — the 5h window was the trigger.",
          "is_bot": false,
          "headline": "feat(diagnostics): get_account_burners v2 — dual 5h+7d tables, projec…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T09:29:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4358450b22a43db2160c679ead4b4ddd8b63ac68",
          "body": "…indow (TRDD-1XM0YSWQ)\n\nAfter a forced account rotation the user needs the culprits of the\nEXHAUSTED account's window — investigate_burn has no account filter and\nget_window_budget no per-session ranking. Attribution is TIME-based\nagainst the account-state timeline (one keychain token active machine\n[…]\nas lower bounds, never papered over.\n\nLive-verified: previous account fmuaddib's final 5h window = 76.1M equiv /\n$507 over 11 sessions, top-3 58% (ai-maestro 25%, ANIME2SVG 19%,\nllm-externalizer 14%).",
          "is_bot": false,
          "headline": "feat(diagnostics): get_account_burners — who exhausted an account's w…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T08:56:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f039230fe43e2a660db4b82a8074abfbb557b0a6",
          "body": "…W17E)\n\nWires the bodyWriters module into the server: new MCP tool (auto-exposed\nas 'agentlenspro get_body_writers' via the live-schema CLI), a lazy\ngetStore accessor on McpServerOptions (same open the ingest pass uses, so\nthe first call pays the open, not every call), and docs. Store failures\ndegra\n[…]\no live-dir-only inside the handler because the question 'which\nsessions must I restart' must stay answerable even mid-migration.\n\nLive-verified post-deploy: 45 writers, 6 active, ranked table correct.",
          "is_bot": false,
          "headline": "feat(diagnostics): get_body_writers MCP tool + CLI command (TRDD-1FEI…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T08:37:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0c74f9fe9e57659e398f9036ac72d2be0b04817",
          "body": "…ter sessions (TRDD-1FEIW17E)\n\nUSER asked which Claude sessions are still writing raw OTEL bodies, ranked\nby rate and total. Attribution unit is the REQUEST body (tail metadata\ncarries session_id via the existing bounded 6KB read); responses carry no\nsession metadata and are aggregated, never guesse\n[…]\ne whose\nsrc_name is already a store row is not re-added — total is the exact union.\nStore-absent degrades to live-only with an explicit note (the tool must\nanswer even while the server store is down).",
          "is_bot": false,
          "headline": "feat(diagnostics): bodyWriters module — attribute + rank raw-body wri…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T08:32:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1be75ab4c0f7b7c4535f1e83e5366195b0fdecac",
          "body": "…g), server live on v2\n\nAttempt 3 succeeded: 78,354 ts corrections + 323 alias rows, full VERIFY\n(208 min) found 100,600 bodies + 328,606 spans with 0 lost, atomic swap\nlanded (manifest schemaVersion 2, migratedFrom 0). Post-migration probe:\n78,354/78,354 idx-joinable rows ts-correct, 0 wrong. Serve\n[…]\np-dir name: the migration keeps the old store\nat .old-v<from>, and since schema 0 IS the v1 layout the actual dir here is\nstore.old-v0 — the docs said .old-v1, which a reader would never find on\ndisk.",
          "is_bot": false,
          "headline": "docs(trdd): K3WDPR7M — schema-v2 migration DONE (0 lost, probe 0 wron…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T08:11:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eaf0b534e5371292b598c89e09dffaaafe059b14",
          "body": "…ble chokepoint\n\nA server booted 3 minutes AFTER 'agentlenspro disable' (2026-07-15 06:28, flag\narmed 06:25): setup.ts's spawn carried no guard at all, and guarding N CLI call\nsites structurally misses the N+1th. The one path every spawner must pass\nthrough is the server process's own boot, so the D\n[…]\ninto unreleased 2.7.0.\n\nWhy it was urgent: a live writer during the store migration's atomic swap\nwould strand fresh bodies in the renamed old dir — real data loss, not a race\ncuriosity. TRDD-K3WDPR7M",
          "is_bot": false,
          "headline": "fix: enforce the kill-switch at the server's own boot — the unbypassa…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T04:38:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "223ad27aaa000a03bdbcd09b6982a4846f103c1f",
          "body": "…gration\n\nThe first real migration run aborted at the appender: BigInt(1783577015814.2808)\nthrows, because statSync mtimeMs keeps a sub-ms fraction and the .idx preserves\nit — while the test fixtures used tidy integers, which is exactly why the tests\nnever caught it. Rounded at the ONE entry point (\n[…]\n 4-hour run;\nfixtures now carry real-shaped float mtimes. Sub-ms is far inside the ±2s\nverification tolerance. Migration failed SAFE as designed: live store\nuntouched, staging discarded. TRDD-K3WDPR7M",
          "is_bot": false,
          "headline": "fix(store): round float .idx mtimes — the real archive aborted the mi…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T04:30:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e64e77dbae5fa76f28af010231076f3f71801e6",
          "body": "USER directive 2026-07-15: 'the verification step must be done everytime the\nsource is gonna be deleted after. even for OTEL logs, statusline logs, hooks\nlogs, etc.' — one invariant, five sites, no site left on trust:\n\n- archiveVerify.ts: per-lump proof of a whole .wad volume (bytes reconstruct +\n  \n[…]\nrrupt snapshot write now aborts with old\n  snapshot AND delta intact.\n\nGates: check-types clean, full suite 1184 passing (13 new adversarial tests\nacross hookSpoolVerify/deltaLogVerify/archiveVerify).",
          "is_bot": false,
          "headline": "feat: verify-before-delete on EVERY source-deletion site (TRDD-K3WDPR7M)",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T04:24:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b452504d5ca6809434e53c228354b47d2bacce8c",
          "body": "…very run plan",
          "is_bot": false,
          "headline": "docs(trdd): K3WDPR7M — USER verify-before-delete directives + ts-reco…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T04:14:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddd633bbd5c2dfe6fa6163e9280554045d1ee3a3",
          "body": "…ion v1->v2\n\nUSER directive 2026-07-15: a source file may be deleted ONLY after verifying\nALL its data — bytes AND capture metadata — is durably in the store. Rationale\nfrom this corpus's own history: the backfill+drain held every byte perfectly\n(hash-proven twice) while stamping 100,600 rows with i\n[…]\nions; schema-0 legally chains through v1.\n\nProbe evidence: 78,031/78,031 idx-joinable rows wrong (drain ran on stale\ncompiled out/ — third instance of 'landed in source, not deployed').\n\nTRDD-K3WDPR7M",
          "is_bot": false,
          "headline": "feat(store): universal verify-before-delete gate + ts-recovery migrat…",
          "author_name": "Emasoft",
          "author_login": "Emasoft",
          "committed_at": "2026-07-15T04:07:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 16,
      "commits_last_year": 897,
      "latest_release_at": "2026-07-17T13:32:37Z",
      "latest_release_tag": "v2.10.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "agentlenspro",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "ai",
            "agent",
            "opentelemetry",
            "telemetry",
            "observability",
            "copilot",
            "claude",
            "tracing"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/agentlenspro",
          "is_deprecated": false,
          "latest_version": "2.10.1",
          "repository_url": "https://github.com/Emasoft/AgentlensPro",
          "versions_count": 16,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2631,
          "first_published_at": "2026-07-11T01:47:55.356000Z",
          "latest_published_at": "2026-07-17T13:33:12.247000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "media/tsconfig.json",
        "standalone/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 225891,
      "source_files_sampled": 320,
      "oversized_source_files": 6,
      "agent_instruction_files": [
        "CLAUDE.md",
        "walkthrough/agents.md"
      ],
      "agent_instruction_max_bytes": 13162
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.14",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.0",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-4c8g-83qw-93j6",
              "GHSA-v2hh-gcrm-f6hx"
            ],
            "fixed_version": "4.1.1",
            "advisory_count": 2,
            "oldest_advisory_days": 0
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "diff",
            "direct": false,
            "version": "7.0.0",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-73rr-hh4g-fpgx"
            ],
            "fixed_version": "8.0.3",
            "advisory_count": 1,
            "oldest_advisory_days": 188
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.2.2",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 3.7,
            "advisory_ids": [
              "GHSA-v422-hmwv-36x6"
            ],
            "fixed_version": "2.3.0",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 4,
          "moderate": 2
        },
        "advisory_count": 8,
        "affected_count": 7,
        "assessed_count": 419,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@duckdb/node-api",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.5.4-r.1"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@preact/signals",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "clsx",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "fflate",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.8.3"
        },
        {
          "name": "preact",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.29.1"
        },
        {
          "name": "sql.js",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.14.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@duckdb/node-api",
            "direct": true,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@preact/signals",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "clsx",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "fflate",
            "direct": true,
            "version": "0.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "preact",
            "direct": true,
            "version": "10.29.1",
            "ecosystem": "npm"
          },
          {
            "name": "sql.js",
            "direct": true,
            "version": "1.14.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-darwin-arm64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-darwin-x64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-linux-arm64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-linux-arm64-musl",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-linux-x64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-linux-x64-musl",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-win32-arm64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-bindings-win32-x64",
            "direct": false,
            "version": "1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.21.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "2.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@preact/signals-core",
            "direct": false,
            "version": "1.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "@puppeteer/browsers",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/mocha",
            "direct": false,
            "version": "10.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "22.19.18",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-buffer-byte-length",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "arraybuffer.prototype.slice",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "async-function",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "available-typed-arrays",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.14",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "browser-stdout",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "chromium-bidi",
            "direct": false,
            "version": "16.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "1.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": false,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "6.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-buffer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-length",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-offset",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decamelize",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-data-property",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-properties",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "devtools-protocol",
            "direct": false,
            "version": "0.0.1638949",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "es-abstract",
            "direct": false,
            "version": "1.24.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-to-primitive",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "8.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "for-each",
            "direct": false,
            "version": "0.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "function.prototype.name",
            "direct": false,
            "version": "1.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "functions-have-names",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "generator-function",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-symbol-description",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "globalthis",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-bigints",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-property-descriptors",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-proto",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "he",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.27",
            "ecosystem": "npm"
          },
          {
            "name": "hosted-git-info",
            "direct": false,
            "version": "2.8.9",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "internal-slot",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-array-buffer",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-async-function",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-bigint",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-boolean-object",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-callable",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-core-module",
            "direct": false,
            "version": "2.16.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-data-view",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-date-object",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-finalizationregistry",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-function",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-map",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-negative-zero",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-number-object",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-regex",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-set",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-shared-array-buffer",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-string",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-symbol",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-typed-array",
            "direct": false,
            "version": "1.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakmap",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakref",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakset",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "isarray",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-better-errors",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "load-json-file",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "log-symbols",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "memorystream",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mitt",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "mocha",
            "direct": false,
            "version": "11.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "modern-tar",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nice-try",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-package-data",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-all",
            "direct": false,
            "version": "4.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "object-keys",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.assign",
            "direct": false,
            "version": "4.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "own-keys",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-parse",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pidtree",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pify",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "playwright",
            "direct": false,
            "version": "1.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "playwright-core",
            "direct": false,
            "version": "1.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "possible-typed-array-names",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "puppeteer-core",
            "direct": false,
            "version": "25.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "read-pkg",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "reflect.getprototypeof",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "regexp.prototype.flags",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "1.22.12",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-array-concat",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "safe-push-apply",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex-test",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "5.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serialize-javascript",
            "direct": false,
            "version": "7.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-length",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-name",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-proto",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shell-quote",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "spdx-correct",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "spdx-exceptions",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "spdx-expression-parse",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "spdx-license-ids",
            "direct": false,
            "version": "3.0.23",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "stop-iteration-iterator",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.padend",
            "direct": false,
            "version": "3.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trim",
            "direct": false,
            "version": "1.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimend",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimstart",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "5.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-preserve-symlinks-flag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-buffer",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-length",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-offset",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-length",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "typed-query-selector",
            "direct": false,
            "version": "2.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.59.2",
            "ecosystem": "npm"
          },
          {
            "name": "unbox-primitive",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "6.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "validate-npm-package-license",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "webdriver-bidi-protocol",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-boxed-primitive",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "which-builtin-type",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "which-collection",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-typed-array",
            "direct": false,
            "version": "1.1.20",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "workerpool",
            "direct": false,
            "version": "9.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "18.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-unparser",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "3.25.76",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": false,
            "version": "3.25.2",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 419,
        "direct_count": 7,
        "indirect_count": 412
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 4,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Emasoft",
          "commits": 530,
          "avatar_url": "https://avatars.githubusercontent.com/u/713559?v=4"
        },
        {
          "type": "User",
          "login": "RogerReed",
          "commits": 367,
          "avatar_url": "https://avatars.githubusercontent.com/u/437230?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.591
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "docker.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 4,
            "reason": "6 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ae5022e8615cf82990521a5382131f8070bf8546",
        "ran_at": "2026-07-22T15:32:30Z",
        "aggregate_score": 3.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T05:16:34Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 2,
          "created_at": "2026-07-16T09:19:09Z",
          "last_comment_at": "2026-07-16T10:42:12Z",
          "last_comment_author": "Emasoft"
        },
        {
          "number": 3,
          "created_at": "2026-07-16T12:18:48Z",
          "last_comment_at": "2026-07-17T04:46:04Z",
          "last_comment_author": "Emasoft"
        },
        {
          "number": 4,
          "created_at": "2026-07-17T04:51:21Z",
          "last_comment_at": "2026-07-17T07:30:47Z",
          "last_comment_author": "Emasoft"
        },
        {
          "number": 5,
          "created_at": "2026-07-18T07:14:39Z",
          "last_comment_at": "2026-07-21T19:36:09Z",
          "last_comment_author": "Emasoft"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Emasoft/AgentlensPro",
    "host": "github.com",
    "name": "AgentlensPro",
    "owner": "Emasoft"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 47,
        "vitality": 72,
        "community": 44,
        "governance": 43,
        "engineering": 64
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 897,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "897 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 897
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 16,
              "latest_release_tag": "v2.10.1",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "16 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "agentlenspro"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2631
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,631 downloads/month across npm",
                "points": 45.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2631,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 21,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.591
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 59% of commits",
                "points": 9.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 59
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 4,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/1 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "followers": 168,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Emasoft",
              "public_repos": 88,
              "account_age_days": 5585
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "168 followers of Emasoft",
                "points": 16,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 168,
                      "login": "Emasoft"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "88 public repos, account ~15 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 88
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "agentlenspro"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 64,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 34,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "6 existing vulnerabilities detected",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 419 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 419
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 8,
              "affected_packages": 7,
              "assessed_packages": 419,
              "unassessed_packages": 0,
              "affected_by_severity": "high 4, moderate 2, low 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 419,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md",
                "walkthrough/agents.md"
              ],
              "agent_instruction_max_bytes": 13162
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md, walkthrough/agents.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md, walkthrough/agents.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "media/tsconfig.json",
                "standalone/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "media/tsconfig.json, standalone/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "media/tsconfig.json, standalone/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 225891,
              "source_files_sampled": 320,
              "oversized_source_files": 6
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "6/320 source files over 60KB",
                "points": 54,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 320,
                      "oversized": 6
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index npm:agentlenspro@2.10.1; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T15:32:38.111574Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/Emasoft/AgentlensPro.svg",
  "full_name": "Emasoft/AgentlensPro",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.