原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"cloud",
"filen",
"sync"
],
"is_fork": false,
"size_kb": 1796,
"has_wiki": true,
"homepage": "https://filen.io",
"languages": {
"JavaScript": 892,
"TypeScript": 1765589
},
"pushed_at": "2026-07-19T11:55:40Z",
"created_at": "2024-05-29T17:07:54Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T03:01:47Z",
"description": "Filen sync engine",
"is_archived": false,
"is_disabled": false,
"license_spdx": "AGPL-3.0",
"default_branch": "main",
"license_spdx_raw": "AGPL-3.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://filen.io",
"name": "Filen Cloud Dienste",
"type": "Organization",
"login": "FilenCloudDienste",
"company": null,
"location": "Germany",
"followers": 826,
"avatar_url": "https://avatars.githubusercontent.com/u/88734086?v=4",
"created_at": "2021-08-10T16:45:38Z",
"is_verified": null,
"public_repos": 26,
"account_age_days": 1809
},
"license": {
"state": "standard",
"spdx_id": "AGPL-3.0",
"raw_spdx": "AGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.3.7",
"kind": "patch",
"published_at": "2026-07-19T11:55:40Z"
},
{
"tag": "v0.3.6",
"kind": "patch",
"published_at": "2026-07-17T18:35:48Z"
},
{
"tag": "v0.3.5",
"kind": "patch",
"published_at": "2026-07-15T10:02:03Z"
},
{
"tag": "v0.3.4",
"kind": "patch",
"published_at": "2026-06-29T20:27:01Z"
},
{
"tag": "v0.3.3",
"kind": "patch",
"published_at": "2026-06-29T20:21:09Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-06-28T17:16:01Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-06-28T12:35:28Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2025-07-06T12:54:50Z"
},
{
"tag": "v0.1.102",
"kind": "patch",
"published_at": "2025-03-21T12:51:29Z"
},
{
"tag": "v0.1.101",
"kind": "patch",
"published_at": "2025-02-09T15:52:19Z"
},
{
"tag": "v0.1.100",
"kind": "patch",
"published_at": "2025-02-09T15:34:47Z"
},
{
"tag": "v0.1.99",
"kind": "patch",
"published_at": "2025-02-04T16:32:39Z"
},
{
"tag": "v0.1.98",
"kind": "patch",
"published_at": "2025-02-04T08:26:18Z"
},
{
"tag": "v0.1.97",
"kind": "patch",
"published_at": "2025-01-17T11:30:36Z"
},
{
"tag": "v0.1.96",
"kind": "patch",
"published_at": "2024-12-22T23:59:41Z"
},
{
"tag": "v0.1.95",
"kind": "patch",
"published_at": "2024-12-13T03:24:41Z"
},
{
"tag": "v0.1.94",
"kind": "patch",
"published_at": "2024-12-11T00:02:32Z"
},
{
"tag": "v0.1.93",
"kind": "patch",
"published_at": "2024-12-09T23:58:46Z"
},
{
"tag": "v0.1.92",
"kind": "patch",
"published_at": "2024-12-09T19:24:48Z"
},
{
"tag": "v0.1.91",
"kind": "patch",
"published_at": "2024-11-30T23:17:28Z"
},
{
"tag": "v0.1.90",
"kind": "patch",
"published_at": "2024-11-29T20:13:30Z"
},
{
"tag": "v0.1.89",
"kind": "patch",
"published_at": "2024-11-29T10:23:50Z"
},
{
"tag": "v0.1.88",
"kind": "patch",
"published_at": "2024-11-29T10:21:53Z"
},
{
"tag": "v0.1.87",
"kind": "patch",
"published_at": "2024-11-28T20:39:51Z"
},
{
"tag": "v0.1.86",
"kind": "patch",
"published_at": "2024-11-28T19:17:54Z"
},
{
"tag": "v0.1.85",
"kind": "patch",
"published_at": "2024-11-28T19:09:49Z"
},
{
"tag": "v0.1.84",
"kind": "patch",
"published_at": "2024-11-23T03:20:35Z"
},
{
"tag": "v0.1.83",
"kind": "patch",
"published_at": "2024-11-23T02:51:11Z"
},
{
"tag": "v0.1.82",
"kind": "patch",
"published_at": "2024-11-22T06:23:14Z"
},
{
"tag": "v0.1.81",
"kind": "patch",
"published_at": "2024-11-20T01:38:20Z"
},
{
"tag": "v0.1.80",
"kind": "patch",
"published_at": "2024-11-16T21:12:12Z"
},
{
"tag": "v0.1.79",
"kind": "patch",
"published_at": "2024-11-12T19:10:39Z"
},
{
"tag": "v0.1.78",
"kind": "patch",
"published_at": "2024-11-12T19:03:02Z"
},
{
"tag": "v0.1.77",
"kind": "patch",
"published_at": "2024-11-12T01:02:05Z"
},
{
"tag": "v0.1.76",
"kind": "patch",
"published_at": "2024-11-07T17:58:11Z"
},
{
"tag": "v0.1.75",
"kind": "patch",
"published_at": "2024-11-05T13:10:27Z"
},
{
"tag": "v0.1.74",
"kind": "patch",
"published_at": "2024-10-15T00:34:08Z"
},
{
"tag": "v0.1.73",
"kind": "patch",
"published_at": "2024-09-23T03:51:17Z"
},
{
"tag": "v0.1.72",
"kind": "patch",
"published_at": "2024-09-22T01:19:02Z"
},
{
"tag": "v0.1.71",
"kind": "patch",
"published_at": "2024-09-21T11:41:37Z"
},
{
"tag": "v0.1.70",
"kind": "patch",
"published_at": "2024-09-21T01:43:36Z"
},
{
"tag": "v0.1.69",
"kind": "patch",
"published_at": "2024-09-21T01:40:29Z"
},
{
"tag": "v0.1.68",
"kind": "patch",
"published_at": "2024-09-21T00:58:15Z"
},
{
"tag": "v0.1.67",
"kind": "patch",
"published_at": "2024-09-20T17:35:29Z"
},
{
"tag": "v0.1.66",
"kind": "patch",
"published_at": "2024-09-19T22:18:21Z"
},
{
"tag": "v0.1.65",
"kind": "patch",
"published_at": "2024-09-19T04:02:53Z"
},
{
"tag": "v0.1.64",
"kind": "patch",
"published_at": "2024-09-19T03:18:38Z"
},
{
"tag": "v0.1.63",
"kind": "patch",
"published_at": "2024-09-19T03:13:37Z"
},
{
"tag": "v0.1.62",
"kind": "patch",
"published_at": "2024-09-14T01:00:26Z"
},
{
"tag": "v0.1.61",
"kind": "patch",
"published_at": "2024-09-12T20:30:09Z"
},
{
"tag": "v0.1.60",
"kind": "patch",
"published_at": "2024-09-10T23:16:02Z"
},
{
"tag": "v0.1.59",
"kind": "patch",
"published_at": "2024-09-10T23:08:02Z"
},
{
"tag": "v0.1.58",
"kind": "patch",
"published_at": "2024-09-09T18:35:36Z"
},
{
"tag": "v0.1.57",
"kind": "patch",
"published_at": "2024-09-06T23:14:53Z"
},
{
"tag": "v0.1.56",
"kind": "patch",
"published_at": "2024-09-06T11:50:00Z"
},
{
"tag": "v0.1.55",
"kind": "patch",
"published_at": "2024-08-28T09:13:09Z"
},
{
"tag": "v0.1.54",
"kind": "patch",
"published_at": "2024-08-27T13:12:08Z"
},
{
"tag": "v0.1.53",
"kind": "patch",
"published_at": "2024-08-26T07:20:59Z"
},
{
"tag": "v0.1.52",
"kind": "patch",
"published_at": "2024-08-25T19:49:39Z"
},
{
"tag": "v0.1.51",
"kind": "patch",
"published_at": "2024-08-24T22:13:14Z"
},
{
"tag": "v0.1.50",
"kind": "patch",
"published_at": "2024-08-18T18:27:41Z"
},
{
"tag": "v0.1.49",
"kind": "patch",
"published_at": "2024-08-16T03:45:14Z"
},
{
"tag": "v0.1.48",
"kind": "patch",
"published_at": "2024-08-16T02:51:02Z"
},
{
"tag": "v0.1.47",
"kind": "patch",
"published_at": "2024-08-15T23:45:45Z"
},
{
"tag": "v0.1.46",
"kind": "patch",
"published_at": "2024-08-15T21:05:08Z"
},
{
"tag": "v0.1.45",
"kind": "patch",
"published_at": "2024-08-15T06:32:59Z"
},
{
"tag": "v0.1.44",
"kind": "patch",
"published_at": "2024-08-15T06:22:44Z"
},
{
"tag": "v0.1.43",
"kind": "patch",
"published_at": "2024-08-15T06:15:11Z"
},
{
"tag": "v0.1.42",
"kind": "patch",
"published_at": "2024-08-14T22:57:09Z"
},
{
"tag": "v0.1.41",
"kind": "patch",
"published_at": "2024-08-12T00:50:34Z"
},
{
"tag": "v0.1.40",
"kind": "patch",
"published_at": "2024-08-10T16:10:55Z"
},
{
"tag": "v0.1.39",
"kind": "patch",
"published_at": "2024-08-10T00:16:38Z"
},
{
"tag": "v0.1.38",
"kind": "patch",
"published_at": "2024-08-10T00:04:51Z"
},
{
"tag": "v0.1.37",
"kind": "patch",
"published_at": "2024-08-09T23:53:12Z"
},
{
"tag": "v0.1.36",
"kind": "patch",
"published_at": "2024-08-09T05:19:57Z"
},
{
"tag": "v0.1.35",
"kind": "patch",
"published_at": "2024-08-09T02:47:42Z"
},
{
"tag": "v0.1.34",
"kind": "patch",
"published_at": "2024-08-08T23:48:43Z"
},
{
"tag": "v0.1.33",
"kind": "patch",
"published_at": "2024-08-07T18:20:09Z"
},
{
"tag": "v0.1.32",
"kind": "patch",
"published_at": "2024-08-07T11:30:29Z"
},
{
"tag": "v0.1.31",
"kind": "patch",
"published_at": "2024-08-07T11:13:16Z"
},
{
"tag": "v0.1.30",
"kind": "patch",
"published_at": "2024-08-07T11:02:37Z"
},
{
"tag": "v0.1.29",
"kind": "patch",
"published_at": "2024-08-06T23:38:05Z"
},
{
"tag": "v0.1.28",
"kind": "patch",
"published_at": "2024-08-06T22:00:51Z"
},
{
"tag": "v0.1.27",
"kind": "patch",
"published_at": "2024-08-06T20:17:47Z"
},
{
"tag": "v0.1.26",
"kind": "patch",
"published_at": "2024-08-06T20:04:30Z"
},
{
"tag": "v0.1.25",
"kind": "patch",
"published_at": "2024-08-06T19:46:30Z"
},
{
"tag": "v0.1.24",
"kind": "patch",
"published_at": "2024-08-05T21:37:39Z"
},
{
"tag": "v0.1.23",
"kind": "patch",
"published_at": "2024-08-05T21:23:37Z"
},
{
"tag": "v0.1.22",
"kind": "patch",
"published_at": "2024-08-04T02:29:32Z"
},
{
"tag": "v0.1.21",
"kind": "patch",
"published_at": "2024-08-04T02:25:21Z"
},
{
"tag": "v0.1.20",
"kind": "patch",
"published_at": "2024-08-03T22:24:34Z"
},
{
"tag": "v0.1.19",
"kind": "patch",
"published_at": "2024-08-02T23:42:28Z"
},
{
"tag": "v0.1.18",
"kind": "patch",
"published_at": "2024-08-02T23:32:46Z"
},
{
"tag": "v0.1.17",
"kind": "patch",
"published_at": "2024-08-02T10:01:30Z"
},
{
"tag": "v0.1.16",
"kind": "patch",
"published_at": "2024-08-02T09:05:45Z"
},
{
"tag": "v0.1.15",
"kind": "patch",
"published_at": "2024-08-01T18:14:52Z"
},
{
"tag": "v0.1.14",
"kind": "patch",
"published_at": "2024-08-01T02:06:08Z"
},
{
"tag": "v0.1.13",
"kind": "patch",
"published_at": "2024-07-31T18:30:23Z"
},
{
"tag": "v0.1.12",
"kind": "patch",
"published_at": "2024-07-31T17:43:38Z"
},
{
"tag": "v0.1.11",
"kind": "patch",
"published_at": "2024-07-31T17:30:56Z"
}
],
"recent_commits": [
{
"oid": "0d025bae60f493a42c2f49a4fcbbb46a31bea4ab",
"body": "…atform)\n\nThe cross-platform path-length e2e still asserted a ~747-char path is SKIPPED\non win32 — the behavior from when the win32 cap was 512. The Windows/SMB\nhardening later raised isPathOverMaxLength's win32 ceiling to the 32767-WCHAR\nextended-length limit (Node/libuv auto-prepends \\\\?\\), which \n[…]\nong-path pipeline the raised cap depends\non. The per-platform boundary itself stays unit-tested in n-unit.\n\nNot related to the #10 rename fix; surfaced on the first win32 e2e run since\nthe cap change.",
"is_bot": false,
"headline": "test(sync): fix stale win32 long-path e2e (macOS is now the strict pl…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T22:33:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff421a3b08fdc291da205ebdeafa3f6d6a154672",
"body": "The REMOTE_BUILD_CONCURRENCY bound test wrapped crypto().decrypt() with an\n`any`-typed handle, which trips the CI eslint no-explicit-any rule (the local\nrun and tsc did not). Replace it with a minimal structural view of the crypto\nsurface it wraps (DecryptArgs/DecryptFn/DecryptSurface) cast through unknown,\nso the instrument is fully typed. No behavior change; the two bound assertions\nstill pass.",
"is_bot": false,
"headline": "test(sync): type the decrypt-concurrency instrument (drop explicit any)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T19:03:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9c12873a51d33b396ed2a49a4b9f0e6f241afb74",
"body": null,
"is_bot": false,
"headline": "chore: bump version",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T18:34:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ba71725cc47e5ea39812f17553ae9a460ea7af6",
"body": "A directory renamed on ONE side while a directory at a DIFFERENT level of the\nsame chain is renamed on the OTHER side (local /top->/top2 + remote\n/top/mid->/top/mid2) must compose to /top2/mid2. It did for the plain case,\nbut when the deeply-nested file was ALSO modified on the renaming side the\nedi\n[…]\n-deep\ncomposition; e2e (conflict) covers both directions against the live backend,\nwhere a rename+modify preserves the inode and exercises the explicit\nfile-rename path the mocked fake cloud does not.",
"is_bot": false,
"headline": "fix(sync): compose cross-side nested directory renames (no duplicate)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T18:26:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a2e1d8ef14ad3193b21b68363bdbd94c3b0351e1",
"body": "The remote tree build decrypts folder and file metadata in bounded-concurrency\nbatches (slice REMOTE_BUILD_CONCURRENCY tuples, await, repeat), capping peak\npending decrypt promises and their retained plaintext regardless of tree size\n— the memory ceiling that keeps a multi-million-item tree from OOM\n[…]\n and files). Verified RED by reverting each loop to an eager map:\npeak jumps to the full item count (2098/2099) and blows the cap.\n\nTest-only: the batching is already correct; this pins the invariant.",
"is_bot": false,
"headline": "test(sync): bound REMOTE_BUILD_CONCURRENCY in the remote tree build",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:41:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "86ebda35c9d9ab2a8637fbcb721418f823775358",
"body": "…loaded\n\nThe upload dedup suppresses a no-content-change re-upload by comparing the\nfile's current md5 against localFileHashes[relativePath]. That cache was\npopulated only on UPLOAD, so a DOWNLOADED file had no entry: `md5 !== cache`\n(cache undefined) was always true, and a bare mtime touch on a dow\n[…]\nuch its mtime (same bytes) — the touch\n cycle starts no upload. Verified RED without the fix.\n- e2e (conflict): the same bare-touch-after-download against the live backend\n emits no upload transfer.",
"is_bot": false,
"headline": "fix(sync): cache a downloaded file's md5 so a bare touch is not re-up…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:37:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "55156f12835ce7ff5c1d97236094b26b1e85b6f7",
"body": "…(#18)\n\nBoth incomplete-read carry-forwards (remote decryptErrors, local\nscanIncomplete) re-assert an absent base item ONLY when its path is not\nalready occupied by a readable item this cycle (`!current.tree[path]`).\nWithout that clause the carry-forward would CLOBBER a path a peer legitimately\nre-c\n[…]\nemoved.\n- IR2 (local): the /photos subtree fails to enumerate (scanIncomplete>0)\n while /a.txt is freshly modified — the modification must survive and the\n un-enumerable subtree must not be deleted.",
"is_bot": false,
"headline": "test(sync): pin the incomplete-read carry-forward reused-path clause …",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:28:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b16f0d144ed4a3bc59096c7357afacf6797d75db",
"body": "State.readLargeRecordFromLineStream guarded only the per-line JSON.parse. The\nstream read itself (opening the read stream, and the `for await` over its\nlines) was unguarded, so a read fault — a transient EIO mid-read on a network\nFS, or a failure opening the stream — threw straight out of the state \n[…]\nf throwing. Verified RED without the fix.\nMocked-only: a transient mid-read EIO cannot be forced on a real CI\nfilesystem; the persisted-state load/save paths are otherwise exercised live\nby state.e2e.",
"is_bot": false,
"headline": "fix(sync): a base-file read fault degrades to an empty base, not a wedge",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:25:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "462eb06c0cf134b062ef4692b7768e7a98be2ced",
"body": "…indow\n\nfs.watch on SMB/NFS (and some FUSE mounts) can silently DROP a change\nnotification. The local scan's freshness gate serves the cached tree while\nlastDirectoryChangeTimestamp has not moved past the cache stamp — so a\ndropped notification meant the gate served the STALE tree forever and the\nch\n[…]\n is a lossy watcher dropping a notification, which\ncannot be forced on a working CI filesystem watcher; the freshness gate and\nthe per-cycle scan it drives are already exercised live across the suite.",
"is_bot": false,
"headline": "fix(sync): force a local rescan when the cache ages past the safety w…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:19:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "08382f8cfde949925132491f51023e94b4f00d5c",
"body": "The local scan skipped the trash directory with a SUBSTRING test\n(`entryPath.includes(\".filen.trash.local\")`), so any user path merely\nCONTAINING the trash name mid-name — e.g. /notes/x.filen.trash.local.txt —\nwas silently dropped from the scan. The remote build skips by basename\nboundary (name.star\n[…]\nn /notes/x.filen.trash.local.txt (no re-download loop), and a\ntwoWay local file containing the name mid-path uploads. tests/e2e/modes.e2e\nadds the live cloudToLocal case. Verified RED without the fix.",
"is_bot": false,
"headline": "fix(sync): trash-directory scan skip uses a boundary, not a substring",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T16:07:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6fd63c8d29dda269392016884cc1aa1d1d620f3e",
"body": "Sync.initialize() awaited smokeTest() before starting the cycle loop.\nsmokeTest retries every SYNC_INTERVAL until the local/remote path is\nreachable — unbounded for an offline drive — and initialize() runs inside\nupdateSyncPairs' mutex, awaited by Promise.all across every pair. So ONE\noffline pair s\n[…]\nVerified RED without the fix (initialize() hangs → the\ntest times out, exactly the updateSyncPairs wedge). The availability gating\nthis now relies on is already covered live by resilience.e2e (Q1/Q3).",
"is_bot": false,
"headline": "fix(sync): don't block pair initialize() on the startup smoke-test retry",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:59:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d12066f4a607b4088fc44abd71b6378b8b42fec",
"body": "…r→file\n\nlocalBackup replacing a local directory with a same-named file emitted a\nRECURSIVE deleteRemoteDirectory + markSubtreeAdded for the backup directory —\ndestroying any FOREIGN child another device had added under it, and even the\nsynced children the additive mode keeps on a local deletion. Th\n[…]\nlBackup\ndir→file keeps a concurrent foreign remote child and the synced child, leaves\nthe backup dir intact, and settles. tests/e2e/backup.e2e.test.ts adds the\nlive case. Verified RED without the fix.",
"is_bot": false,
"headline": "fix(sync): additive backup keeps foreign children on an originated di…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:50:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb0c4ad4d6654f2d2a3f7d2965ee365f00ca7f84",
"body": "…ct mirror)\n\ncloudToLocal promises local == remote, so a stray local file at a path the\nremote also holds must be reverted to the remote's bytes. The revert was\ngated on `localDiverged`, which needs a persisted base; with no base and an\nEQUAL size it never fired — noBaseSizeDiverged only catches a s\n[…]\nolocal-nobase-stray.test.ts — no base,\nsame-size newer local stray becomes the remote's bytes and the remote is\nuntouched. tests/e2e/modes.e2e.test.ts adds the live case. Verified RED\nwithout the fix.",
"is_bot": false,
"headline": "fix(sync): cloudToLocal reverts a no-base same-size local stray (stri…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:45:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6112ccc475053142cc2046e325682c0825993793",
"body": "…ivergence)\n\nWith no persisted base (a genuine first sync, or lost/corrupt state) and the\nsame path on both sides, \"did this side change\" falls back to a strictly-newer\nwhole-second mtime. When both copies carry the SAME floored-second mtime but\nDIFFERENT sizes, neither localChanged nor remoteChange\n[…]\nonverges (tie→local); equal sizes stay idempotent.\ntests/e2e/conflict.e2e.test.ts reproduces it against the live backend by\nstamping both copies to the same whole second. Verified RED without the fix.",
"is_bot": false,
"headline": "fix(sync): twoWay no-base fallback keeps the size signal (no silent d…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:41:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14675a6a3eea2dca2ded947c6b17be854e30ac38",
"body": "…ted-fail\n\nFinding #10 was the one place the suite was FALSELY GREEN. XD2/XD4 asserted\nonly that the modified bytes survived SOMEWHERE and that the two sides\nconverged — both of which hold even when the result is a permanent\nDUPLICATE. A cross-side nested directory rename where the file is also\nmodi\n[…]\nle.txt, the pre-rename path is gone) and pins them under\nit.fails, so the bug is CI-visible instead of falsely green and the tests\nflip to a hard failure the moment a real fix lands. No source change.",
"is_bot": false,
"headline": "test(sync): pin the cross-side nested-rename duplicate (#10) as expec…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:34:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "557919fc765e3042e3d728859fbc7a0956c821a6",
"body": "The live unlink cache-update evicts a deleted directory's descendants by\nscanning the whole tree with a `for..in`. It ran that O(tree) scan for a\nFILE too — which has no descendants — so deleting a large flat folder did one\nfull-tree scan per file: O(N²). On a project that targets 100k–1M files the\n\n[…]\ns exactly one (the\nfix does not weaken subtree eviction). Verified RED without the fix (the\nper-file scans reappear). Behavioral deletion correctness stays covered by\nthe existing deletion e2e suites.",
"is_bot": false,
"headline": "perf(sync): make bulk file deletion O(N) instead of O(N²)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:12:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "36146b7fb24efc8e9178cc13acba98e621ef4b9e",
"body": "processTask gated every not-yet-started task on waitForPause, which BLOCKED\nthe task until resume. But it runs inside the cycle, which holds the\nauto-refreshing account lock — so pausing a pair mid-cycle held that lock for\nthe entire pause and starved every OTHER device on the account (none could\nsy\n[…]\nke\n timers; RED without the fix (the cycle never resolves).\n- tests/e2e/lifecycle.e2e.test.ts adds the mid-cycle-pause case against the\n live backend (complementing the existing pre-cycle-pause I2).",
"is_bot": false,
"headline": "fix(sync): pausing mid-cycle releases the account lock (no starvation)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T15:06:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58f6821195ce6912994bdfcc10a01301621fbb45",
"body": "isPathIgnored's cache was keyed by path alone, but the .filenignore verdict\nis type-dependent: a dir-only rule like `build/` ignores `build` as a\nDIRECTORY (trailing slash) but not as a FILE. So once a `build` directory was\nscanned and cached {ignored:true} under key `build`, replacing it with a\nsam\n[…]\n. Their intent (cache preserved across unchanged re-init,\n cleared on rule change) is unchanged — sanctioned edit of a test that\n pinned the wrong behavior.\nVerified RED without the fix (IC1 fails).",
"is_bot": false,
"headline": "fix(sync): key the local ignore cache by path AND type (BUG-005 reopen)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:48:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1ab64b718ba82ddc745e2ac3dd7c6fe92e577c8c",
"body": "The additive backup modes deliberately TOLERATE a foreign type change on the\nside they promise never to delete (localBackup never deletes the remote;\ncloudBackup never deletes the local — reverting a dir→file there would delete\nthe foreign item). But the addition pass then tried to write the source'\n[…]\n tests/e2e/backup.e2e.test.ts adds the localBackup case against the live\n backend (which genuinely rejects upload-under-a-file).\nVerified RED without the guard once the fake is faithful (both wedge).",
"is_bot": false,
"headline": "fix(sync): additive backup tolerates a foreign dir→file without wedging",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:44:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfe01e9b36bdc48684488fb66819d642b6ecca0d",
"body": "…ntom rename\n\nThe F8 guard distinguishes a genuine local rename from an ext4-style\ninode-reuse coincidence (\"delete a.txt + create c.txt\" landing c.txt on\na.txt's freed inode) by the file's birthtime: a rename preserves it, a\nreused inode belongs to a freshly-created file with a newer one. As a\nrela\n[…]\n non-zero birthtimes — so this class is mocked-only;\nthe real inode-reuse-with-birthtime path is already covered by lifecycle.e2e\n(I6) and the localBackup additive-keep invariant by confirm.e2e (AA6).",
"is_bot": false,
"headline": "fix(sync): don't let a birthtime-0 volume turn inode reuse into a pha…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:33:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9fac5bcc1124043a47c0dfdb9511a2bdb0ea40fc",
"body": "The large-deletion confirmation gate is guarded on `previousTree.size > 0`.\nA cycle's transfer handlers add/remove entries in the live directory-tree\ncache's `.tree` in place but never touch its `.size`, so the end-of-cycle\nbase snapshot copied a stale `result.size` that disagreed with a fully\npopul\n[…]\ne/confirm.e2e.test.ts adds both against the live backend.\nVerified RED without the fix (2 fail). Full mocked suite green, incl. the\nexisting Category G gate tests (G3 documented this very limitation).",
"is_bot": false,
"headline": "fix(sync): derive base-tree size from the tree so the deletion gate arms",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:23:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f266acef60bbaf6fd433522bdb76bf27411a369e",
"body": "The incomplete-remote-read guard re-asserts the persisted base so a skipped\nitem is never mistaken for a deletion — but it was gated on decryptErrors>0.\nA different inconsistent-response shape slipped through with zero protection:\na missing intermediate folder tuple in /v3/dir/tree. Every returned i\n[…]\n\n- tests/e2e/resilience.e2e.test.ts reproduces the orphan against the live\n backend by dropping one real folder tuple by uuid.\nVerified RED without the fix (3 fail incl. the local-deletion scenario).",
"is_bot": false,
"headline": "fix(sync): carry base forward on a structural orphan in the remote tree",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:15:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45df72c9dd0076e5c148c90d2b5b43e688acbe0a",
"body": "The local scan prunes provably-.filenignore'd subtrees from the FastGlob\nwalk. A bare-name rule (`node_modules`) emitted a **-prefixed prune glob\nthat applies at EVERY depth, but the safety probe only ever checked the\ntop-level form. The standard \"ignore all X, keep one nested X\" idiom\n\n node_mod\n[…]\niom is introduced over a settled base (the cloud-delete path).\n- tests/e2e/ignore.e2e.test.ts adds both against the live backend.\nVerified RED without the fix (5 fail incl. the cloud-delete scenario).",
"is_bot": false,
"headline": "fix(ignorer): keep traversal-prune globs subset-safe under negations",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T14:05:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9dbb078231082621e4bb42d7d20765675c412aa5",
"body": "…letion)\n\nFastGlob scans the local tree with suppressErrors:true, so a transient\nreaddir failure on one directory (EIO/EACCES/ENOTDIR — routine on SMB/NFS\nand removable media) silently omits that whole subtree from the scan. The\nomitted items were then absent from the fresh tree, indistinguishable f\n[…]\nbtree over a settled base and asserts no deleteRemote*\nfires and the cloud copies survive, then convergence after recovery. Needs\na harness cap: globFs partial-readdir injection (setGlobReaddirError).",
"is_bot": false,
"headline": "fix(sync): carry local base forward on an incomplete scan (no mass de…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T13:55:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92eef068cca0e17e5936f386ce7d6b6c07dab3f5",
"body": "The mocked suite ran entirely on memfs (posix, case-sensitive, stable inodes, integer\nmtimes) — structurally blind to the Windows/SMB behaviors behind every v3.0.50 field\nbug. Add, on top of the fake-fs trait modes:\n\n- fs-trait-matrix: representative shapes x each faithful volume trait (SMB ino:0,\n \n[…]\nl/backup\n modes, not just twoWay).\n- resilience-state-save: a state-save I/O failure mid-session does not re-upload\n (in-memory base carries forward); a lost base re-derives without re-transferring.",
"is_bot": false,
"headline": "test: harden the suite against the Windows/SMB bug classes",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T13:39:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8826401854cb77edb1b5cc470dacf76a234b3e94",
"body": "isPathOverMaxLength capped win32 paths at 512 chars — a conservative guess between the\nlegacy 260 MAX_PATH and the real ceiling. Node/libuv auto-prepends the \\\\?\\ prefix for\nabsolute paths, so fs ops handle paths up to the 32767-WCHAR long-path limit regardless\nof the app manifest or LongPathsEnable\n[…]\n at 512) while a >32767 path is still skipped;\ndeep-nesting (deep path syncs both directions + settles); anti-silent-drop (long/unicode\nnames, broad tree, deep path all sync with zero ignore reasons).",
"is_bot": false,
"headline": "fix(sync): correct the win32 path-length cap to the long-path ceiling",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T13:39:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3297d2dfe1e48cb648ddb78251fdef25852c955",
"body": "The backend is case-insensitive, so a path that differs only in casing between the\nlocal disk and the cloud is the SAME item. The add/delete/modify/type-change passes\ncompared exact-case, so a case-only divergence with no active rename (a fresh sync,\nlost/cleared state, or a cross-device difference)\n[…]\nolume both directions; directional modes) + live e2e. Harness: the\nfake fs gains a case-insensitive, case-preserving volume mode (+ SMB ino:0 / fractional\nmtime trait modes) with conformance coverage.",
"is_bot": false,
"headline": "fix(sync): case-insensitive whole-path matching in the delta engine",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-18T13:39:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1e66b50085784c8a80bedd136706440ec80ca484",
"body": null,
"is_bot": false,
"headline": "chore: bump version",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-17T18:35:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9ba75fb506c08b17ca561e055d6ce499a8ccc8c5",
"body": "The v3.0.50 containment checks used `resolved.startsWith(root + sep)`. When\nthe sync root is a filesystem mount root — a Windows mapped-drive root (Z:\\)\nor a UNC share root (\\\\NAS\\share), the common Synology-over-SMB shape —\n`path.resolve()` already ends in a separator, so appending one more yields \n[…]\nthe win32 Z:\\ and \\\\NAS\\share\nshapes via an injected path flavor (every CI leg) plus a host-native /-root\nrepro; the scenario and live suites drive the real filter and mkdir sink at a\nmount-root pair.",
"is_bot": false,
"headline": "fix(sync): admit mount-root sync pairs in the path-traversal guard",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-17T13:37:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fcf7462f464a133a5af99dcc0448cdc9b65f88a5",
"body": null,
"is_bot": false,
"headline": "chore: bump deps and version",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-15T10:01:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff21fed2a1b52d83a9a2a565558ae6ad15aa51d7",
"body": "Item names come from the cloud and are joined onto the local sync root to build each local\npath. path.join collapses `..` segments, so a name containing them could resolve OUTSIDE the\nroot, and a download-move / mkdir / rename / delete would then act on a path that is not part\nof the pair. The tree \n[…]\ns invalidPath and nothing resolves outside the root; each\n filesystem operation throws when given such a path), and live e2e (the operations reject an\n out-of-root path against the real filesystem).",
"is_bot": false,
"headline": "fix(sync): ensure every synced path resolves within the sync root",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-13T03:06:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9bf8fb06f0b5b98e6cf4ca2dd84b5ad5f8069508",
"body": "…cal tree walks",
"is_bot": false,
"headline": "fix: deterministic case-insensitive collision resolution in remote/lo…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-10T22:45:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d034c631bd05c556bd82eb5c7648f7c954cb438e",
"body": null,
"is_bot": false,
"headline": "fix: keep synced items within the sync root",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-07-10T21:25:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bac146bf4c66a9d1a5cc8babfafff7cdb525674",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 0.3.4",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T20:26:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dde238d182bce4af7f15e806c34a4bc0916d0149",
"body": "- Bump every action to its current major: actions/checkout v4 -> v7,\n actions/setup-node v4 -> v6, github/codeql-action v3 -> v4 (init, autobuild,\n analyze, upload-sarif).\n- npm-publish workflow: target Node 24 (the engine is \"node\": \">=24\"; it was\n pinned to 20) and install with a plain `npm ci`\n[…]\ny and wrong.\n- Remove .github/dependabot.yml: it only watched the npm ecosystem (daily) and\n never github-actions, which is how the action versions drifted; dependency\n updates are handled manually.",
"is_bot": false,
"headline": "ci: upgrade workflow actions, fix the publish install, drop dependabot",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T20:26:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22effce9b5a393a22334afd8305289ca4673f947",
"body": null,
"is_bot": false,
"headline": "chore: bump version",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T18:49:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0478c3b3067f2d752e8e97c245d3eccb04c336a5",
"body": "…dlink edits, FIFO)\n\nFills the special-file/identity scenarios the second-phase audit surfaced:\n- IX1 a synced file PERMANENTLY replaced by a symlink keeps its cloud copy across\n many cycles with no wedge (mocked)\n- IX2 a divergent edit to one of two shared-inode files re-syncs it alone (mocked)\n- \n[…]\nation\n(uuid-keyed per-pair state, isolated by construction) and mid-byte-stream\ntransfer pause (SDK-internal; the engine's signal routing is covered by I3/I4/I5)\nare accepted as documented boundaries.",
"is_bot": false,
"headline": "test(sync): cover identity/special-file edge cases (symlink loop, har…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T18:47:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc7fd21335d41a2cd13b19e4595a3b65ee7bfb42",
"body": "…ss machines\n\nThe root .filenignore is the ignore list the engine reads from the local sync\nroot every cycle. It now syncs even when excludeDotFiles is on, so a user's\ncurated ignore config reaches every machine on the pair (the users who exclude\ndotfiles are exactly the ones who most want a shared \n[…]\ne-filenignore-sync (IG1-6), a unit regression, and\nlive e2e. The e2e snapshot helper now skips .filenignore on both sides\nsymmetrically so the synced config never affects tree-convergence comparisons.",
"is_bot": false,
"headline": "feat(sync): sync the root .filenignore so one ignore list shares acro…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T18:13:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "336ee02f0d81f085da77640f50e93929b8304b26",
"body": "The live suite runs serially against one account and keeps growing, so give it\ngenerous headroom and never flake a slow-but-healthy run on a loaded runner; a\ngenuine hang is still caught by the per-test timeouts. CI e2e job 90 -> 180 min,\nvitest.e2e config test/hook/teardown 1h -> 2h, every per-test timeout 15 -> 30\nmin. Literal-only; no test behavior changes.",
"is_bot": false,
"headline": "test(e2e): raise live-suite timeouts (CI job, vitest config, per-test)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T18:12:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d90fcf2b2bf5920f04d246dd77984f12641a51f0",
"body": "…ty fuzzers\n\nThe weird/conflict/race scenarios were all pinned at tiny (1-4 item) scale, so the\nengine's aggregate code paths only ever ran trivially: collapseDeltas, the\ndirectory-survivor keep + its splice maintenance, the rename-rebase (BUG-A/B),\ngate-counting, the depth-sort, the parallel task b\n[…]\nreverted. Also\npins F9 noBaseSizeDiverged on the additive backup modes (a previously untested\nbranch). Full live e2e parity. No engine change was needed - the engine is\ncorrect at scale on every path.",
"is_bot": false,
"headline": "test(sync): scale-harden the aggregate code paths + structural proper…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T18:11:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1b193c0ee091c7fc57076addacdc8d23dabbe578",
"body": "…mote move\n\nAdds a moveRemote harness helper (cross-directory remote move = rename-then-move\nwith overwriteIfExists, mirroring the engine's own remote.ts sequence), closing a\npre-existing parity gap where cross-dir remote moves had no live counterpart.\n\nweird-edge-3.e2e (20 tests) validates the roun\n[…]\ne\nmovePath faithfulness fix (XS/XC-live exercise the occupied-destination path\nlive), and one representative case per new category (XD/RR/DR/MT/PC/FD/DC/XN/RS/\nXM/BS), plus restart recovery (RS-live).",
"is_bot": false,
"headline": "test(e2e): live parity for the round-3 weird scenarios + cross-dir re…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T16:06:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b8eb6a0833c31b8b78f6c7a476c52ac4d0a9c3df",
"body": "Found via a systematic same-path conflict matrix (the touch row/column was the\nlast gap — touch detection is asymmetric: a local touch is visible via mtime, a\nremote touch mints no uuid so it is invisible).\n\nBug: modify-vs-modify resolved by newer mtime, so a bare local touch (newer\nmtime, unchanged\n[…]\nes are excluded). No hashing added to any hot path.\n\nPinned by ti-touch-interactions (TI1-8, incl. the no-cache TI8) and\nrc-restart-amid-conflict (RC1-5), RED->GREEN; live regressions in weird-edge-3.",
"is_bot": false,
"headline": "fix(sync): a bare mtime touch must not clobber a concurrent remote edit",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T16:05:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cabfc7e9134b4a37a42ea5619404b5b7594aa6fd",
"body": "…mtime, restart\n\n13 new mocked categories, all green (no engine bug in this vein — the cross-side\nreconciliation is now exhaustively pinned):\n\n- XD/XN: nested + deep/divergent cross-side directory renames (rebase composition)\n- XC: split rename chain (a->b local / b->c remote)\n- XS: true cross-side \n[…]\ncreate the source path in one cycle\n- MT: extreme mtime (far-future / epoch-0), loop-free\n- RS: restart mid cross-side structural reconciliation\n- BS: structural change under the additive backup modes",
"is_bot": false,
"headline": "test(sync): weird-scenario coverage for cross-side structure, swaps, …",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T16:05:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ca5013f90a1c5e524cf5ff585399dc7e1c750e99",
"body": "The controls.movePath test control (a peer-device move/rename) reassigned\nparent+name with no collision handling, so a move onto an OCCUPIED name left\ntwo live siblings sharing a name in one parent — impossible on the real backend\n(per-parent uniqueness; a rename-onto-occupied trashes the occupant).\n[…]\nbut converges live. Mirror the SDK's own\nmoveFile/moveDirectory collision logic — trash a same-type occupant, reject a\ncross-type one. No engine change; no existing test relied on the permissive path.",
"is_bot": false,
"headline": "fix(tests): make fake-cloud movePath faithful to backend name uniqueness",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T16:05:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "77b1527438d6d8dbe7ff679273d5a6b53ec1a0f9",
"body": "Exercises the remaining reachable branches the symlink-subtree and ignore-gate\nfixes introduced (verified via deltas.ts branch coverage):\n\n- SL7: a remote child deleted under a locally-symlinked folder is not propagated\n as a local delete and does not error (the remote-deletions ancestor guard).\n- \n[…]\n a subtree WHILE another device deletes it keeps the\n (ignored) local copy and raises no spurious large-deletion prompt — the\n dropped deletes never double-count into the gate from either direction.",
"is_bot": false,
"headline": "test(sync): cover the symmetric ignore/symlink deletion branches",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T14:09:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f6ad7a8aa0978e3b1c3d97883e00f7ea4486682",
"body": "Validates every fix and scenario from this round against the real local\nfilesystem + Filen backend (the fake cloud can be too permissive). 14 tests:\nmove-into-renamed-dir (file/dir/no-dup), move+modify content survival (the\nlive-only F1 data-loss repro), additive type-change tolerance, mirror revert\n[…]\nkeep-both, mode-switch authority, no-base newer-wins,\nsymlink-folder subtree retention + no wedge, file->symlink->file round-trip,\ndir-rename beats dir-delete, and a one-link rename of REAL hardlinks.",
"is_bot": false,
"headline": "test(e2e): live-backend parity for the cross-side hardening round",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T13:57:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2be8b4ee719170011b250513c1345a4159f113c3",
"body": "Adds mocked scenario categories pinning already-correct engine behavior across\nunder-tested seams (no engine change). All converge / settle with no data loss:\n\n- ZY: no common base (fresh, or lost/corrupt state) with DIVERGENT content ->\n newer-mtime wins; state loss never spuriously deletes a one-\n[…]\ndeleted target; both sides replace a dir's contents).\n- HL: renaming one of two hardlinked files degrades gracefully (both links kept,\n converges, settles) on identical-content (real-hardlink) bytes.",
"is_bot": false,
"headline": "test(sync): weird-scenario coverage for cross-side races and edge seams",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T13:57:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f3993d697145e3d59fa85a60de9ecb29a8fd148b",
"body": "Four edge-case bugs surfaced by new weird-scenario tests, all fixed in the\ndelta engine only (SDK/backend untouched), perf-gated, no regressions.\n\n1. Move-into-a-concurrently-renamed-directory DUPLICATION (ZW). A file or\n directory moved INTO /dir while the other side renamed /dir -> /dir2 in the\n\n[…]\n nothing); remote-additions also stops re-creating an\n ignored directory / descendant (which otherwise wedged every cycle), while a\n remote file at an exactly-ignored path still heals (keeps F15).",
"is_bot": false,
"headline": "fix(sync): cross-side reconciliation hardening (4 fixes in deltas.ts)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T13:57:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92814dc486e75f7d7256ce0da4f04994d7688b76",
"body": "The readdir/readdirSync spy casts in zs-ignore-traversal-pruning carried the\nproperty's `| undefined` into the assignment target, which tsc rejects under\nexactOptionalPropertyTypes (vitest's esbuild transform skipped it, so it only\nsurfaced in `npm run typecheck`/CI). Cast to NonNullable<...> instead. No test\nlogic change.\n\nClaude-Session: https://claude.ai/code/session_01GRbezK9PNWaiwVhYwamokW",
"is_bot": false,
"headline": "test(sync): fix exactOptionalPropertyTypes violation in ZS readdir spy",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:46:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc1d25958174978e7c19576f526046a449b70fe2",
"body": "Every individual e2e test/hook timeout (previously 120s / 180s / 300s) overrode the generous global\ntestTimeout and was the binding constraint that could flake on a slow GitHub runner. Bump them all to\na uniform 900_000 (15 min) — a 3-7.5x increase that's still well under the 90-min job cap even with\nthe config's retry: 1, so a genuinely hung test still fails the job rather than hanging forever. No\ntest logic or assertions changed.",
"is_bot": false,
"headline": "test(e2e): raise per-test timeouts to 15 min for slow CI",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:40:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "867fba73907c4f02bdcfb2ab11b75d3c11644011",
"body": "Adds live-backend counterparts for the most distinctive ZU cells so the directional delete×modify\nconflict resolution is verified against the real filesystem + backend, not only the in-memory fake:\nZU1-live (localToCloud — local delete beats a foreign remote modify), ZU3-live (cloudToLocal —\nremote delete beats a foreign local modify), ZU5-live (localBackup — a local delete never propagates\neven under a concurrent foreign remote modify). add-only.",
"is_bot": false,
"headline": "test(sync): e2e parity for the directional-mode conflict matrix (ZU)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:37:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0a2c47520e04efc6e6f6135ae3c7c980df7906a",
"body": "…a-loss guard\n\nCloses two enumeration gaps surfaced by a final systematic sweep (mode × conflict, and the permission\nmatrix). Add-only; no existing test changed; no engine change needed (both behaviors were already\ncorrect — these pin them).\n\n- zu-directional-conflict-matrix: the delete×modify confl\n[…]\n The e2e uses a\n real, persistent chmod and also asserts clean reconciliation once readable again. The existing e2e\n only covered a brand-new denied file (skipped on upload), not the data-loss case.",
"is_bot": false,
"headline": "test(sync): directional-mode conflict matrix + permission-revoked dat…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:35:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b93bfd79e0a00d6227a0daba794ffed916146bba",
"body": "…ion gate\n\nFollow-up to the .filenignore traversal pruning. The large-deletion confirmation gate keys on the\nraw delete counts, which are tallied in the deletion passes BEFORE the end-of-process ignore filter\ndrops ignored-path deltas. Pre-pruning, a now-ignored path flowed through ignoredLocalPaths\n[…]\nes + ignoring\na prunable directory that holds the whole side) and asserts no prompt + remote survives; ZT2 confirms\na real emptying still prompts; ZT3 covers a partial ignore with a surviving sibling.",
"is_bot": false,
"headline": "fix(sync): keep ignore-pruned paths from false-firing the large-delet…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:22:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1b83fe708a5119117ba951722f94202b53175fca",
"body": "Drops the post-matrix `cleanup` job from the live SDK E2E workflow and updates the header comments to match. The workflow now only runs the platform test matrix, while concurrency still ensures newer pushes supersede in-flight runs.",
"is_bot": false,
"headline": "ci: remove E2E workflow cleanup job",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:13:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "57b5db651f6d7a8a7938810dc2ed034494fa146d",
"body": "…-check before lstat\n\nThe local directory walk globbed `**/*` with no ignore awareness, then filtered every entry AFTER\nan lstat. So an excluded subtree (e.g. node_modules) was still fully traversed and stat'd each\ncycle, and a path excluded precisely because it is pathological (a dead network mount\n[…]\nclude / prefix-similar sibling /\ndir-only-vs-same-named-file / ignore-after-sync-no-delete / convergence), and weird-edge.e2e\nZS-live (the file-vs-dir safety case on real FastGlob + the live backend).",
"is_bot": false,
"headline": "perf(sync): prune .filenignore'd subtrees from the local scan, ignore…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T11:11:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7cd0f40680d48854a1eea7b2204c17b934e45296",
"body": "…plicate\n\nA cross-parent move that also renames the basename is two SDK calls in remote.rename()\n— renameFile/renameDirectory THEN moveFile/moveDirectory. If the move-half failed after\nthe rename-half committed (a transient network/quota/permission error mid-operation), the\nbackend was left renamed-\n[…]\n a same-size edit with a backwards mtime still uploads\n (guards the load-bearing != over >), backwards-touch no-churn, future-dated mtime, and\n uuid-based (time-independent) remote change detection.",
"is_bot": false,
"headline": "fix(sync): roll back a partial rename+move so a faulted move can't du…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T10:45:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e29b5b9eb69f99ad4f0eb917c423cc486ae9210e",
"body": "File metadata can decrypt without a `lastModified` (older files, or other clients) even though the SDK\ntype declares it required. convertTimestampToMs(undefined) returned NaN, which then poisoned downstream\ncomparisons (NaN !== NaN makes a file look changed every cycle) and threw via `new Date(NaN)`\n[…]\n were already handled — dir\ntime fields are never compared (type-guarded), and the rename guard's creation check runs on local fs\nbirthtime. Unit-tested in tests/unit/time-handling-robustness.test.ts.",
"is_bot": false,
"headline": "fix(sync): tolerate a missing file lastModified in remote metadata",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T09:57:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a4c9f4cc0ac3f2d7aab819093e231bcef8fc0c6",
"body": "…time\n\nThe inode+birthtime rename guard (F8 — prevents an ext4 inode reuse being misread as a rename)\nrejected a GENUINE directory rename when the platform reports the directory's birthtime\nunreliably across the rename. Observed on Windows: it silently broke cross-side dir-rename\nreconciliation ther\n[…]\ned the cheap checks, so it costs nothing on the normal path. Unit-tested in\ndir-rename-corroboration.test.ts; the live behavior is validated by the e2e edge BUG-A/BUG-B tests\non a real Windows runner.",
"is_bot": false,
"headline": "fix(sync): harden directory-rename detection against unreliable birth…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T09:40:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7911c90d821b7d6edae2d212cbbe1cb000d30a86",
"body": "…ispatch + orphan cleanup\n\nThe live e2e suite now runs on every push to main (was nightly + manual) so live-backend\nregressions surface per-commit; the deterministic suite (test.yml) still gates push/PR.\n\n- concurrency: a newer commit on a ref cancels that ref's in-flight run, so the slow\n (~40 min\n[…]\non a sibling matrix runner, then empties\n the trash. load-env.ts lets the standalone script read .env.e2e like the vitest config does, so\n it works both locally (npm run test:e2e:cleanup) and in CI.",
"is_bot": false,
"headline": "ci(e2e): run on every push, cancel superseded runs, single-platform d…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T09:40:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af7f215a20687151bb868865422fec998e0913b7",
"body": "Systematically enumerate the engine's behavior space -- the per-path\ntree-state triple (base x local x remote), cross-path identity relations\n(rename/move/swap/rotation/hardlink/inode-reuse), the five modes, faults,\nand cycle boundaries -- and add the previously-missing scenarios. 104 new\ntests acro\n[…]\nn accepted content-\nblindness limitation, since the engine never hashes in a hot path).\n\nExisting tests are untouched. Mocked: 645 passed + 1 tripwire (81 files);\nfull live e2e: 140 passed (16 files).",
"is_bot": false,
"headline": "test(sync): expand mocked + e2e suites with weird/edge/race scenarios",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T01:21:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d21f654b516829d9693ddc1c9422bf32ea6592b",
"body": "…ation\n\nThree conflict scenarios silently lost data or left the local and remote\nreplicas permanently diverged against the real backend (the in-memory test\nharness was too permissive to catch them):\n\n- file<->directory NAME SWAP: the rename detector emitted a cross-type\n rename (a file onto a direc\n[…]\ny (F7), in both deletion passes.\n\nAll three fixes are O(1)/zero-cost on the normal path and never hash in a\nhot path. Mocked suite green (645 + 1 known tripwire); full live e2e green\n(140 / 16 files).",
"is_bot": false,
"headline": "fix(sync): prevent three data-loss/divergence bugs in delta reconcili…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-29T01:21:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a4ac81f73bfa350e90281dbbe4586a1114edafe7",
"body": "…log)\n\nThe rename transfer events the engine emits carried only the destination path\n(relativePath = the rename's 'to'), so a consumer (the desktop sync log) could\nnot tell an in-place rename from a move, and could not even show the source —\nevery relocation read as 'renamed'. Add 'from' and 'to' to\n[…]\nehavior changes, the on-wire shape only gains fields (backwards\ncompatible). 559 mocked tests green; new regression test pins from/to for both an\nin-place rename (same dir) and a move (different dir).",
"is_bot": false,
"headline": "feat: include from/to in rename transfer messages (move vs rename in …",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T22:57:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "09bcea4749cb8c4c09f54b4d23f6a72e760fc610",
"body": null,
"is_bot": false,
"headline": "chore: bump version",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T17:15:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "57659b821839fdfe3460275809a780ade878d750",
"body": "The concat form in 8f1a459 used single-quoted strings (they contain double\nquotes); the repo's quotes rule requires double quotes. Switch to a template\nliteral — byte-identical output, lint + typecheck clean.",
"is_bot": false,
"headline": "style: use a template literal for the state line (lint: doublequote)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T12:17:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f1a4599bd46033ec04cd5e237683165b0a4ee24",
"body": "writeLargeRecordSerializedAndAtomically built each line as\nJSON.stringify({ prop, data }) — allocating a wrapper object per entry. Build\nthe line by concatenating the two stringified fields directly\n('{\"prop\":'+JSON.stringify(prop)+',\"data\":'+JSON.stringify(data)+'}'). The\noutput is byte-for-byte id\n[…]\nh are unchanged; it just drops the per-entry wrapper allocation.\n\nBehavior-identical: 559 mocked tests green incl. the byte-format-sensitive\nstate.test.ts / state-refencode-regression / j-state-cache.",
"is_bot": false,
"headline": "perf: build state lines by concat, not a wrapper-object stringify",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T12:00:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e72ff175825369350d69b6b797157573f7556815",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 0.3.1",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T11:45:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62d06fc6bbb320fddcf0c160e321030943969fa0",
"body": "Behavior-identical reductions in per-item hot paths:\n- isPathIgnored (local + remote): one ignoredCache.get() instead of two (it ran\n a redundant second get() per item on every scan/build — and after the cache\n now survives a cycle, that is a hit for every unchanged path every cycle).\n- remote pat\n[…]\ns via the JSON.parse catch).\n\nCovered by existing tests (state.test.ts blank/whitespace handling, the scan\nsuites exercise isPathIgnored on every file). 559 mocked tests green; typecheck\n+ lint clean.",
"is_bot": false,
"headline": "perf: drop redundant lookups in hot paths (micro-wins)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T11:40:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd47e3d4b0b16ef3fd9752f10368c729c9ff2503",
"body": "…ear)\n\nAfter the O(1) semaphore (b904347) and the remote-build rewrite (0f281bb) these\npaths are linear, so the benches go to 200k/500k/1M (where the old O(N^2) build\ntook 22s+ at 200k). Also adds profile-incremental.ts, the per-phase cycle\nprofiler. Bench-only; not run in CI.",
"is_bot": false,
"headline": "test(bench): scale semaphore/remote-build benches to large N (now lin…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T05:44:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f281bb34afcff21b6ad8a69c1a2091efb6d91f8",
"body": "remoteFileSystem.getDirectoryTree is rewritten:\n\n1. UNORDERED correctness (bug fix). The /v3/dir/tree response can arrive\n unordered — no guarantee a parent folder precedes its children, nor that\n folders[0] is the sync root. The old loop built paths incrementally in array\n order and required \n[…]\nrder). New tests/unit/remote-tree-unordered-regression.test.ts proves\na shuffled response builds the identical tree (RED on old code: 'Invalid base\nfolder parent') and a no-root response still throws.",
"is_bot": false,
"headline": "perf+fix: order-independent, batched remote tree build",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T05:31:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dd7434313760f1dd9094857f6eec5f368aa741b7",
"body": "tasks.process dispatched deltas in 12 type passes by scanning the whole\ndeltasSorted array 12 times (10 sequential 'if type !== X continue' loops + 2\n.filter() passes for the transfers) — 12*O(deltas) just to order the work, which\ncosts real time on a bulk cycle (e.g. an initial sync of a huge tree)\n[…]\ncked tests green; new dispatch-order regression test\n(tests/unit/tasks-dispatch-order-regression.test.ts) pins deletes-before-creates-\nbefore-uploads ordering + convergence in a mixed one-cycle batch.",
"is_bot": false,
"headline": "perf: partition task deltas once instead of 12 filter-passes",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T05:21:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "211c02c8208717cb51a1a92a2dfb144e72c97498",
"body": "State save/load was the biggest per-cycle O(N) cost (300k: save 1.5s/5s CPU,\nload 2.2s/1.4GB RSS). Two behavior-preserving changes:\n\n1. writeLargeRecordSerializedAndAtomically now accumulates ~64KB batches and\n writes those instead of one stream.write()+drain per entry. Emitted bytes are\n byte-f\n[…]\nnged); new guards in tests/unit/state-refencode-regression.test.ts pin the\nref format, the round-trip rebuild, legacy-format back-compat, the missing-file\ngate, and the shared-inode last-wins rebuild.",
"is_bot": false,
"headline": "perf: state persistence — batch writes + ref-encode index files",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T05:15:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "801a4d701e3b920633f11332b86cd4ae534fb233",
"body": "ignorer.initialize() runs every cycle (to pick up .filenignore edits) and\nunconditionally cleared both filesystem ignoredCaches + rebuilt the matcher. The\nper-path ignore cache was therefore wiped every cycle, so every tree scan\nrecomputed the expensive per-file ignore checks (micromatch + the gitig\n[…]\ncle, 20k nodes): local scan 544ms -> 76ms, whole\ncycle 700ms -> 225ms (3.1x). Behavior-identical: 546 mocked tests green; new\nwhite-box regression tests in tests/unit/ignorer-cache-regression.test.ts.",
"is_bot": false,
"headline": "perf: skip ignoredCache wipe when ignore rules are unchanged",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T05:08:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b904347870e0cf48acdd0094aaf85f07a9569392",
"body": "Semaphore.processQueue dequeued waiters with Array.shift() (O(n)). When many\ntasks await one semaphore the waiting queue grows to ~N and each of the N\nrelease() calls shifted an ~N-length array, making the whole fan-out O(N^2).\nThis dominated the remote tree build (every file awaits the 1024-wide\nli\n[…]\nidentical: the existing Semaphore tests are unchanged and green; new\nlarge-fan-out regression tests (tests/unit/semaphore-regression.test.ts) pin\nFIFO order, the concurrency cap, and purge accounting.",
"is_bot": false,
"headline": "perf: O(1) amortized Semaphore dequeue (was O(N^2) under fan-out)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T04:59:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ea86041f28dfb950e588c77d83d467103a93fff",
"body": "A vitest-based benchmark harness for the sync engine measuring wall time, CPU\ntime and memory (gc-stabilized retained heap + peak RSS) at scale (up to\nmillions of nodes). Bench files live in tests/bench/**/*.bench.ts and are NOT\nmatched by the mocked suite's *.test.ts include, so they never run in n\n[…]\n, and a\nlong-running leak/degradation check.\n\nRun: NODE_OPTIONS='--expose-gc --max-old-space-size=120000' \\\n npx vitest run --config vitest.bench.config.ts\nthen: npx tsx tests/bench/render.ts <label>",
"is_bot": false,
"headline": "test: add performance benchmark suite (excluded from CI)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T04:59:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "618dbabf3aad343ce808faf85396e77dbb27ff38",
"body": "The fake cloud's acquireResourceLock ignored maxTries/tryTimeout and threw on\nthe first contention. The engine always acquires with maxTries:Infinity, so the\nreal SDK BLOCKS on a contended lock until it frees — it never returns an\nimmediate contention failure. Tests built on the old fake therefore a\n[…]\n AA1/AA2: a contended cycle now BLOCKS on acquire (no cycleError) and\n completes once the lock frees, applying all pending work — the convergence and\n no-work-while-blocked invariants are unchanged.",
"is_bot": false,
"headline": "test: model the SDK's blocking lock acquire faithfully in the fake",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T03:54:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a6379afab668ac36e5363110df58a76dfcc783ea",
"body": "download() streams the remote file into a uuid-named temp under the local trash\ndirectory and commits it with a single move. The size-mismatch guard already\ndiscarded the temp before throwing, but the general catch (a rejected/partial\ntransfer, or a failure during the commit move) re-threw without r\n[…]\nry exit.\n\nRegression: tests/scenarios/zo-download-temp-cleanup.test.ts fails the commit\nmove so the download lands in its catch with a fully-staged temp, and asserts\nthe local trash dir is left empty.",
"is_bot": false,
"headline": "fix: discard a download's staged temp file when the transfer fails",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T03:38:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3eaee45dd314fbf065e642ae7891711e3142b8cc",
"body": "… once\n\nprocess() sorted the delta set by path depth twice — once over the full\npre-collapse set and again over the collapsed result — and each comparator\nrecomputed path.split(\"/\") on both operands, so every comparison re-split two\npaths (O(n log n) splits per sort).\n\ncollapseDeltas only filters su\n[…]\n) with a\ndeep-first add subtree (raw emission depth-descending) so the depth-ascending\ncontract fails without the final sort, and asserts a child delete still folds\ninto its ancestor directory delete.",
"is_bot": false,
"headline": "perf: collapse the two delta depth-sorts into one and split each path…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T03:32:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1bebcdf75833e0eafef7e5e199031612135b9d1f",
"body": "getDirectoryTree() mapped every glob entry to a promise up front, so a tree\nwith N entries launched all N lstat/access operations and allocated N pending\npromises and in-flight stat results at once — an O(N) peak-memory spike on top\nof the unavoidable result tree, plus unbounded pressure on the libu\n[…]\nueued.\n\nRegression: tests/scenarios/zm-scan-concurrency.test.ts wraps the per-entry\nlstat and asserts peak in-flight stat ops never exceed the bound (the buggy\nfan-out peaked at the full entry count).",
"is_bot": false,
"headline": "perf: bound the local scan's stat fan-out to fixed-size batches",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T03:21:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "34509142c92e4ca4bedee9aca01bb185ca02a0b9",
"body": "…Clone\n\nEvery change-cycle deep-cloned BOTH the local and remote trees via\nstructuredClone to form the next cycle's base. That copied every item\nobject on every cycle — O(tree) CPU and a second full copy of the tree in\nmemory — when the only isolation actually required is at the MAP level.\n\nThe dire\n[…]\ny suites (mocked + live) exercise exactly this cross-cycle base\ncorrectness and stay green, plus state/property/resilience e2e (19 live\ncycles' worth) confirm no base corruption over many real cycles.",
"is_bot": false,
"headline": "perf: snapshot the cycle base with a shallow map copy, not structured…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T03:04:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fa4d23887f6f72feb0a115afb6f1ffd3537dc29f",
"body": "…sToState\n\napplyDoneTasksToState walked the ENTIRE tree (and every cached hash/inode)\nfor every done task to relocate/purge descendants — including file renames\nand deletes, which have no descendants. Across a cycle that renames or\ndeletes many scattered files that is O(tasks * tree): super-linear f\n[…]\nr tasks run. This fixes the\ninefficiency the audit identified so the (still unit-tested) helper is\ncorrect and linear if ever re-enabled; there is no runtime change today and\nhence no e2e counterpart.",
"is_bot": false,
"headline": "perf: skip whole-tree descendant scan for file tasks in applyDoneTask…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:58:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "96a8ec7e81b8a8b74f16e1df0523bf9b5ddd5b3a",
"body": "collapseDeltas scanned ALL renamed/deleted directories for every delta to\nfind each child's nearest enclosing ancestor, and rebasePathAcrossRenames\nscanned ALL renames for every tree entry. A directory move emits a delta\nand a rename per descendant, so both were O(entries * directories *\npathLength)\n[…]\nAdded a 30k-delta\nscale test that pins the linear output and trips the runner timeout if the\nquadratic scan ever returns. Correctness re-verified against the live\nbackend (dir move/rename/delete e2e).",
"is_bot": false,
"headline": "perf: index renamed/deleted dirs to make dir-move delta collapse linear",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:51:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2e5e1c67501ae697f834d2163e1991e7b34a25f4",
"body": "No-op and idempotency assertions used transferOps(), which only sees file\nup/downloads and is blind to spurious renames, deletes, and directory\ncreates. A wrong post-restart base re-derivation that renamed or deleted a\npath — exactly the failure these tests guard against — slipped straight\nthrough.\n\n[…]\nnd (state/sync/resilience/lifecycle/platform/property e2e — 44 tests)\nand the full mocked suite (534): every settled, post-restart, and\nidempotent cycle genuinely performs zero operations of any kind.",
"is_bot": false,
"headline": "test: assert complete no-ops (all task categories), not just transfers",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:29:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "adba0f87736e53e832326e8a06c23ea9c7bc2df6",
"body": "deltas.process() is async (it awaits a content hash on the same-size /\nnewer-mtime path) and read this.sync.mode in ~20 places across its passes.\nupdateMode() mutates sync.mode synchronously from the main thread at any\ntime, so a mode switch landing during one of those awaits split a single\ncycle ac\n[…]\ncycle. Task execution reads no mode, so it needs\nno snapshot.\n\nVerified RED->GREEN by flipping the mode inside the one awaited dependency\n(createFileHash) in tests/scenarios/zl-mode-atomicity.test.ts.",
"is_bot": false,
"headline": "fix: compute a cycle's deltas under a single mode snapshot",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:18:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a07f9b85d429447aeb051772896ef46aa099b8c",
"body": "isValidPath's win32 branch checked illegal characters and reserved device\nnames but accepted a component ending in '.' or ' '. Windows silently\nstrips trailing dots and spaces, so such a file would be created on disk\nunder a different name than the engine recorded — the next scan sees a\nmissing reco\n[…]\ner-OS path rule (win32 branch only); verified RED->GREEN in the\ncross-platform unit suite via stubbed process.platform, which the\nmatrixed CI also runs natively on Windows (tests/unit/n-unit.test.ts).",
"is_bot": false,
"headline": "fix: reject Windows paths ending in a dot or space",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:09:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d28ee3970f6326405129730683d675f3a6cef489",
"body": "…oved\n\nThe twoWay remote-deletions pass had no ignore/error guard, while the\nsymmetric local-deletions pass skips ignored and errored paths (BUG-006).\nSo when a path that is present on disk but excluded from the scanned tree\n— an over-long name, an invalid path, a default-ignore that grew across\nan \n[…]\n already\nexcludes ignored/errored paths, so it needed no change.\n\nVerified RED->GREEN by driving deltas.process() directly with an injected\nignored entry (tests/scenarios/zk-ignore-asymmetry.test.ts).",
"is_bot": false,
"headline": "fix: do not delete a locally-ignored file when its remote copy is rem…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T02:07:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82aa35401ff8f36501ef921389e10959c6b8c203",
"body": "Two issues in the local-trash cleanup (sync.ts):\n\nM2: the 30-day eviction sweep globbed with onlyFiles:true, so it skipped\nevery directory in the trash. Deletes move a removed directory into the\ntrash wholesale (by basename), so it lands as a top-level directory — and\nwith deep:0 the sweep could not\n[…]\ncal-only (a folder on disk + a client timer), so no backend role — the\nmocked-only boundary is documented in the e2e regressions header.\nVerified RED->GREEN in the mocked suite (tests/scenarios/zj-*).",
"is_bot": false,
"headline": "fix: evict trashed directories and tear down the local-trash sweep timer",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:58:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2de9fd861baa729beb3b719cfdc7dd0d25b356ee",
"body": "The loadPreviousTrees completeness gate checked previousRemoteTreePath\ntwice and never previousLocalINodesPath, even though the inodes file is\nread unconditionally right after. A missing or partially-written inodes\nsibling (e.g. an interrupted state write) passed the gate and then threw\nENOENT mid-l\n[…]\n\n\nRequire all four persisted files to exist; otherwise treat the saved\nstate as empty. Verified RED->GREEN in both the mocked suite and against\nthe live backend (restart with the inodes file removed).",
"is_bot": false,
"headline": "fix: treat a missing local-inodes state file as no saved state",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:49:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0896b57b01a2b77f9b7e44b7c4e64ad3676af678",
"body": "…ts retry\n\nThe local smoke test retries every SYNC_INTERVAL for as long as the local\nsync root is unavailable (an unmounted drive, a disconnected network\nfilesystem). It ran AFTER the lock was acquired, so the entire outage held\nthe account lock and starved every other device on the account.\n\nRun th\n[…]\n lock is NOT acquired while the smoke test keeps\nfailing (then proceeds on recovery); RED with the smoke test under the lock.\nMocked-only: this is lock ordering during a LOCAL outage, no backend role.",
"is_bot": false,
"headline": "fix: run the local smoke test before acquiring the lock; de-recurse i…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:43:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd949016c594d3faff21cd4d0126b518ff26f8bd",
"body": "…emoved\n\nThe large-deletion confirmation gate blocks the cycle on a 1s poll loop\nuntil the user answers — while HOLDING the sync lock. The loop only checked\nthe confirmation result, so pausing or removing the pair while it waited\n(or a user who simply never answers) left it spinning forever, holding\n[…]\nied); RED without the fix (the capped tick loop fails fast\ninstead of hanging). Mocked-only: the bail is client-side control flow with\nno backend role — the gate itself is covered live in confirm.e2e.",
"is_bot": false,
"headline": "fix: bail the deletion-confirmation wait when the pair is paused or r…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:36:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b371ae56fba93e4053931c101a99eda4fc2cdc8c",
"body": "…e kept\n\nWhen one side deleted a directory while the other added (or kept a\nmodified) child inside it in the same cycle, the raw delta set held both\ndeleteXDirectory <dir> and the child's own add. collapseDeltas subsumed the\nchild's sibling deletes under the dir-delete, and the dir-delete then wiped\n[…]\nst still delete the dir), direct unit\ncoverage of the new directoriesWithSurvivingChildren helper, and live\ne2e regressions in both directions. All existing rename/move scenarios\n(Z, E, R) stay green.",
"is_bot": false,
"headline": "fix: don't cascade a directory delete over a live child the other sid…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:32:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d8d7d2f4ddaa4ee8cef536ad3dc0a8d1f174eb2e",
"body": "isNameOverMaxLength / isPathOverMaxLength counted String.length (UTF-16\ncode units) on every platform, but the limits are not all in code units:\n\n - Linux NAME_MAX is 255 BYTES and PATH_MAX is 4096 BYTES.\n - macOS PATH_MAX is 1024 BYTES (verified: a 473-unit / 1273-byte path\n is ENAMETOOLONG) —\n[…]\n guards across platforms (Category N multibyte cases), mocked Category\nAC (linux skips a 300-byte name as nameLength, darwin syncs it), and the\nlive cross-platform e2e (asserted per matrix-runner OS).",
"is_bot": false,
"headline": "fix: measure filename/path length in the unit each OS actually uses",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:16:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "84519a4ca91f1fbe9b42d3c632a8a1ca6d06f44a",
"body": "…t lost\n\ngetDirectoryTree() skips a rescan while lastDirectoryChangeTimestamp <\ncache.timestamp. The cache was stamped when the walk ENDED, so a file\nedited after the engine lstat'd it but before the walk returned recorded\na change time earlier than the stamp — the next cycle then judged the\ncache f\n[…]\nt is RED with the old stamp and GREEN with the fix. No e2e\ncounterpart: a read-during-scan race can't be made deterministic against\na real filesystem without flakiness (documented in regressions.e2e).",
"is_bot": false,
"headline": "fix: stamp the local scan cache at walk start so a mid-scan edit isn'…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:09:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f8de7b674a447c4e2a6dc6a33edc158b52d414c",
"body": "…mtime\n\nIn twoWay the download gate's remoteWins term applied the newer-mtime\ntiebreak unconditionally. That tiebreak only resolves a CONFLICT (both\nsides changed), but it also gated the no-conflict case: when ONLY the\nremote changed (local untouched since the base) a remote edit whose\nwhole-second \n[…]\nited conflict control that must still resolve local-newer-wins);\nplus the live-backend e2e regression suite, which also backfills the C1\nmove-into-a-new-nested-dir regression against the real backend.",
"is_bot": false,
"headline": "fix: pull a remote change onto an unchanged local copy regardless of …",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T01:01:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "343829731cebc3b25f1936ce2b34ca9f0d3d62de",
"body": "…orever)\n\nWhen the last holder released and the server releaseResourceLock call\nfailed, release() restored acquiredCount to >= 1 so the holder could\n'retry' — but the holder is already gone. The count never returned to 0\nagain, so every later acquire/release pair just oscillated above 0, the\nrelease\n[…]\nd\nhold.\n\nRewrites the lock unit tests to pin the corrected invariant (refresh stops\nafter a failed release; the held state resets so the next acquire is a real\nserver acquire, not a re-entrant no-op).",
"is_bot": false,
"headline": "fix: release the lock unconditionally on the final release (no held-f…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T00:52:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72cc4523fb934b0fab5bc6d787d55610bdba729c",
"body": "…vel remote ops\n\nremote.mkdir() could not create a directory whose missing parent is the\nsync root: the intermediate-directory loop hit the `!parentItem continue`\nguard before the `parentIsBase` branch that supplies remoteParentUUID, so\nmkdir('/x/y') threw whenever '/x' did not already exist. It als\n[…]\n-level file's parent to remoteParentUUID. Adds\ncategory ZE regression tests (2-/3-level moves, directory move, mirror\nmode, and a transient top-level rename error that must surface, not be\nswallowed).",
"is_bot": false,
"headline": "fix: create nested dirs from sync root; stop swallowing failed top-le…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-28T00:43:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e09dab763022caa1aa096e01e99a638535456b81",
"body": "…trols\n\nTwo mocked tests failed only on the Windows CI runner because they fed\nengine-computed paths (built with the host path.join, so backslash-separated\non Windows) into places that expect posix:\n\n- m-golden M2 pinned the state layout with hardcoded '/state/v2/' and read the\n persisted files thr\n[…]\nix literals other tests pass, so no\n behavior change on macOS/Linux.\n\nVerified: full mocked suite 493/44 green on macOS; win32 path normalization\nchecked by simulation (keys match, layout pins hold).",
"is_bot": false,
"headline": "test: fix Windows path-separator portability in golden pin + fake con…",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-27T23:13:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f5eb24bbd9fbf0cc8bd5717f983f83cae350c985",
"body": "The local rename pass keys on inode: an inode that sat at path P in the base\nbut now sits at path Q is treated as a rename P->Q and propagated as a remote\nrename. But the OS recycles inode numbers -- ext4 hands a just-freed inode to\nthe very next created file -- so deleting a.txt and creating c.txt \n[…]\nrename, no re-upload), using a new fake-fs controls.setInode(path, ino) to force\nthe reuse memfs will not produce on its own. ZD1/ZD2 are RED without the fix.\nThe live regression is I6 itself on ext4.",
"is_bot": false,
"headline": "fix: don't mistake inode reuse for a rename (silent data loss on ext4)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-27T22:57:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b81c0aa543322315e01a70e9d37c0cae8a8337f1",
"body": "Extends `testTimeout`, `hookTimeout`, and `teardownTimeout` in `vitest.e2e.config.ts` to 3,600,000ms to better accommodate slow CI and long-running end-to-end transfers. Also reformats dotenv value parsing into a multi-line chain for readability without changing behavior.",
"is_bot": false,
"headline": "test: increase e2e Vitest timeouts to 1 hour",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-27T21:58:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d01e4d245fb71c37916ce98e6efe9efe0bc20ec1",
"body": "The lint script wrapped its globs in single quotes (eslint 'src/**/*.ts'\n'tests/**/*.ts'). Unix shells strip single quotes and let ESLint expand the\nglobs, but Windows cmd.exe treats them as literal characters, so ESLint\nsearches for a file literally named 'src/**/*.ts', matches nothing, and the\nbui\n[…]\nt step. Double quotes are stripped by both cmd.exe and\nsh, so ESLint receives the bare patterns and expands them itself on every\nplatform. Behavior on macOS/Linux is unchanged (still 86 files linted).",
"is_bot": false,
"headline": "fix: make the lint script cross-platform (double-quote globs)",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-27T21:57:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "482cb44361dc5669d3854d53e8e9229e51d3716d",
"body": "The engine has no write-ahead log; crash-safety rests on one invariant:\nthe persisted base advances only after a cycle with zero task errors, so a\nkill (or a user stop, which aborts in-flight transfers) mid-cycle leaves\nthe on-disk base at the last clean cycle while the fs/remote may already be\npart\n[…]\nartial state. Add two live\nstate.e2e counterparts (un-synced changes on both sides, and an un-synced\nrename, surviving a restart). Distinct from Category S, which restarts only\nbetween settled cycles.",
"is_bot": false,
"headline": "test: cover crash / stop mid-run recovery",
"author_name": "Dwynr",
"author_login": "Dwynr",
"committed_at": "2026-06-27T21:38:10Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 100,
"commits_last_year": 164,
"latest_release_at": "2026-07-19T11:55:40Z",
"latest_release_tag": "v0.3.7",
"releases_from_tags": false,
"days_since_last_push": 5,
"active_weeks_last_year": 5,
"days_since_latest_release": 5,
"mean_days_between_releases": 58.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@filen/sync",
"exists": true,
"license": "AGPLv3",
"keywords": [
"filen"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@filen/sync",
"is_deprecated": false,
"latest_version": "0.3.7",
"repository_url": "https://github.com/FilenCloudDienste/filen-sync",
"versions_count": 108,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2802,
"first_published_at": "2024-05-29T17:07:40.781000Z",
"latest_published_at": "2026-07-19T11:56:04.864000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 2,
"stars": 16,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-02-21",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": null,
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 90826,
"source_files_sampled": 241,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "axios",
"direct": false,
"version": "0.28.1",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 8.6,
"advisory_ids": [
"GHSA-3g43-6gmg-66jw",
"GHSA-3p68-rc4w-qgx5",
"GHSA-42h9-826w-cgv3",
"GHSA-43fc-jf86-j433",
"GHSA-4hjh-wcwx-xvwj",
"GHSA-5c9x-8gcm-mpgx",
"GHSA-62hf-57xw-28j9",
"GHSA-6chq-wfr3-2hj9",
"GHSA-7q8q-rj6j-mhjq",
"GHSA-898c-q2cr-xwhg"
],
"fixed_version": "1.18.0",
"advisory_count": 25,
"oldest_advisory_days": 504
},
{
"name": "elliptic",
"direct": false,
"version": "6.5.7",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-848j-6mx2-7j84",
"GHSA-fc9h-whq2-v747",
"GHSA-vjh7-7g9h-fjfh"
],
"fixed_version": "6.6.1",
"advisory_count": 3,
"oldest_advisory_days": 647
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 2
},
"advisory_count": 28,
"affected_count": 2,
"assessed_count": 128,
"malicious_count": 0,
"assessed_package": "npm:@filen/sync@0.3.7",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@filen/sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.4.2"
},
{
"name": "fast-glob",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.3.3"
},
{
"name": "fs-extra",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^11.3.0"
},
{
"name": "ignore",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^7.0.3"
},
{
"name": "micromatch",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.8"
},
{
"name": "msgpackr",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.4"
},
{
"name": "pino",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^9.5.0"
},
{
"name": "rotating-file-stream",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.2.5"
},
{
"name": "uuid",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^11.0.5"
},
{
"name": "write-file-atomic",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@filen/sdk",
"direct": true,
"version": "0.4.2",
"ecosystem": "npm"
},
{
"name": "fast-glob",
"direct": true,
"version": "3.3.3",
"ecosystem": "npm"
},
{
"name": "fs-extra",
"direct": true,
"version": "11.3.5",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": true,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": true,
"version": "7.0.5",
"ecosystem": "npm"
},
{
"name": "micromatch",
"direct": true,
"version": "4.0.8",
"ecosystem": "npm"
},
{
"name": "msgpackr",
"direct": true,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "pino",
"direct": true,
"version": "9.14.0",
"ecosystem": "npm"
},
{
"name": "rotating-file-stream",
"direct": true,
"version": "3.2.9",
"ecosystem": "npm"
},
{
"name": "uuid",
"direct": true,
"version": "11.1.1",
"ecosystem": "npm"
},
{
"name": "write-file-atomic",
"direct": true,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@bcoe/v8-coverage",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@cspotcode/source-map-support",
"direct": false,
"version": "0.8.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/runtime",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/eslint-utils",
"direct": false,
"version": "4.9.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/regexpp",
"direct": false,
"version": "4.12.2",
"ecosystem": "npm"
},
{
"name": "@eslint/config-array",
"direct": false,
"version": "0.23.5",
"ecosystem": "npm"
},
{
"name": "@eslint/config-helpers",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "@eslint/core",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@eslint/eslintrc",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "10.0.1",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "8.57.1",
"ecosystem": "npm"
},
{
"name": "@eslint/object-schema",
"direct": false,
"version": "3.0.5",
"ecosystem": "npm"
},
{
"name": "@eslint/plugin-kit",
"direct": false,
"version": "0.7.2",
"ecosystem": "npm"
},
{
"name": "@hapi/hoek",
"direct": false,
"version": "9.3.0",
"ecosystem": "npm"
},
{
"name": "@hapi/topo",
"direct": false,
"version": "5.1.0",
"ecosystem": "npm"
},
{
"name": "@humanfs/core",
"direct": false,
"version": "0.19.2",
"ecosystem": "npm"
},
{
"name": "@humanfs/node",
"direct": false,
"version": "0.16.8",
"ecosystem": "npm"
},
{
"name": "@humanfs/types",
"direct": false,
"version": "0.15.0",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/config-array",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/module-importer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/object-schema",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/retry",
"direct": false,
"version": "0.4.3",
"ecosystem": "npm"
},
{
"name": "@isaacs/cliui",
"direct": false,
"version": "8.0.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/base64",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/base64",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/buffers",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/buffers",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/codegen",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/codegen",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-core",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-fsa",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-node",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-node-builtins",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-node-to-fsa",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-node-utils",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-print",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/fs-snapshot",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/json-pack",
"direct": false,
"version": "1.21.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/json-pack",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/json-pointer",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/json-pointer",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/util",
"direct": false,
"version": "1.9.0",
"ecosystem": "npm"
},
{
"name": "@jsonjoy.com/util",
"direct": false,
"version": "17.67.0",
"ecosystem": "npm"
},
{
"name": "@microsoft/eslint-formatter-sarif",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-darwin-arm64",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-darwin-x64",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-linux-arm",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-linux-arm64",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-linux-x64",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@msgpackr-extract/msgpackr-extract-win32-x64",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@napi-rs/wasm-runtime",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "@noble/hashes",
"direct": false,
"version": "1.8.0",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.scandir",
"direct": false,
"version": "2.1.5",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.stat",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.walk",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "@oxc-project/types",
"direct": false,
"version": "0.137.0",
"ecosystem": "npm"
},
{
"name": "@pinojs/redact",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "@pkgjs/parseargs",
"direct": false,
"version": "0.11.0",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-android-arm64",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-arm64",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-x64",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-freebsd-x64",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm-gnueabihf",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-gnu",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-musl",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-ppc64-gnu",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-s390x-gnu",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-gnu",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-musl",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-openharmony-arm64",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-wasm32-wasi",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-arm64-msvc",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-x64-msvc",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/pluginutils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@sideway/address",
"direct": false,
"version": "4.1.5",
"ecosystem": "npm"
},
{
"name": "@sideway/formula",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "@sideway/pinpoint",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "@standard-schema/spec",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node10",
"direct": false,
"version": "1.0.12",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node12",
"direct": false,
"version": "1.0.11",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node14",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node16",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "@tybys/wasm-util",
"direct": false,
"version": "0.10.3",
"ecosystem": "npm"
},
{
"name": "@types/braces",
"direct": false,
"version": "3.0.5",
"ecosystem": "npm"
},
{
"name": "@types/chai",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/deep-eql",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "@types/esrecurse",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/fs-extra",
"direct": false,
"version": "11.0.4",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/jsonfile",
"direct": false,
"version": "6.1.4",
"ecosystem": "npm"
},
{
"name": "@types/micromatch",
"direct": false,
"version": "4.0.10",
"ecosystem": "npm"
},
{
"name": "@types/mime-types",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "26.0.1",
"ecosystem": "npm"
},
{
"name": "@types/uuid",
"direct": false,
"version": "10.0.0",
"ecosystem": "npm"
},
{
"name": "@types/write-file-atomic",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/eslint-plugin",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/parser",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/project-service",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/scope-manager",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/tsconfig-utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/type-utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/types",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/typescript-estree",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/visitor-keys",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@ungap/structured-clone",
"direct": false,
"version": "1.3.2",
"ecosystem": "npm"
},
{
"name": "@vitest/coverage-v8",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.17.0",
"ecosystem": "npm"
},
{
"name": "acorn-jsx",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "acorn-walk",
"direct": false,
"version": "8.3.5",
"ecosystem": "npm"
},
{
"name": "agent-base",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "agentkeepalive",
"direct": false,
"version": "4.6.0",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "6.15.0",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "6.2.3",
"ecosystem": "npm"
},
{
"name": "arg",
"direct": false,
"version": "4.1.3",
"ecosystem": "npm"
},
{
"name": "argparse",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "asn1.js",
"direct": false,
"version": "5.4.1",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "ast-v8-to-istanbul",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "asynckit",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "atomic-sleep",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "axios",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "axios",
"direct": false,
"version": "1.18.1",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "base64-js",
"direct": false,
"version": "1.5.1",
"ecosystem": "npm"
},
{
"name": "bn.js",
"direct": false,
"version": "4.12.4",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "1.1.15",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "5.0.6",
"ecosystem": "npm"
},
{
"name": "braces",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "brorand",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "buffer",
"direct": false,
"version": "6.0.3",
"ecosystem": "npm"
},
{
"name": "call-bind-apply-helpers",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "callsites",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "charenc",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "color-convert",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "color-name",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "combined-stream",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "concat-map",
"direct": false,
"version": "0.0.1",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "core-util-is",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "create-require",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "cross-env",
"direct": false,
"version": "7.0.3",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "crypt",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "crypto-api-v1",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "crypto-js",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "deep-is",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "delayed-stream",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "des.js",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "detect-libc",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "diff",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "doctrine",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "dotenv",
"direct": false,
"version": "16.6.1",
"ecosystem": "npm"
},
{
"name": "dunder-proto",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "eastasianwidth",
"direct": false,
"version": "0.2.0",
"ecosystem": "npm"
},
{
"name": "elliptic",
"direct": false,
"version": "6.5.7",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "9.2.2",
"ecosystem": "npm"
},
{
"name": "es-define-property",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "es-errors",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "es-object-atoms",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "es-set-tostringtag",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "10.6.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "8.57.1",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "7.2.2",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "9.1.2",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "11.2.0",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "9.6.1",
"ecosystem": "npm"
},
{
"name": "esquery",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "esrecurse",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "estraverse",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "esutils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "eventemitter3",
"direct": false,
"version": "5.0.4",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-json-stable-stringify",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "fast-levenshtein",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "fastq",
"direct": false,
"version": "1.20.1",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "fill-range",
"direct": false,
"version": "7.1.1",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "flatted",
"direct": false,
"version": "3.4.2",
"ecosystem": "npm"
},
{
"name": "follow-redirects",
"direct": false,
"version": "1.16.0",
"ecosystem": "npm"
},
{
"name": "foreground-child",
"direct": false,
"version": "3.3.1",
"ecosystem": "npm"
},
{
"name": "form-data",
"direct": false,
"version": "4.0.6",
"ecosystem": "npm"
},
{
"name": "fs.realpath",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "function-bind",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "get-intrinsic",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "get-proto",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "glob",
"direct": false,
"version": "10.5.0",
"ecosystem": "npm"
},
{
"name": "glob",
"direct": false,
"version": "7.2.3",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "glob-to-regex.js",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "13.24.0",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "17.7.0",
"ecosystem": "npm"
},
{
"name": "gopd",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "graceful-fs",
"direct": false,
"version": "4.2.11",
"ecosystem": "npm"
},
{
"name": "graphemer",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "has-symbols",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "has-tostringtag",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "hash.js",
"direct": false,
"version": "1.1.7",
"ecosystem": "npm"
},
{
"name": "hasown",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "hmac-drbg",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "html-escaper",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "https-proxy-agent",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "humanize-ms",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "hyperdyperid",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "ieee754",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "import-fresh",
"direct": false,
"version": "3.3.1",
"ecosystem": "npm"
},
{
"name": "imurmurhash",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "inflight",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "inherits",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "is-buffer",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "is-extglob",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "is-glob",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "is-number",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "is-path-inside",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "isarray",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-coverage",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-report",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-reports",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "jackspeak",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "joi",
"direct": false,
"version": "17.13.4",
"ecosystem": "npm"
},
{
"name": "js-crypto-aes",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "js-crypto-env",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "js-crypto-hash",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "js-crypto-hmac",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "js-crypto-key-utils",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "js-crypto-pbkdf",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "js-crypto-random",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "js-encoding-utils",
"direct": false,
"version": "0.7.3",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "10.0.0",
"ecosystem": "npm"
},
{
"name": "js-xxhash",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "jschardet",
"direct": false,
"version": "3.1.4",
"ecosystem": "npm"
},
{
"name": "json-buffer",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "json-stable-stringify-without-jsonify",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "jsonfile",
"direct": false,
"version": "6.2.1",
"ecosystem": "npm"
},
{
"name": "keyv",
"direct": false,
"version": "4.5.4",
"ecosystem": "npm"
},
{
"name": "levn",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "lodash",
"direct": false,
"version": "4.18.1",
"ecosystem": "npm"
},
{
"name": "lodash.clonedeep",
"direct": false,
"version": "4.5.0",
"ecosystem": "npm"
},
{
"name": "lodash.merge",
"direct": false,
"version": "4.6.2",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "10.4.3",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "magicast",
"direct": false,
"version": "0.5.3",
"ecosystem": "npm"
},
{
"name": "make-dir",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "make-error",
"direct": false,
"version": "1.3.6",
"ecosystem": "npm"
},
{
"name": "math-intrinsics",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "md5",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "memfs",
"direct": false,
"version": "4.57.8",
"ecosystem": "npm"
},
{
"name": "merge2",
"direct": false,
"version": "1.4.1",
"ecosystem": "npm"
},
{
"name": "mime-db",
"direct": false,
"version": "1.52.0",
"ecosystem": "npm"
},
{
"name": "mime-types",
"direct": false,
"version": "2.1.35",
"ecosystem": "npm"
},
{
"name": "minimalistic-assert",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "minimalistic-crypto-utils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "10.2.5",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "3.1.5",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "9.0.9",
"ecosystem": "npm"
},
{
"name": "minimist",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "minipass",
"direct": false,
"version": "7.1.3",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "msgpackr-extract",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.15",
"ecosystem": "npm"
},
{
"name": "natural-compare",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "node-forge",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "node-gyp-build-optional-packages",
"direct": false,
"version": "5.2.2",
"ecosystem": "npm"
},
{
"name": "obug",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "on-exit-leak-free",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "once",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "optionator",
"direct": false,
"version": "0.9.4",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "package-json-from-dist",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "parent-module",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "path-exists",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "path-is-absolute",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "path-scurry",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "2.3.2",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "pino-abstract-transport",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "pino-std-serializers",
"direct": false,
"version": "7.1.0",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.15",
"ecosystem": "npm"
},
{
"name": "prelude-ls",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "process-nextick-args",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "process-warning",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "progress-stream",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "proxy-from-env",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "proxy-from-env",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "punycode",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "queue-microtask",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "quick-format-unescaped",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "readable-stream",
"direct": false,
"version": "2.3.8",
"ecosystem": "npm"
},
{
"name": "real-require",
"direct": false,
"version": "0.2.0",
"ecosystem": "npm"
},
{
"name": "resolve-from",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "reusify",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "rimraf",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "rimraf",
"direct": false,
"version": "5.0.10",
"ecosystem": "npm"
},
{
"name": "rolldown",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "run-parallel",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "rxjs",
"direct": false,
"version": "7.8.2",
"ecosystem": "npm"
},
{
"name": "safe-buffer",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "safe-stable-stringify",
"direct": false,
"version": "2.5.0",
"ecosystem": "npm"
},
{
"name": "safer-buffer",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.5",
"ecosystem": "npm"
},
{
"name": "sha3",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "signal-exit",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "sonic-boom",
"direct": false,
"version": "4.2.1",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "speedometer",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "split2",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "4.2.3",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "string_decoder",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "strip-json-comments",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "striptags",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "text-table",
"direct": false,
"version": "0.2.0",
"ecosystem": "npm"
},
{
"name": "thingies",
"direct": false,
"version": "2.6.0",
"ecosystem": "npm"
},
{
"name": "thread-stream",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "through2",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "to-regex-range",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "tree-dump",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "ts-api-utils",
"direct": false,
"version": "2.5.0",
"ecosystem": "npm"
},
{
"name": "ts-node",
"direct": false,
"version": "10.9.2",
"ecosystem": "npm"
},
{
"name": "tslib",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "tsx",
"direct": false,
"version": "4.22.4",
"ecosystem": "npm"
},
{
"name": "type-check",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "0.20.2",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
},
{
"name": "typescript-eslint",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "8.3.0",
"ecosystem": "npm"
},
{
"name": "universalify",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "uri-js",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "utf8",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "util-deprecate",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "v8-compile-cache-lib",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.1.0",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "wait-on",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "word-wrap",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "8.1.0",
"ecosystem": "npm"
},
{
"name": "wrappy",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "xtend",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "yn",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "yocto-queue",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 455,
"direct_count": 11,
"indirect_count": 444
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 3,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 59
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "Dwynr",
"commits": 310,
"avatar_url": "https://avatars.githubusercontent.com/u/14013321?v=4"
},
{
"type": "User",
"login": "szapp",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/20203034?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.997
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codeql.yml",
"e2e.yml",
"eslint.yml",
"npmPublish.yml",
"test.yml"
],
"has_docs_dir": false,
"linter_configs": [
"eslint.config.mjs"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 1,
"reason": "dependency not pinned by hash detected -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool detected: CodeQL",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "32 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "0d025bae60f493a42c2f49a4fcbbb46a31bea4ab",
"ran_at": "2026-07-25T09:11:06Z",
"aggregate_score": 5.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-19T11:56:08Z",
"oldest_open_prs": [
{
"number": 66,
"created_at": "2026-07-22T17:29:18Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2024-12-13T03:15:23Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/FilenCloudDienste/filen-sync",
"host": "github.com",
"name": "filen-sync",
"owner": "FilenCloudDienste"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"security": 56,
"vitality": 78,
"community": 40,
"governance": 44,
"engineering": 78
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 78,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"commits_last_year": 164,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 5
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "5/52 weeks with commits",
"points": 3.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 5
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "164 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 164
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 92,
"inputs": {
"releases_count": 100,
"latest_release_tag": "v0.3.7",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 58.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~58.3 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 58.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 6,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 6 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 6
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 40,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"forks": 2,
"stars": 16,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "16 stars",
"points": 19.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 16
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (AGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "AGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 58,
"inputs": {
"packages": [
"@filen/sync"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2802
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,802 downloads/month across npm",
"points": 46,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2802,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 44,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 18,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.997
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 4,
"inputs": {
"merged_prs": 3,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 59
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "3/62 decided PRs merged",
"points": 1.9,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 3,
"decided": 62
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"followers": 826,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "FilenCloudDienste",
"public_repos": 26,
"account_age_days": 1809
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "826 followers of FilenCloudDienste",
"points": 21,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 826,
"login": "FilenCloudDienste"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "26 public repos, account ~4 yr old",
"points": 20.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 26
}
},
{
"code": "account_age_years",
"params": {
"years": 4
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@filen/sync"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "108 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 108
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 78,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.mjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"cloud",
"filen",
"sync"
],
"has_wiki": true,
"homepage": "https://filen.io",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://filen.io",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "3 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 3
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 56,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 52,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 5.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool detected: CodeQL",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "32 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "good",
"name": "Dependency advisories",
"note": "Matched the npm:@filen/sync@0.3.7 runtime dependency closure — what installing the published package pulls in — 128 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@filen/sync@0.3.7",
"assessed": 128
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 70,
"inputs": {
"source": "osv",
"advisories": 28,
"affected_packages": 2,
"assessed_packages": 128,
"unassessed_packages": 0,
"affected_by_severity": "high 2",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "2 affected: axios 0.28.1 (high 8.6), elliptic 6.5.7 (high 7.5)",
"points": 6.6,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 2,
"packages": "axios 0.28.1 (high 8.6), elliptic 6.5.7 (high 7.5)"
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "2 advisory-carrying package(s) unaddressed past 90 days; oldest published 647 days ago",
"points": 28.5,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 2,
"oldest": 647
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 128,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 4
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 58,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.mjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 1,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 90826,
"source_files_sampled": 241,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/241 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 241,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-25T09:11:11.546977Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/FilenCloudDienste/filen-sync.svg",
"full_name": "FilenCloudDienste/filen-sync",
"license_state": "standard",
"license_spdx": "AGPL-3.0"
}