公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 02:07 UTC

Gitlawb / zero

The coding agent that answers to you, your model, your machine, your rules.

GoMIT★ 1,104 星标⑂ 110 复刻始于 2026年5月在 GitHub 上查看 ↗

Gitlawb/zero 的健康指数为 100 分中的 73 分,处于「良好」区间。 其得分最高的类别是AI Readiness(86/100),最低的是Security(62/100)。 最近一次更新在今天。 近期的大部分工作由 2 位贡献者完成。

73
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

73
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Gitlawb组织
932 关注者17 个公开仓库始于 2026年3月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/Gitlawb/zerov0.5.0-50 天前
npm@gitlawb/zero0.5.03,240160 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

72良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
5.5/36提交节奏 — 52 周中有 8 周有提交
18/18提交量 — 最近一年 587 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year587
human_commit_share0.97
days_since_last_push0
active_weeks_last_year8

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 5 个发布版本
36/36发布时效 — 最近一次发布版本于 0 天前
27/27发布节奏 — 约每 4.9 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count5
latest_release_tagv0.5.0
releases_from_tags
days_since_latest_release0
mean_days_between_releases4.9

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

74良好 · 占总体的 18%
评分方式
49.4/60星标 — 1,104 个星标
17/25复刻 — 110 个复刻
1.7/15关注者 — 3 位关注者
所用输入
forks110
stars1,104
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonwindow_too_short

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
46.8/80月度下载量 — go, npm 合计每月 3,240 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesgithub.com/Gitlawb/zero, @gitlawb/zero
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads3,240
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

73良好 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
14.5/22.5提交分布 — 头号贡献者编写了 35% 的提交
13.5/13.5贡献者广度 — 28 位贡献者
6/10OpenSSF Scorecard:Contributors — project has 2 contributing companies or organizations -- score normalized to 6
所用输入
bus_factor2
contributors_sampled28
top_contributor_share0.354
评分方式
31.7/46.8议题解决 — 68% 的议题已关闭
34.1/38.3PR 接受 — 已裁定的 PR 中 531/595 已合并
15/15OpenSSF Scorecard:Code-Review — all changesets reviewed
所用输入
merged_prs531
open_issues46
closed_issues97
issue_closed_ratio0.678
closed_unmerged_prs64
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
21.4/25所有者影响力 — Gitlawb 有 932 位关注者
9.8/25既往记录 — 17 个公开仓库,账户约 0 年
所用输入
followers932
owner_typeOrganization
is_verified
owner_loginGitlawb
public_repos17
account_age_days127
评分方式
25/25已发布且可解析 — go, npm 上有 2 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 16 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/Gitlawb/zero, @gitlawb/zero
ecosystemsgo, npm
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

81良好 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 5 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://zero.gitlawb.com
10/10仓库描述
10/10主题标签 — 13 个主题标签
10/10Wiki
所用输入
topicsai-agent, ai, anthropic, cli, code-assistant, coding-agent, developer-tools, gemini, llm, mcp, ollama, openai, terminal
has_wiki
homepagehttps://zero.gitlawb.com
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

62中等 · 占总体的 16%

安全态势

53中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
5/5Pinned-Dependencies — all dependencies are pinned
3.5/5SAST — SAST tool is not run on all commits -- score normalized to 7
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.2
已排除计分(无数据或不适用):packaging。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages104
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 104 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

86优秀 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 97 次人类提交中有 97 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes3,827
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 7 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilesgo.sum, package-lock.json
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.07
toolchain_manifestsgo.mod, internal/agenteval/testdata/fixtures/zero-mini/go.mod, internal/perfbench/testdata/edit/go.mod, internal/perfbench/testdata/fix/go.mod, internal/perfbench/testdata/nav/go.mod, internal/perfbench/testdata/refactor/go.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.3/55可控的文件大小 — 采样的 1,231 个源文件中有 16 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes217,150
source_files_sampled1,231
oversized_source_files16

关键数据

1,104GitHub 星标
28贡献者
587最近 12 个月提交数
0距最近推送天数
5发布版本数
2巴士系数(bus factor)
46开放议题
Go, npm软件包生态系统数

数据采集警告

  • deps.dev does not index npm:@gitlawb/zero@0.5.0; advisories assessed against the repository dependency graph instead

更多细节

Star 与 Fork 历史 1,104 ★ / 110 ⇿
1,104Star
110Fork
4发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

仅显示最近的历史——该仓库超出采集窗口,因此未采集最早的历史记录。

02004006008001,0001,2001,1041104872026-072026-072026-07
主版本 0次版本 4修订 0
OpenSSF Scorecard 5.2 / 10
5.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 02:06 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
7SASTSAST tool is not run on all commits -- score normalized to 7
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
直接依赖 15
注册表软件包版本约束清单文件
Gocharm.land/bubbles/v2v2.1.1go.mod
Gocharm.land/bubbletea/v2v2.0.8go.mod
Gocharm.land/lipgloss/v2v2.0.5go.mod
Gogithub.com/alecthomas/chroma/v2v2.27.0go.mod
Gogithub.com/atotto/clipboardv0.1.4go.mod
Gogithub.com/aymanbagabas/go-udiffv0.4.1go.mod
Gogithub.com/charmbracelet/colorprofilev0.4.3go.mod
Gogithub.com/charmbracelet/x/ansiv0.11.7go.mod
Gogithub.com/charmbracelet/x/termv0.2.2go.mod
Gogithub.com/coder/websocketv1.8.15go.mod
Gogithub.com/ledongthuc/pdfv0.0.0-20250511090121-5959a4027728go.mod
Gogolang.org/x/sysv0.47.0go.mod
Gomvdan.cc/sh/v3v3.13.1go.mod
npmagent-browser^0.30.1package.json
npmtuistory^0.10.0package.json
全部依赖 104

来自 GitHub 依赖图的完整解析依赖集合:15 个直接依赖与 89 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gocharm.land/bubbles/v2v2.1.1直接
Gocharm.land/bubbletea/v2v2.0.8直接
Gocharm.land/lipgloss/v2v2.0.5直接
Gogithub.com/alecthomas/chroma/v2v2.27.0直接
Gogithub.com/atotto/clipboardv0.1.4直接
Gogithub.com/aymanbagabas/go-udiffv0.4.1直接
Gogithub.com/charmbracelet/colorprofilev0.4.3直接
Gogithub.com/charmbracelet/x/ansiv0.11.7直接
Gogithub.com/charmbracelet/x/termv0.2.2直接
Gogithub.com/coder/websocketv1.8.15直接
Gogithub.com/ledongthuc/pdfv0.0.0-20250511090121-5959a4027728直接
Gogolang.org/x/sysv0.47.0直接
Gomvdan.cc/sh/v3v3.13.1直接
npmagent-browser0.30.1直接
npmtuistory0.10.0直接
Gogithub.com/charmbracelet/ultravioletv0.0.0-20260703014108-f5a850f9c2b7间接
Gogithub.com/charmbracelet/x/exp/goldenv0.0.0-20260615092313-b57e5e6d29bb间接
Gogithub.com/charmbracelet/x/termiosv0.1.1间接
Gogithub.com/charmbracelet/x/windowsv0.2.2间接
Gogithub.com/clipperhouse/displaywidthv0.11.0间接
Gogithub.com/clipperhouse/uax29/v2v2.7.0间接
Gogithub.com/dlclark/regexp2/v2v2.5.0间接
Gogithub.com/go-quicktest/qtv1.102.0间接
Gogithub.com/lucasb-eyer/go-colorfulv1.4.0间接
Gogithub.com/mattn/go-runewidthv0.0.24间接
Gogithub.com/muesli/cancelreaderv0.2.2间接
Gogithub.com/rivo/unisegv0.4.7间接
Gogithub.com/rogpeppe/go-internalv1.15.0间接
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41e间接
Gogolang.org/x/expv0.0.0-20260611194520-c48552f49976间接
Gogolang.org/x/syncv0.22.0间接
npm@clack/core1.4.2间接
npm@clack/prompts1.6.0间接
npm@hono/node-server1.19.14间接
npm@hono/node-ws1.3.1间接
npm@opentui/core0.2.16间接
npm@opentui/core-darwin-arm640.2.16间接
npm@opentui/core-darwin-x640.2.16间接
npm@opentui/core-linux-arm640.2.16间接
npm@opentui/core-linux-x640.2.16间接
npm@opentui/core-win32-arm640.2.16间接
npm@opentui/core-win32-x640.2.16间接
npm@opentui/react0.2.16间接
npm@resvg/resvg-wasm2.6.2间接
npm@sec-ant/readable-stream0.4.1间接
npm@sindresorhus/merge-streams4.0.0间接
npmansi-regex6.2.2间接
npmbun-ffi-structs0.2.2间接
npmclone1.0.4间接
npmcross-spawn7.0.6间接
npmdefaults1.0.4间接
npmdiff9.0.0间接
npmemoji-regex10.6.0间接
npmerrore0.11.0间接
npmexeca9.6.1间接
npmfast-string-truncated-width3.0.3间接
npmfast-string-width3.0.2间接
npmfast-wrap-ansi0.2.2间接
npmfigures6.1.0间接
npmget-east-asian-width1.6.0间接
npmget-stream9.0.1间接
npmget-them-args1.3.2间接
npmghostty-opentui1.5.0间接
npmgoke6.12.3间接
npmhono4.12.27间接
npmhuman-signals8.0.1间接
npmis-plain-obj4.1.0间接
npmis-stream4.0.1间接
npmis-unicode-supported2.1.0间接
npmisexe2.0.0间接
npmkill-port-process4.0.2间接
npmmarked17.0.1间接
npmnpm-run-path6.0.0间接
npmparse-ms4.0.0间接
npmpath-key3.1.1间接
npmpath-key4.0.0间接
npmpicocolors1.1.1间接
npmpid-port2.0.1间接
npmpretty-ms9.3.0间接
npmreact19.2.7间接
npmreact-devtools-core7.0.1间接
npmreact-reconciler0.33.0间接
npmscheduler0.27.0间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmshell-quote1.9.0间接
npmsignal-exit4.1.0间接
npmsisteransi1.0.5间接
npmstd-env4.1.0间接
npmstring-dedent3.0.2间接
npmstring-width7.2.0间接
npmstrip-ansi7.1.2间接
npmstrip-final-newline4.0.0间接
npmtypescript5.9.3间接
npmunicorn-magic0.3.0间接
npmwcwidth1.0.1间接
npmweb-tree-sitter0.25.10间接
npmwhich2.0.2间接
npmws7.5.11间接
npmws8.21.0间接
npmyoctocolors2.1.2间接
npmyoga-layout3.2.1间接
npmzigpty0.2.1间接
npmzod4.3.6间接
依赖安全公告 1

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 104 个包,其中也包含从不交付的开发与测试版本固定:1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
@hono/node-server1.19.14间接12.0.5

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai-agent",
        "ai",
        "anthropic",
        "cli",
        "code-assistant",
        "coding-agent",
        "developer-tools",
        "gemini",
        "llm",
        "mcp",
        "ollama",
        "openai",
        "terminal"
      ],
      "is_fork": false,
      "size_kb": 7987,
      "has_wiki": true,
      "homepage": "https://zero.gitlawb.com",
      "languages": {
        "Go": 11160305,
        "Shell": 9514,
        "Makefile": 1846,
        "JavaScript": 43861,
        "PowerShell": 5821
      },
      "pushed_at": "2026-07-22T01:37:48Z",
      "created_at": "2026-05-28T14:11:35Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T01:37:42Z",
      "description": "The coding agent that answers to you, your model, your machine, your rules.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://gitlawb.com",
      "name": "Gitlawb",
      "type": "Organization",
      "login": "Gitlawb",
      "company": null,
      "location": null,
      "followers": 932,
      "avatar_url": "https://avatars.githubusercontent.com/u/268502891?v=4",
      "created_at": "2026-03-16T03:54:24Z",
      "is_verified": null,
      "public_repos": 17,
      "account_age_days": 127
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-22T01:37:48Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-17T05:25:43Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-09T15:19:22Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-06T03:51:15Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-02T07:20:55Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a50574f673c3cb681937f02ce5f9be86e81beba8",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.5.0 (#714)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-22T01:37:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c00a4734b5a830f861ba638388d5e0a3b361a10a",
          "body": "Co-authored-by: binyangzhu000-sudo <224954946+binyangzhu000-sudo@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Atlas Cloud provider preset (#784)",
          "author_name": "nb213",
          "author_login": "binyangzhu000-sudo",
          "committed_at": "2026-07-22T00:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2479884dea49580c853a53536c3bbab22ce8a2bf",
          "body": "* feat(plugins): add zero plugins info command\n\nAdd plugins info to inspect manifest state, extension counts, and\nlockfile source/hash with optional hash drift detection.\n\n* fix(plugins): derive lock dir from plugin install path for info\n\nRemove LockDir from InfoOptions and read the lockfile from\nfilepath.Dir(plugin.PluginDir) so lock metadata matches the resolved\nplugin location. Consolidate duplicate lock hash output lines.",
          "is_bot": false,
          "headline": "feat(plugins): add zero plugins info command (#773)",
          "author_name": "Felix-Ayush",
          "author_login": "Ayush7614",
          "committed_at": "2026-07-22T00:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab2f9fbd3e43c1665f45f73f185579cd93a65618",
          "body": "* Add shell completion generation\n\nAdd zero completions for bash, zsh, fish, PowerShell, and Elvish using one shared command tree that covers aliases, nested commands, root flags, and common exec flags.\n\nValidate missing and unsupported shell arguments as usage errors and document safe installation \n[…]\nvation.\n\nRefs #499\n\n* Fix Elvish completion syntax\n\nClose generated Elvish conditional branches, use value equality, and validate generated script structure plus native Bash and Zsh syntax.\n\nRefs #499",
          "is_bot": false,
          "headline": "Add shell completion generation (#764)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-22T00:13:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "baa4be13ac5321da4e9f53e864dd1cd395481200",
          "body": "Co-authored-by: Amp <amp@ampcode.com>",
          "is_bot": false,
          "headline": "fix: make extension installs transactional (#762)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-22T00:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddfdf2878e7e5ffd0a7682df51831d8ece6ee65b",
          "body": "* fix: expose authenticated ChatGPT models to ACP\n\nCo-authored-by: Pierre Bruno <pierrebruno@hotmail.ch>\n\n* fix(acp): persist discovered model selections\n\n* fix(acp): normalize model selections\n\n---------\n\nCo-authored-by: Amp <amp@ampcode.com>",
          "is_bot": false,
          "headline": "Fix ChatGPT OAuth model discovery and ACP model selection (#724)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-22T00:11:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96859c9bd16f6dad4e332efc7e68178b9116118a",
          "body": "* feat(sandbox): unify command execution and enforcement\n\n* test(sandbox): make platform contracts portable\n\n* fix(sandbox): close execution lifecycle races\n\nBound retained interactive output, preserve interruption state, and start workspace observation before process launch.\n\nProtect active runtime\n[…]\neatbelt host-local network allowances after native validation showed localhost filters can reach host interfaces.\n\nTrack process reap completion so retained sessions cannot signal a stale numeric PID.",
          "is_bot": false,
          "headline": "feat(sandbox): unify command execution and enforcement (#781)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-21T13:25:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3524f795e5fdbb827166a84f03351cedfc9eba30",
          "body": "… (#767)\n\nCloses #721.\n\n`zero providers use <name>` wrote activeProvider to config.json and reported\n\"Active provider set to <name>\" even when ZERO_PROVIDER was set, which applyEnv\nmakes win over config.json unconditionally. So the switch was reported as a\nsuccess while `providers current` still sho\n[…]\n) so tests stay hermetic against an\nambient ZERO_PROVIDER. The related env-derived-profile \"not found\" case the issue\nalso mentions is already handled by the unpersisted-provider path (#707) and #716.",
          "is_bot": false,
          "headline": "fix(cli): warn when ZERO_PROVIDER overrides a providers-use selection…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1f41735a7f6b7928a1875e986a4dca39d106cb9",
          "body": "…il the suite (#684) (#766)\n\n* fix(lsp): make the real-gopls check opt-in so a broken gopls can't fail the suite\n\nCloses #684.\n\nTestManagerCheckRealGopls skipped only when gopls was absent from PATH, so an\ninstalled-but-unhealthy gopls (e.g. an unusable persistent-index cache that makes\nthe server e\n[…]\nver and never touches the developer's global gopls; the\nreal check still runs on demand with ZERO_GOPLS_INTEGRATION=1.\n\n* test(lsp): require ZERO_GOPLS_INTEGRATION=1 exactly, so =0 keeps the check off",
          "is_bot": false,
          "headline": "fix(lsp): make the real-gopls check opt-in so a broken gopls can't fa…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4945684fa26aa5994eda59dcabedc817423c535d",
          "body": "… (#765)\n\nCloses #728.\n\nThe Windows ACL setup resolved each target's pathname independently across\nos.Stat, GetNamedSecurityInfo, and SetNamedSecurityInfo (and again on rollback),\nso during elevated setup a lower-privileged local user could swap a target for a\nsymlink/junction between operations and\n[…]\n it runs in CI), and the not-exist\nmapping. The full privilege-boundary race can't be reproduced in CI, so the guard\nis verified structurally (one handle for read and write) and by junction rejection.",
          "is_bot": false,
          "headline": "fix(sandbox): bind Windows elevated ACL setup to one no-follow handle…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5140d4bf7b115dff72ec33d104e062aaca96cf40",
          "body": "Documents expectations for keeping contribution flow sustainable during the\nstabilization phase: one issue per bug (no bundled multi-finding audits), keep\nonly a few items open at a time, and hold AI-assisted contributions to the same\nper-item verification bar. Complements the existing issue-approved gate, which\nalready covers PR-to-issue linkage and scope; the gap was submission volume.",
          "is_bot": false,
          "headline": "docs(contributing): add contribution volume and batching guidance (#783)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:16:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3967d49d64998341af8ef6d7523fc63aeb2a5a7a",
          "body": "* feat(tui): let the permission prompt take free-text feedback inline\n\n\"No, and tell Zero what to do differently\" now opens an inline input on the\npermission card instead of silently cancelling: type an instruction, Enter sends\nit, Esc returns to the option list. The text is delivered as a Deny deci\n[…]\nceKeepsStagedAttachment (mutation-verified\nagainst the missing guard) and TestPermissionFeedbackRendersNoClickableOptionsWhileTyping.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(tui): permission prompt takes free-text feedback inline (#780)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89bdc6719a1e1b3a3ef0e36b91a7839b3efdfba9",
          "body": "…ring (#779)\n\n* fix(tools): read_file recovers a backwards line range instead of erroring\n\nrenderReadFileRange hard-failed when end_line < start_line, costing the caller a\nwhole retry for an arithmetic slip. It was also inconsistent: start_line past EOF\nreturns a friendly note and end_line past EOF \n[…]\nheader/separator or a stray out-of-range line would still pass. Compare the\nwhole result.Output against the exact expected rendering.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tools): read_file recovers a backwards line range instead of erro…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:27:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "722bb3121682d9cd9cd4bc6c127e9014d719262a",
          "body": "The focused permission prompt was the only prompt card in the TUI that used\nbrand/warning colours for its interior, and both read badly on cool themes such\nas dracula:\n\n1. The selected option (\"Yes, proceed\") was filled with zeroTheme.badge — the\n   brand chip meant for short labels (\" 0 \", \" ASK \",\n[…]\ng and not the brand accent, the body carries no permBg wash, and\nthe PERMISSION badge keeps its amber fill so the card still reads as a warning.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tui): stop the permission card clashing on cool themes (#778)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:09:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a21a052a4a32ce9cb3c93c94350cd24e138532cd",
          "body": "* feat(sandbox): disable the sandbox via config (#687)\n\nAdd a sandbox.enabled field (`\"sandbox\": {\"enabled\": false}`). ModeDisabled\nalready short-circuits the engine but had no config surface.\n\n- SandboxConfig.Enabled *bool (pointer distinguishes an explicit false from an\n  omitted key).\n- mergeConf\n[…]\nannot enable) and asserting the provider itself is\nstill applied, so the guard cannot be satisfied by dropping the command wholesale.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(sandbox): disable the sandbox via config (#687) (#746)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:37:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f079b90f82dac7b7ae0864b279dc9094e31a6627",
          "body": "…73) (#745)\n\n* fix(sandbox): AST second opinion for interactive-command bypasses (#473)\n\nThe interactive-command guard split shell commands with a hand-written parser\n(splitShellSegments), which mis-handles unusual quoting, command substitution,\nsubshells, and newline separators — an interactive pro\n[…]\nof hard-blocking.\n\nGenuine detection is unchanged: `git rebase -i HEAD~1` and the #473 bypass\ncases still classify exactly as before.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(sandbox): AST second opinion for interactive-command bypasses (#4…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:31:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b30c3971b40b06ba52ad649ba9dc0ad560d4be4c",
          "body": "…ep the sidebar under the / palette (#775)\n\n* fix(tui): label model rows by id when the description is prose\n\nThe model picker (provider wizard AND onboarding, which share displayLabel)\nlabelled each row with the provider's Description, falling back to the ID only\nwhen the description was \"generic\".\n[…]\n rows beneath it.\n\nThe genuinely full-width overlays keep suppressing the sidebar, pinned by the\nnew test alongside the palette case.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tui): model rows labelled by id when the description is prose; ke…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:28:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da9fb50f549f6701eb136fc99f6178d0772d9334",
          "body": "…ry guidance (#749 follow-up) (#768)\n\n* fix(tools): give write_stdin's invalid-session errors the same recovery guidance\n\nFollow-up to #749 (write_stdin session-id probing) / #702.\n\nwrite_stdin had three \"no valid live session\" error paths with three different\nmessages and signatures: a missing sess\n[…]\nSessionID to cover missing/zero/negative/\nnon-integer and assert the recovery message. Guardrail signature/halt tests\nunchanged.\n\n* test(tools): cover the explicit session_id: nil case for write_stdin",
          "is_bot": false,
          "headline": "fix(tools): give write_stdin's invalid-session errors the same recove…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-20T08:29:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "684901165d1b7f50a8bb4af31b1c1951e6926a79",
          "body": "…(#727) (#744)\n\nThe ambient ZERO_SANDBOXED=1 + ZERO_SANDBOX_BACKEND markers are user-controlled\nat an unsandboxed process boundary. Policy could auto-allow an ordinary shell\ncommand (backend reports a native wrapping sandbox) while the runner, seeing the\nsame markers, returned an unwrapped pass-thro\n[…]\ns the normal approval\npath instead of auto-allowing. Immediate mitigation per the issue; authenticated\nlaunch provenance is the longer-term fix.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(sandbox): don't auto-allow shell when re-entrancy skips wrapping …",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T06:26:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1975c1b396b3236ed648870230b4f85863b1d03",
          "body": "…s (#763)\n\n* fix(perfbench): grant write tools so mutating tasks measure real edits\n\nThe turn benchmark invoked `zero exec` in its default read-only posture,\nwhich exposes no write or shell tools (no edit_file/apply_patch/\nwrite_file/exec_command/bash). So the mutating classes (edit/fix/\nrefactor) c\n[…]\nTest on its own.\n- Drop the now-dead \"if WorkspaceFixture != empty\" branch: the fixtureless guard\n  added earlier already guarantees it is set.\n\nNo behavior change; the 4-task glm-5.2 smoke stays 4/4.",
          "is_bot": false,
          "headline": "fix(perfbench): grant write tools so mutating tasks measure real edit…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-20T06:04:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c6d3022bd7801eaad6a0440bb21a27221887297",
          "body": "* feat(tui): add /undo as an alias for /rewind (#698)\n\n/undo was unregistered and fell through to commandUnknown. Add it to the\n/rewind command's aliases (the same mechanism /quit, /find, /mcp-status use), so\nit dispatches to the existing rewind handler with args intact.\n\n* test(tui): cover the /und\n[…]\nmmand(\"/undo 123\") assertion so both the latest and numeric\n<sequence> forms of the /rewind contract are exercised through the alias.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(tui): add /undo as an alias for /rewind (#698) (#747)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T06:02:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "974fc036c2f9a194722f2e8fddbb4fdbf797effe",
          "body": "Token exchange/refresh and the device authorization/poll POSTs validated only\nthe initial endpoint, then let the http.Client follow a 307/308 that replays the\nform body (code, PKCE verifier, refresh_token, client_secret) to an unvalidated\norigin.\n\nAdd withoutRedirects(): a shallow client copy whose \n[…]\n to it), RequestDeviceCode, and pollDeviceOnce. The caller's\nclient is never mutated; legitimate token endpoints that return 200 are unaffected.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(oauth): refuse redirects on credential POSTs (#729) (#741)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T02:49:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cbd144d11e5cb67bc5fea46f5b294562dac7a1a",
          "body": "…716)\n\n* fix(providers): stop \"provider not found\" for env-derived profiles\n\n* fix(providers): address env profile review feedback\n\n* fix(providers): keep env JSON response schemas stable",
          "is_bot": false,
          "headline": "fix(providers): stop \"provider not found\" for env-derived profiles (#…",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-20T02:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0b6b9e5c96fcedb7905999cdcb501cce2af7247",
          "body": "…711)\n\n* docs(readme): note govulncheck/golangci-lint install to GOPATH/bin\n\nThe installed binaries land in $GOPATH/bin (default ~/go/bin), which must\nbe on PATH to run govulncheck directly. Document the export snippet so the\nlint/security tooling from the contributor setup actually resolves.\n\n* doc\n[…]\nlback, and\nrerunning the old snippet appended the same directory repeatedly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): note govulncheck/golangci-lint install to GOPATH/bin (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-20T02:21:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d74ceb11271ed68a21c19248210e098f411805fb",
          "body": "* fix(tui): cache settled alt-screen transcript\n\n* fix(tui): invalidate settled alt-screen cache on in-place status row updates\n\nsetDoctorStatusRow, setSandboxSetupStatusRow, and setCompactStatusRow all\nmutate an already-flushed transcript row in place (m.transcript[i] = row)\nwithout invalidating th\n[…]\now, so the next settle rebuilds the cache.\n\nAddresses PR #647 review feedback from Vasanthdev2004.\n\n* fix(tui): invalidate settled transcript cache\n\n* fix(tui): invalidate settled file selection cards",
          "is_bot": false,
          "headline": "fix(tui): cache settled alt-screen transcript (#647)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-20T02:20:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fbf85984f679058125951fe2d5e4f200e09a3e2f",
          "body": "A model that calls write_stdin with no live session probed sequential\nsession_ids (1, 2, 3, …), each failing, and the run ground on for a long\ntime before halting. The repeated-failure guard keys on a normalized,\n80-char-truncated signature of the tool error, and the old message\n\"Unknown exec sessio\n[…]\nold, plus the schema floor and the\nrecovery text. The TUI \"Sent input\" label on a failed write_stdin\n(issue criterion 4) is a separate cosmetic concern in a shared hot path\nand is left as a follow-up.",
          "is_bot": false,
          "headline": "fix(agent): stop write_stdin session_id probing thrash (#702) (#749)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-19T16:43:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9242b9e037eb9b38f90e7fa076b5228a759697ae",
          "body": "* Add transcript-grounded structured task state\n\nProject existing plan, tool-result, changed-file, verification, and completion events into a deterministic per-run snapshot.\n\nEmit content-free aggregate snapshots to traces. Carry bounded objective context through compaction and ground completion che\n[…]\nested: go run ./cmd/zero-release smoke\n\nTested: govulncheck ./... (no vulnerabilities found)\n\nAdvisory: pinned golangci-lint reports only unrelated pre-existing findings\n\nTested: git diff HEAD --check",
          "is_bot": false,
          "headline": "Add transcript-grounded structured task state (#761)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T16:08:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e267bdbee4a77813e93a7ab51f0c575b66cee8c",
          "body": "* feat(tui): add isolated btw conversations\n\nAdd /btw with inline-question support, isolated non-resumable session forks, background main-run routing, and safe return behavior.\n\nRefs #637\n\n* test(tui): cover btw return controls\n\nPreserve drafts when Ctrl+C is pressed during an active BTW run and cover returning to the parent through the documented /btw toggle.\n\n* Address BTW isolation review feedback\n\n* Reject explicit resumes of side sessions\n\n* Harden BTW isolation lifecycle",
          "is_bot": false,
          "headline": "feat(tui): add isolated /btw conversations (#748)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T15:07:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739a47e3eac92c3decc8734f52a4d99c7480c3ca",
          "body": "* perf(agent): preserve prompt cache prefixes\n\nBuild the system prompt once per run, fingerprint the exact emitted prompt and ordered tool definitions, and expose the full system-prompt hash in traces.\n\nAdd normalized and serialized two-turn regressions covering append-only messages, stable tools, a\n[…]\norder\n\nReturn registered tools in name order so provider-visible tool lists and prompt-prefix fingerprints cannot drift with Go map iteration. Add a regression covering the registry ordering contract.",
          "is_bot": false,
          "headline": "perf(agent): preserve prompt cache prefixes (#760)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T14:59:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce4a996ffac4482e704f0fd61b3e442398fb2401",
          "body": "Discovery metadata was merged without the https/loopback endpoint rule that\nconfigured endpoints already pass, letting a malicious issuer downgrade the\nauthorization/token/device/registration endpoint after config validation.\n\n- Add exported ValidateEndpointURL as the single endpoint-safety rule;\n  \n[…]\niscovered endpoint before merge in the provider resolveEndpoints\n  and validate resolved MCP metadata in both branches; fail closed on insecure.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(oauth): validate discovered endpoints before merge/use (#511) (#739)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-19T04:26:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "378d538e240c289e57821e9f9628f76034419d01",
          "body": "…0b+PR10c) (#740)\n\n* perf(agent): execution profiles, --exec-profile, bench passthrough, TUI /profile (PR10b+10c)\n\n* fix(execprofile): harden profiles against review findings\n\n- fast escalates on critical-risk mutations, not high: the sandbox marks\n  every shell command high before command analysis,\n[…]\ning may\nlegitimately be empty); an unknown ring preserves an explicit preference,\nmatching the cross-provider picker's behavior, while the profile's own\nfill still applies only where support is known.",
          "is_bot": false,
          "headline": "perf(agent): execution profiles with one-shot posture escalation (PR1…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T19:23:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "015452c1c98a39eabb021324182094e188a8bd47",
          "body": "…reps (#737)\n\n* fix(perfbench): keep the stamped answer file out of negative oracle greps\n\n* fix(perfbench): exclude stamped answer from positive oracle greps too",
          "is_bot": false,
          "headline": "fix(perfbench): keep the stamped answer file out of negative oracle g…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T17:24:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af875df58775484304fc65586bd6c74552ad01a2",
          "body": "* trace(perf): add posture escalation counter\n\n* feat(agent): typed posture-escalation policy and tool-result risk field\n\n* feat(agent): posture controller wiring and executed-risk stamping\n\n* test(agent): cover posture controller, escalation act path, and risk stamping\n\n* test(agent): pin zero risk on not-executed results\n\n* fix(agent): wire uncertain-path escalation and validate risk thresholds",
          "is_bot": false,
          "headline": "perf(agent): posture-escalation signals and controller (PR10a) (#736)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T17:02:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbd94430143df6754d68551d1028ad8f15b82f1b",
          "body": "…rst-class (#730)\n\n* fix(perfbench): absolutize the bench binary and make errored tasks first-class\n\n* fix(perfbench): state that errored tasks count as pass-rate failures\n\n* fix(perfbench): align errored-task wording with the actual tier accounting\n\n* chore(perfbench): never commit generated baseline reports",
          "is_bot": false,
          "headline": "fix(perfbench): absolutize the bench binary and make errored tasks fi…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T16:09:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fae754460832bbb557c0880cbe2abea8a9d1011",
          "body": "* docs: refresh repository agent guidelines\n\n* docs: make validation guidance non-mutating",
          "is_bot": false,
          "headline": "docs: refresh repository agent guidelines (#734)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-18T16:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cc6f43bf7f6f7c6d9f654113dc2141ec3acfc5b",
          "body": "… ideas (#732)\n\n* docs(community): wire Discussions as the front door for questions and ideas\n\n* docs(community): restore LF endings and make feature routing coherent",
          "is_bot": false,
          "headline": "docs(community): wire Discussions as the front door for questions and…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T16:04:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77960229b839dca856616f846839aa773f2923f7",
          "body": "* fix(doctor): report missing npm native binary in wrapper\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(doctor): preserve JSON output for missing native binary\n\n* fix(doctor): preserve doctor CLI behavior in wrapper fallback\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* style: gofmt\n[…]\nme copy. Add regression tests with ZERO_WRAPPER_SIMULATE_BUN to guard against future drift.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(doctor): detect missing native binary during runtime checks (#450)",
          "author_name": "uma-prasad",
          "author_login": "michaelkillgta",
          "committed_at": "2026-07-18T14:49:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "60dc84e7a38c5544ebc047f3cfaf4625dd1e83b5",
          "body": "…telemetry (PR8) (#723)\n\n* trace(perf): add provider prewarm span and prefix-stability counters\n\n* feat(openai): optimized turn session with prewarm and prefix telemetry\n\n* feat(providers): gate optimized OpenAI turn sessions behind env flag\n\n* feat(cli): wire optimized turn sessions into headless e\n[…]\nnsports, fingerprint wire order and cache key\n\n* test(openai): pin keep-alive transports in probe-expecting tests\n\n* feat(providers): preserve resolved capabilities on switched-model fallback sessions",
          "is_bot": false,
          "headline": "perf(openai): optimized turn session — background prewarm and prefix …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T08:54:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30e2c3f7ffa1d5e487bd10b59d4e823cda191d48",
          "body": "…er (PR7) (#720)\n\n* perf(providers): add provider capabilities and default turn-session adapter (PR7)\n\n* fix(providers): project effective reasoning efforts into capabilities\n\n* feat(agent): carry optimized turn sessions across mid-run model switches\n\n* test(agent): cover swap-time session open failure",
          "is_bot": false,
          "headline": "perf(providers): provider capabilities and default turn-session adapt…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T04:03:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18cce358a29409ab937e92ff9af77bf98749f6aa",
          "body": "Extract completion decisions from the agent loop into a feature-gated typed policy with complete, incomplete, and uncertain outcomes. Preserve bounded plan-stall nudges and allow at most one semantic acceptance check for self-correcting runs.\n\nTested: make build\n\nTested: make test\n\nTested: go fmt ./...\n\nTested: go vet ./...\n\nTested: make lint\n\nTested: govulncheck ./...\n\nNote: repository-wide pinned golangci-lint reports 36 pre-existing unrelated findings; internal/agent/... reports 0 issues.",
          "is_bot": false,
          "headline": "Add deterministic completion policy (#719)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-17T18:59:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5670c427ff39c628fb0822fd5c9317ee2174583",
          "body": "* perf(output): add token-aware budget contract\n\n* perf(output): add semantic retention policies\n\n* perf(output): budget results after redaction\n\n* perf(output): propagate tool truncation metadata\n\n* perf(output): trace semantic budget decisions\n\n* perf(output): classify core tool output\n\n* docs(out\n[…]\n hook budgets and search paths\n\n* fix(output): preserve alias and truncation metadata\n\n* test(trace): validate output budget metadata\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(output): add token-aware semantic output budgeting (PR11) (#717)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T18:32:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31d45d5f14e915acb9946e8b8eb81632c48f126a",
          "body": "…715)\n\nUpgrade the parallel tool planner from SideEffectRead probes to the PR5\nCapabilitiesOf contract: EffectReadOnly + ThreadSafe + auto-allowed, with\nresource-key conflict boundaries so same-path reads stay sequential.\n\nMark audited pure reads ThreadSafe (read_file, read_minified_file,\nlist_direc\n[…]\ne-conflict).\n\nTests cover the capability gate, key conflicts, extendParallelRun windows,\nand catalog ThreadSafe audit for concurrent-safe reads.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(agent): concurrent read-only tool batches via capability gate (#…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T12:22:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "727ad4d321fab45d0cf40f8535522e3d94e55c4a",
          "body": "…misread as correctness (#712)\n\n* perf(turn-bench): Phase 0 — strengthen oracles so pass rate can't be misread as correctness\n\nThe baseline manifest's pass/fail contract had three holes that let a weak\nor no-op agent read as a pass:\n\n  - edit grep oracles were substring checks: a reworded line (e.g.\n[…]\nfactor-05 removed from the\n'no oracleTest' inventory (it now has TestGreetWrapped); the nav-01 named-\nfact prose corrected to the three files the oracle actually anchors on;\ntest comment #701 -> #712.",
          "is_bot": false,
          "headline": "perf(turn-bench): Phase 0 — strengthen oracles so pass rate can't be …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-17T12:02:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e666395d47a059a54c9cf00ab251d127ecc4f21f",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.4.0 (#625)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T05:25:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9043baedcff7776c7373645b57563cac06b31847",
          "body": "* fix(sandbox): scrub dynamic credential env vars\n\n* fix(sandbox): tolerate env assignments in configured sensitive keys\n\nA config value mistakenly given as a full assignment (e.g.\n\"COMPANY_LLM_SECRET=...\") would never match the real env key during\nscrubbing, silently re-exposing the credential to s\n[…]\negraded-fallback\npath with both a configured and a dynamically named secret.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sandbox): scrub dynamic credential env vars (#682)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-17T05:04:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d8c31cf16a3080344e3be7039408fcae71c075d",
          "body": "…ride user disable (#609)\n\nA user-level MCP server disable is now sticky. The project config\n(a cloned repo's ./.zero/config.json) cannot re-enable a server the\nuser disabled, and cannot disable a server the user explicitly enabled.\n\nThe previous merge just assigned base.Disabled = next.Disabled, so\n[…]\n ignored.\n\nPorts the fix onto main's refactored MCP merge (internal/config/mcp_merge.go\nand mergeProjectMCPConfig), which splits project-scope merging from the\ngeneral mergeMCPConfig path.\n\nFixes #512",
          "is_bot": false,
          "headline": "fix(config): enforce MCP trust boundary so project config cannot over…",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-17T05:03:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "824ecdbcf9c467c35ef4e2666770fdadcb5bf402",
          "body": "* fix(hooks): run sessionEnd hooks after Esc/Ctrl+C interrupts\n\nOn interrupt, Run returns with ctx already canceled. The deferred\ndispatchSessionEnd call passed that same ctx into Hooks.Dispatch, whose\ncontext.WithTimeout derives an already-canceled child context, so the\nhook process never actually \n[…]\nude Sonnet 5 <noreply@anthropic.com>\n\n* test(agent): fall back to GOROOT for hook regression\n\n* test(agent): justify GOROOT fallback\n\n---------\n\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): run sessionEnd hooks after Esc/Ctrl+C interrupts (#606)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-17T05:03:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b9c2f0c083e02bcd3aad68fb7af0501a9e7cd61",
          "body": "…y issuance) (#655)\n\n* feat(aimlapi): AI/ML API guided onboarding (top-up + key issuance)\n\nAdd the AI/ML API provider integration to the zero CLI: a guided TUI\nonboarding sub-flow that takes an existing key or an email top-up and\nwrites the issued key into the provider profile, attributed to the\nGit\n[…]\nheckout responses\n\n* fix(providers): reconcile aimlapi catalog after rebase\n\n---------\n\nCo-authored-by: Lookoff123 <bataryshkinairina@gmail.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(aimlapi): AI/ML API provider with guided onboarding (top-up + ke…",
          "author_name": "StanAIML",
          "author_login": "Lookoff-AIMLAPI",
          "committed_at": "2026-07-17T04:49:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ef8576df7d0775a5b815bc0776a794cadb75c34",
          "body": "* perf(tools): add explicit tool effect metadata\n\nIntroduce fail-closed EffectClass and ToolCapabilities on every built-in\ntool so a later concurrent read-only batch PR can decide safety from\nexplicit metadata rather than tool names. Plugin and MCP tools stay\nEffectUnknown. No concurrent execution i\n[…]\n for conflict keys\n- Validate constructor-declared capabilities before normalization\n- Unify session/process ID key extraction helper\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(tools): add explicit effect metadata for safe concurrency (#705)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T04:48:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c5c6e78a8a0e228bdf53d7be90934fbce9d98c3",
          "body": "Compute a seven-field SHA-256 fingerprint of the cacheable prompt\nprefix (base instructions, confirmation policy, project context, skills,\ntools, tool schemas, complete) and emit one prefix_hash event per turn\nthrough the trace recorder. The complete hash is the SHA-256 of the\ncanonical join of the \n[…]\ns unchanged; the fingerprint is purely\nadditive observability. The Anthropic cache_control breakpoint work\nalready in main is not touched.\n\nCo-authored-by: anandh8x <anandh8x@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(perf): emit prompt-prefix hash fingerprint per turn (#704)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-17T04:47:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f669f455021be51319ee3b8298cd48a17f745c7",
          "body": "* feat(tui): Ctrl+X leader chords and emacs menu navigation\n\nAdd Ctrl+X leader shortcuts for common slash commands (with Ctrl+X ?\nchord map), and Ctrl+P/N previous/next selection in modals and pickers.\n\n* fix(tui): drop Ctrl+X e /edit leader chord\n\n/edit replaces the composer and would discard an in\n[…]\nN as a no-op\n\nReserve Ctrl+N for emacs menu navigation so it never falls through to\nremapped global bindings when no selection surface is open.\n\n* docs: drop manual CHANGELOG entries for TUI shortcuts",
          "is_bot": false,
          "headline": "feat(tui): Ctrl+X leader chords and emacs menu navigation (#699)",
          "author_name": "Leonardo Faoro",
          "author_login": "lfaoro",
          "committed_at": "2026-07-17T04:44:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b42cd567b96d6f7e0818594e53ff31cce1e42e9",
          "body": "… (#672)\n\n* fix(tui): stop the composer cursor blinking while typing or unfocused\n\nThe composer's cursor blinked on a fixed timer unconditionally, including\nmid-keystroke, which made typing feel janky since the cursor's job is to mark\nthe current position. Gate the existing blink tick on two states \n[…]\n.PasteMsg and right-click clipboardReadMsg paths, so a paste right after\nthe blink phase hid the caret renders solid immediately instead of waiting\nfor a tick that would toggle off a stale idle state.",
          "is_bot": false,
          "headline": "fix(tui): stop the composer cursor blinking while typing or unfocused…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-17T04:43:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "665bd4b3d0c6c54c6622bfa44b6e024d2acc06d9",
          "body": "* draft(tui): add theme interface and Claude/Codex presets proposal\n\nIntroduces the Theme interface alongside the initial specifications and styling models for the Claude (card-based, warm) and Codex (high-density, split-screen cyberpunk) layout presets. Detailed design plans are documented in docs/\n[…]\ngs.\n- docs/THEMES.md no longer claims the extended invariants run against the\n  whole registry: it now says new palettes must be added to the\n  per-palette contrast tests or given equivalent coverage.",
          "is_bot": false,
          "headline": "WIP: feat(tui): TUI theme presets (Dune and Neon) (#634)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-17T04:38:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9acb4113cc3337b3f361a16278e9cf11ca105e34",
          "body": "* feat(cli): show ZERO wordmark on --version\n\nThe TUI's empty-state ZERO ascii art gets exposed via a new tui.Wordmark\nhelper and printed above the version line for `zero -v`/`--version`.\nColoring only applies when stdout is a real TTY and NO_COLOR isn't set,\nso redirected or piped output (scripts p\n[…]\nerminals. The terminal's default foreground works on any background.\n- smokeVersion goes back to requiring the exact \"zero <version>\" output\n  instead of the suffix match that papered over the banner.",
          "is_bot": false,
          "headline": "feat(cli): show ZERO wordmark on --version (#673)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-16T15:02:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d66a9dda69c32aa59f4bea903cfefe00d4b7adef",
          "body": "* feat(providers): add AI/ML API preset\n\n* fix(providers): relocate aimlapi preset and drop referral header\n\nAddresses the two review asks on #402:\n\n- Move the AI/ML API descriptor out of catalog slot #2 (it sat above the\n  first-party OpenAI/Anthropic/Google entries) down next to openrouter in\n  th\n[…]\ny: Dmitry Tumanov <d1m7asis@gmail.com>\nCo-authored-by: Vasanthdev2004 <vasanth.dev2004@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(providers): add AI/ML API preset (rebased onto main) (#621)",
          "author_name": "404ҜĦΔƗ",
          "author_login": "404khai",
          "committed_at": "2026-07-16T14:57:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d579996b43741a2e57e3e38fcdd8484fcfc34e9",
          "body": "…loading (#696)\n\n* feat(skills): discover shared ~/.agents/skills with multi-root skill loading\n\nAdd ~/.agents/skills as a read-only global discovery root after the\nprimary\nZero skills dir and before plugin roots. Unify runtime and CLI discovery\non\none multi-root path (DiscoveryRoots / LoadFromRoots\n[…]\nrror on Windows\n\nWindows maps ENOTDIR to ErrNotExist, so ReadDir on a regular file looked\nlike a missing skills dir. Reclassify existing non-directories and assert\nthe portable load behavior in tests.",
          "is_bot": false,
          "headline": "feat(skills): discover shared ~/.agents/skills with multi-root skill …",
          "author_name": "Leonardo Faoro",
          "author_login": "lfaoro",
          "committed_at": "2026-07-16T13:59:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abe24bcb10244c57e6b7d30acf3aa2a58d6081d0",
          "body": "…(#700)\n\n* Add per-turn tracing and a turn-benchmark harness (Phase 0 baseline)\n\nIntroduce an opt-in `internal/trace` package that attributes a run's wall\ntime to named spans — prompt build, provider connect/queue, generation,\ntool queue/execution, permission wait, verification, compaction,\npersiste\n[…]\nildOnlyClasses field (taskbench.go), and the PR body already says\n'48-task manifest'. The Share->exclusiveShare rename is tracked in #701.\n\ngo build/vet/gofmt clean; go test -race green for perfbench.",
          "is_bot": false,
          "headline": "Add per-turn tracing and a turn-benchmark harness (Phase 0 baseline) …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-16T13:58:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "75a78e715bf23154f69c8c79cb58eb4b535b2a2a",
          "body": "* feat(cli): wire MCP serve WorkspaceRoot and --add-dir scope\n\nPass the resolved workspace into mcp.ServeOptions and honor --add-dir so\nresources/list and scoped tools can expose extra roots beyond cwd.\n\n* fix(cli): keep lexical serve --add-dir roots for path matching\n\nUse symlink-resolved paths only for deduplication so Scope roots stay\naligned with the un-evaluated WorkspaceRoot MCP serve already passes.",
          "is_bot": false,
          "headline": "feat(cli): wire MCP serve WorkspaceRoot and --add-dir scope (#694)",
          "author_name": "Felix-Ayush",
          "author_login": "Ayush7614",
          "committed_at": "2026-07-15T13:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "850244943031a3cbe0f20714d00e896f355a81cc",
          "body": null,
          "is_bot": false,
          "headline": "test(tui): isolate provider wizard credentials (#688)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-15T13:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0bcfdda41e08dfd18bfbde4cd89a3fe1c1c416c",
          "body": "Updates charm.land bubbles/bubbletea/lipgloss v2, golang.org/x/sys,\ngolang.org/x/sync, and dlclark/regexp2/v2 to their latest patch releases.",
          "is_bot": false,
          "headline": "chore(deps): bump go module dependencies (#669)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-15T13:06:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bb6b5745af90321d1e657a12a1976cded5dd1bd",
          "body": "The launcher recording a spawn and the job's Runs counter incrementing\nare sequential but distinct steps in the scheduler goroutine\n(fireIfIdle's Spawn call, then run's job.incRuns()). The test polled\nonly the launcher's recorded count, then asserted Runs immediately\nwith no wait, so a scheduler goroutine preempted between those two\nsteps could be observed with a stale Runs value under CI load. Wait\nfor Runs itself instead of assuming the launcher signal implies it.",
          "is_bot": false,
          "headline": "fix(swarm): wait for job.Runs directly in scheduler skip test (#667)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-15T13:05:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fc1220f6ac66fb3ae67b637cbbed7068d2213c0",
          "body": "…660)\n\n* fix(windows): retry atomic file renames on Access is denied / Sharing violation\n\n* test(swarm): add unit tests for rename retry and non-retryable errors\n\n* test(swarm): skip TestMailboxRenameRetry on non-Windows platforms\n\n* fix(sandbox): scrub sensitive provider credentials from sandbox en\n[…]\nensitiveEnv's sensitiveKeys list: both are real bearer secrets read\nfrom the environment but were missing from the scrub list, leaving them\nreadable by sandboxed commands when set in the parent shell.",
          "is_bot": false,
          "headline": "fix(sandbox): scrub sensitive credentials from sandbox environment (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T13:46:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80c39aa599b6a1caf1ce229c40efbc8157983ae9",
          "body": null,
          "is_bot": false,
          "headline": "docs: add codebase minimization guideline to AGENTS.md (#661)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T07:15:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bd9742fa95c41b93ea4e718628aed0ff3ae9dd0",
          "body": "…ox denials (#659)\n\n* fix(tools): classify silent wrapped Windows command failures as sandbox denials\n\nA Windows restricted-token sandbox failure is often completely silent:\nwhen the token cannot open the target executable or its DLLs (or an\nMSYS runtime dies during init), the command exits nonzero \n[…]\nnd in the silent-denial test\n\nThe heuristic treats windows-elevated identically to\nwindows-restricted-token, but only the latter was exercised.\nParameterize the silent-failure test over both backends.",
          "is_bot": false,
          "headline": "fix(tools): classify silent wrapped Windows command failures as sandb…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T07:13:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91ea6ded7503538834a84d090f78670a363c62d3",
          "body": "* fix(keyring): pass generic password via stdin on macOS\n\nPass the generic password secret to security add-generic-password via stdin instead of passing it as a command-line argument. This prevents the secret from leaking to the local process list (visible via ps) and aligns the macOS keyring implem\n[…]\nslash and\ndouble quote escaped inside double quotes). The parser is line-based with a\n4096-byte buffer, so Set rejects newlines and oversized payloads up front\nrather than corrupting the stored value.",
          "is_bot": false,
          "headline": "fix(keyring): pass generic password via stdin on macOS (#574)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T06:46:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa3052a1422a4ad30a3a6295829564f42dee31a8",
          "body": "Co-authored-by: octo-patch <266937838+octo-patch@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(providers): refresh MiniMax model coverage (#665)",
          "author_name": "Octopus",
          "author_login": "octo-patch",
          "committed_at": "2026-07-13T14:33:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c986d327b5ed26338d295c23bea5839681db8d0",
          "body": "* feat(tui): press up to edit queued messages\n\nPressing up with a message queued pops it back into the composer for\nediting, taking priority over history recall. While a message is queued\nthe empty composer shows a hint placeholder. A second prompt queued\nduring the same run now stacks under the first instead of replacing it.\n\n* refactor(tui): remove openclaude references from queued_message comments",
          "is_bot": false,
          "headline": "feat(tui): press up to edit queued messages (#656)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T14:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5d2e327c8681671aa8a9e5378801215b747edcf",
          "body": "…onfigured (#658)\n\nRemoving the WRITE_RESTRICTED flag in #612 made the restricted-SID check\napply to reads as well as writes. Default Windows DACLs grant\nBUILTIN\\Users rather than any SID in the token's restricted list\n(random capability SIDs, logon SID, Everyone), so the sandboxed process\ncould no \n[…]\ned token and trade spawn\ncapability for read-deny enforcement. DenyRead is empty by default, so\nthe common case regains a working sandbox while #612's guarantee holds\nfor the profiles that rely on it.",
          "is_bot": false,
          "headline": "fix(sandbox): use WRITE_RESTRICTED token when no DenyRead paths are c…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T14:17:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c4815a66ed07d9cf90b825adfd936d3ac07639d",
          "body": "… sandbox (#654)\n\n* fix(sandbox): stop blocking git fetch/commit/add by unblocking .git writes\n\nThe sandbox denied every write under .git for shell-executed commands,\nso any git operation that touches its own metadata (fetch, commit, add,\npull, merge, stash) failed under the default sandbox. Narrow \n[…]\nonly converted a bare backslash, so\nthe Windows smoke run diverged from the forward-slash golden. Replace all\nbackslashes with slashes during normalization so the shared golden passes on\nevery runner.",
          "is_bot": false,
          "headline": "fix(sandbox): unblock git fetch/commit/add under the write-restricted…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:56:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "635c93af51ebc20f3e0917917e55a79edfe27c35",
          "body": "* fix(agent): raise default and deep-mode turn budgets\n\nThe default per-run tool-turn budget of 50 was still too low for larger\nmulti-step tasks that span several files: agents hit the ceiling and\nstopped with a \"remaining work\" summary instead of finishing. Raise the\ndefault from 50 to 80.\n\nThe \"de\n[…]\n runs get a genuinely larger budget again.\n\nUsers can still override per-session with /turns or --max-turns (bounded\nby MaxTurnsCeiling).\n\n* test(cli): expect deep-mode MaxTurns=160 after budget raise",
          "is_bot": false,
          "headline": "fix(agent): raise default and deep-mode turn budgets (#650)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:54:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "893b7b424cc203a2fcf92327a4e25c84286a90e0",
          "body": "… dropping them (#645)\n\n* fix(config): surface unknown/typo'd config fields instead of silently dropping them\n\njson.Unmarshal ignores unknown JSON keys by default, so typos such as\n\"maxTurn\" or \"sandbox.network\" were silently discarded: the user\nbelieved a setting (e.g. a sandbox hardening option) w\n[…]\n the unknown-field test assertions order-independent (search by\n  FieldPath instead of assuming issues[0]).\n\nAdd regression coverage for legacy provider keys and valid case\nvariants not being flagged.",
          "is_bot": false,
          "headline": "fix(config): surface unknown/typo'd config fields instead of silently…",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-13T13:52:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da41c3a75b782d6e0836fe13346321e40a90fbb4",
          "body": "… (#628)\n\n* fix(lock): prevent POSIX lock file overwrite and leak on Windows/Unix\n\nDuring lock reclamation, reclaiming a suspected stale lock renames the file aside and renames it back if not stale. On POSIX systems, the rename back silently overwrites any new lock file created in the gap. On Window\n[…]\nrite a competing\nlock rather than detect it. A fully race-free reclaim would need an\nOS-level advisory lock checked non-destructively instead of by moving\nthe file, which is a larger change than this.",
          "is_bot": false,
          "headline": "fix(lock): prevent POSIX lock file overwrite and leak on Windows/Unix…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:45:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a5b7fd5b8af636ecb8ff8d796e7cf6ebcf20f78",
          "body": "…26+ (#635)\n\n* docs: add Go code quality & security checks and bump Go version to 1.26+\n\n* docs: address CodeRabbit review comments and use pinned versions and Go 1.26.5+\n\n* docs: remove trailing blank lines at end of AGENTS.md\n\n* docs: add missing /v2/ segment to golangci-lint install path\n\nThe go \n[…]\n the same section already\nhad the correct v2 path.\n\n* docs: trim AGENTS.md below 8 KiB guideline and clean up README cross-compile header\n\n* docs: address CodeRabbit review feedback on extending guide",
          "is_bot": false,
          "headline": "docs: add Go code quality & security checks and bump Go version to 1.…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:37:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "212734adf3b5f982e22385161205aa1afe4634fe",
          "body": "…name (#631)\n\nWhen writing credentials or generating user secrets, files are written using a write-to-temp-then-rename pattern. However, neither package called Sync (fsync) on the temporary file before closing and renaming. If a crash or power failure occurred shortly after write, this could result in truncated or 0-byte key/credential files on disk.\n\nAdd tmp.Sync() calls to writeNewSecretFile and Store.write to guarantee durability.",
          "is_bot": false,
          "headline": "fix(securefile,credstore): call Sync on temp file before close and re…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:35:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2efe6d539e29374b3ef39c2290bdea81f33a228b",
          "body": "…#627)\n\n* fix(plugins): resolve relative executable paths against plugin root\n\nWhen a plugin registers a tool or a hook command as a relative path (e.g. ./tools/helper.sh), running it in the caller's workspace CWD allows local execution hijacking by placing a malicious script at that path in the unt\n[…]\n permission was always overwritten by one of\nthe switch arms below it, including a case that just reassigned the\nsame PermissionPrompt value the initializer already held. Flagged by\nineffassign in CI.",
          "is_bot": false,
          "headline": "fix(plugins): resolve relative executable paths against plugin root (…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:34:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e1405d0b7abff5b3ccb3cfdb66d64d6d3322922",
          "body": "…626)\n\n* feat(npm): ship the native binary as platform optionalDependencies\n\nReplace the postinstall downloader with Codex-style platform packages:\nsuffixed versions of @gitlawb/zero (X.Y.Z-<platform>-<arch>) carrying the\nbinary, sandbox helpers, and the vendored agent-browser/tuistory tree,\nreferen\n[…]\n platforms and say so honestly in the notice and docs.\n- Correct Windows support wording everywhere: x64 only, ARM runs under\n  emulation (README, README_ZH, INSTALL.md incl. the release-target list).",
          "is_bot": false,
          "headline": "feat(npm): ship the native binary as platform optionalDependencies (#…",
          "author_name": "Kevin Codex",
          "author_login": "kevincodex1",
          "committed_at": "2026-07-11T15:25:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1af58828eb3c22567599c000736c913a290959d2",
          "body": "…636)\n\nInteractive TUI always has a session ID, so every completion request\nforwarded OpenAI's prompt_cache_key. Strict openai-compatible gateways\n(e.g. NVIDIA NIM) reject unknown fields with a 400, while plain zero\nexec usually has no session and omits the field.\n\nDisable prompt_cache_key for ProviderKindOpenAICompatible; keep it for\nofficial OpenAI. ZERO_DISABLE_PROMPT_CACHE_KEY remains a global kill\nswitch.\n\nFixes #624\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(openai): omit prompt_cache_key for openai-compatible providers (#…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-10T13:43:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc06fe72caf45f72d2cba1e8a835c0f5b405c1e8",
          "body": "When executing a security-critical beforeTool hook, if the hook command fails to launch (e.g. binary not found, missing execute permission), it previously failed open and let tool execution proceed.\n\nUpdate classifyResult to return AuditBlocked, true when a launch error occurs on a beforeTool hook, enforcing a fail-closed policy. Observational afterTool hooks still fail open.",
          "is_bot": false,
          "headline": "fix(hooks): fail closed on launch failures for beforeTool hooks (#629)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T08:42:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4bd703cfb28dab2dfa3c2ddba46237e1bb2e164",
          "body": "… (#630)\n\nInside fireJob, the Mutate transaction callback previously returned the stale in-memory job copy (read at tick start). This clobbered any concurrent updates made to the job (such asExpr, Prompt, or Cwd edits) while the job was running.\n\nUpdate the callback to apply schedule and status changes directly onto the fresh current job loaded from disk, and return current.",
          "is_bot": false,
          "headline": "fix(cron): prevent cron job Mutate from clobbering concurrent updates…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T08:41:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa73a76f1bd1b6fe97bac2fbff2d61b7474139f2",
          "body": "…#620)\n\nWhen a run is completed or canceled (agentResponseMsg) while an askUser prompt is pending, or when a stale/superseded askUserRequestMsg is received, the answer callback is now invoked with nil. This unblocks the waiting agent loop goroutine, preventing goroutine leaks and runner hangs.",
          "is_bot": false,
          "headline": "fix(tui): resolve pending askUser callbacks to prevent runner hangs (…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:12:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b4f48d2dcb66402c13bde0c3cfe9c9371da19fb",
          "body": "When parsing CLI flags, positional prompt text placed immediately after flags requiring values (e.g. --auto, --notify, --max-turns) would be greedily consumed as their value by nextFlagValue. Refine nextFlagValue to validate choices/types (autonomy levels, notify modes, integers) to detect invalid values early and fail validation rather than eating positional arguments.",
          "is_bot": false,
          "headline": "fix(cli): prevent consuming positional arguments as flag values (#619)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f78b36c770daa4577a9f99265b18a354454e36eb",
          "body": "When falling back from a failed PTY start to a pipe execution, the command attributes are reset. Previously, resetExecCommandForPipeFallback set command.SysProcAttr = nil, which stripped custom settings like Windows CmdLine quoting. Update the fallback logic to restore the original SysProcAttr instance, and add TestStartExecProcessPTYFallbackPreservesSysProcAttr to cover.",
          "is_bot": false,
          "headline": "fix(tools): preserve SysProcAttr during PTY fallback (#618)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db00ee3d57db97e0fbe23cb8628e8bcb47f6f09",
          "body": "… (#617)\n\nUsing unqualified taskkill / taskkill.exe commands on Windows can allow binary hijacking under certain conditions. Update all process termination callers on Windows to resolve the absolute path to taskkill.exe under System32 (referencing SystemRoot/windir environment variables, falling back to C:\\Windows).",
          "is_bot": false,
          "headline": "fix(windows): resolve absolute path for taskkill to prevent hijacking…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:08:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ea53841a5d54c37a153779ae86bea010659433c",
          "body": "…creation (#616)\n\nOn Windows, a concurrent holder's os.Remove leaves the lock file in a 'delete pending' state, causing a racing O_EXCL create to fail with ERROR_ACCESS_DENIED (mapped to os.ErrPermission). Treat os.ErrPermission as lock contention / already-existing lock, matching the collision checks in cron, hooks, oauth, and securefile.",
          "is_bot": false,
          "headline": "fix(daemon): handle os.ErrPermission as collision during O_EXCL lock …",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:07:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8536cc87f7a885f9e436d6ef28f5f325201623dc",
          "body": "…615)\n\n* fix(securefile): reclaim stale lock files to prevent permanent DOS\n\nWhen createSecretFile fails to acquire the O_EXCL lock because it already exists, check if the file is stale (older than 10 seconds). If so, atomically reclaim it via a rename-aside check, preventing a permanent DOS after a\n[…]\nshes. Update the lock file to write and verify process-specific tokens, and add TestCreateSecretFileReclaimsStaleLock to cover the stale reclaim flow.\n\n* style(securefile): gofmt const block alignment",
          "is_bot": false,
          "headline": "fix(securefile): reclaim stale lock files to prevent permanent DOS (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:07:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddc4927aac5544bf4dd2c46615aeda5a81c96576",
          "body": "truncateHint slices string hints using a raw byte offset (s[:max]), which can split multi-byte UTF-8 characters (like CJK characters, emojis, or accents) in half and produce invalid UTF-8 sequences. Update it to count and slice by runes to guarantee valid UTF-8, and add a unit test TestToolTitleTruncateHintRuneSafe to verify.",
          "is_bot": false,
          "headline": "fix(acp): make truncateHint rune-safe (#614)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0184581ec234ea414e0a47bc33e8b0f4ddfb497b",
          "body": "…bdirectories (#613)\n\nCurrently, both gitBranchForPrompt (agent) and gitBranch (tui) check for a .git entry directly inside the current working directory. When starting Zero in nested folders/subdirectories of a repository, the check fails and the branch segment is omitted.\n\nExport findProjectGitRoo\n[…]\npackage, and use it in both functions to resolve the correct repository root before checking HEAD and resolving the branch name. Also resolve relative worktree gitdirs relative to the repository root.",
          "is_bot": false,
          "headline": "fix(agent,tui): resolve git branch detection when starting Zero in su…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d96ac7e55c760a97f28c0e6ceaf1ec3b4ab717a",
          "body": "…ss (#612)\n\nOn Windows, creating restricted tokens with windowsWriteRestricted (0x08) instructs the kernel to skip checking the restricted SIDs list for read operations. This bypasses DenyRead path policies on NTFS. Remove the flag to enforce restricted SID constraints on both read and write operations, and add integration test assertions to verify that DenyRead paths are correctly blocked.",
          "is_bot": false,
          "headline": "fix(sandbox): remove windowsWriteRestricted flag to fix DenyRead bypa…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdddb05ba84b1600ae6c3a20028bf83afe474c44",
          "body": "Co-authored-by: Gautam Manchandani <gautammanch@Gautams-MacBook-Air.local>",
          "is_bot": false,
          "headline": "fix: harden MCP credential boundaries (#597)",
          "author_name": "Gautam Manchandani",
          "author_login": "GautamBytes",
          "committed_at": "2026-07-10T01:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6117af86d6bc87a4ee66910e99d76cb16b03fed",
          "body": "…essages (#608)\n\n* fix(agent): scope self-reported incompletion to sentences about the current objective\n\nThe detector matched inability stems anywhere in the final message, so a\nconversational recap of a past exchange (\"You asked if I could work\nautonomously ... so I couldn't actually do it at the \n[…]\nmpletion-gate combined with --use-spec is now rejected at parse\ntime, mirroring the --self-correct check: the spec-draft path never\nconsults the completion gate, so the flag would be silently ignored.",
          "is_bot": false,
          "headline": "fix(exec): stop false INCOMPLETE downgrades on conversational final m…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T00:59:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "584ef75a46b58e5b87e42c68467ece523cec5ea6",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.3.0 (#537)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-09T15:19:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a880ce80a6ec72da511fb9bdf6dd69291c72a64b",
          "body": "…space trust (#529)\n\n* feat(workspacetrust): add exact-match trust store for project config gating\n\n* feat(hooks): add ExcludeProject option to LoadConfig\n\n* feat(plugins): add ExcludeProject option to Load\n\n* feat(cli): gate project hooks and plugins behind workspace trust\n\nTrust check lives inside\n[…]\not and the extensions listing) are enumeration-only and stay\nungated.\n\n* test(cli): adapt MCP startup-skip tests to two-arg resolveMCPConfig\n\n---------\n\nCo-authored-by: Kevin Codex <kevin@gitlawb.com>",
          "is_bot": false,
          "headline": "feat: gate project-scoped hooks, plugins, and MCP servers behind work…",
          "author_name": "beardthelion",
          "author_login": "beardthelion",
          "committed_at": "2026-07-09T02:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7cfb99fed7b88ebc09a2f251cb82864d3c2cade",
          "body": null,
          "is_bot": false,
          "headline": "fix: bump Go to 1.26.5 for crypto/tls fix (GO-2026-5856) (#607)",
          "author_name": "Kevin Codex",
          "author_login": "kevincodex1",
          "committed_at": "2026-07-09T02:02:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc9b2d25c79e089f34cb7b5b6a7f7c7b8233123",
          "body": "…ermux) (#603)\n\n* fix(update): clearer error on unsupported release platform (android/termux)\n\nzero update/upgrade fails on Android/Termux because GOOS \"android\" has\nno published release archive. Replace the generic \"unsupported release\nplatform: android\" error with a clear, actionable message expla\n[…]\nfrom source. Termux runs zero fine via the npm wrapper; it just has no self-updating release archive. Point users at 'npm update -g @gitlawb/zero', the documented Termux install/upgrade path, instead.",
          "is_bot": false,
          "headline": "fix(update): clearer error on unsupported release platform (android/t…",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-09T01:34:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66a63964149fb2f07e646e5f1987627c5cd9ac28",
          "body": "* fix(modelregistry): reject oversized models.dev cache responses\n\nRead modelsDevFetchLimit+1 bytes instead of modelsDevFetchLimit. If the\nresponse exceeds the 32 MiB guard, return an error and leave any\nexisting cache untouched.\n\nFixes #510\n\n* address review: include byte count in error, make overs\n[…]\nad vs the limit\n- test payload is limit+1 bytes (matches the reported repro)\n- test explicitly clears ZERO_DISABLE_MODELS_FETCH so it exercises\n  the oversized path regardless of the outer environment",
          "is_bot": false,
          "headline": "fix(modelregistry): reject oversized models.dev cache responses (#602)",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-09T01:33:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a05e6486f7a63281b869064db03dfc5531e6a04",
          "body": "Co-authored-by: Gautam Manchandani <gautammanch@Gautams-MacBook-Air.local>",
          "is_bot": false,
          "headline": "perf(grep): stop content scan after head limit (#601)",
          "author_name": "Gautam Manchandani",
          "author_login": "GautamBytes",
          "committed_at": "2026-07-09T01:33:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92a92ceb29dc63f5216ab140ef9a6dd9afe17df8",
          "body": "…refixed model ids (#599)",
          "is_bot": false,
          "headline": "feat(modelregistry): infer reasoning efforts for Hunyuan and vendor-p…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:33:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "062328b632a2d27353a6d47c522bbd22d7282539",
          "body": "* fix: warn about untracked scratch files left behind after a run\n\nFixes #551. Headless exec runs could leave behind debug/scratch files\n(e.g. _fix_test.py, _debug.py) created by write_file during iteration,\nwhich would then be silently swept up by a later git add -A.\n\n- FileTracker now records bran\n[…]\ntch-created scratch files\n\n* fix: address scratch warning review feedback\n\n* fix: tighten scratch warning lifecycle\n\n---------\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: warn about untracked scratch files left behind after a run (#571)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-09T01:25:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f10ed0c893ce6de08923f143d681ba96f0fcfe3a",
          "body": "…ix (#468)\n\n* merge: rebase onto main, combine Windows shell guidance with #476's MSYS text\n\n#476 merged into main and rewrote the same \"Shell syntax: Windows cmd.exe...\"\nguidance string in system_prompt.go and shellGuidanceForGOOS in\nshell_runtime.go that this branch also edits (this PR's fix for t\n[…]\nell syntax description test for exec_command\n\n* chore: retrigger CI after infra flake\n\n* style(tools): gofmt exec_command_test.go\n\n---------\n\nCo-authored-by: Vasanthdev2004 <vasanth.dev2004@gmail.com>",
          "is_bot": false,
          "headline": "fix(tools): Windows cmd.exe quoting guidance and clipboard escaping f…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a52d98cad7cd0086dee9aede4ce477e432bd385",
          "body": "…red (#586)\n\n* fix(mcp): skip RFC 8414 discovery when OAuth endpoints are preconfigured\n\nresolveAuthorizationServer performed a real network metadata discovery call even when the MCP server config already supplied both the authorization and token endpoints. When discovery blocks (offline, unreachabl\n[…]\nendpoints. Use a transport that\nfails the test on any outbound request so the fast path is actually\nwhat is being verified.\n\n---------\n\nCo-authored-by: gnanam1990 <gnanam1990@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(mcp): skip RFC 8414 discovery when OAuth endpoints are preconfigu…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:21:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 5,
      "commits_last_year": 587,
      "latest_release_at": "2026-07-22T01:37:48Z",
      "latest_release_tag": "v0.5.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 8,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 4.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/Gitlawb/zero",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/Gitlawb/zero",
          "is_deprecated": false,
          "latest_version": "v0.5.0",
          "repository_url": "https://github.com/Gitlawb/zero",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-22T01:37:36Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "@gitlawb/zero",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@gitlawb/zero",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/Gitlawb/zero",
          "versions_count": 16,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3240,
          "first_published_at": "2026-07-02T07:09:39.913000Z",
          "latest_published_at": "2026-07-22T01:46:36.923000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 110,
      "stars": 1104,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-02",
            "count": 31
          },
          {
            "date": "2026-07-03",
            "count": 35
          },
          {
            "date": "2026-07-04",
            "count": 3
          },
          {
            "date": "2026-07-05",
            "count": 6
          },
          {
            "date": "2026-07-06",
            "count": 11
          },
          {
            "date": "2026-07-07",
            "count": 3
          },
          {
            "date": "2026-07-08",
            "count": 4
          },
          {
            "date": "2026-07-09",
            "count": 3
          },
          {
            "date": "2026-07-10",
            "count": 2
          },
          {
            "date": "2026-07-11",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 2
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 3
          },
          {
            "date": "2026-07-19",
            "count": 2
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 110,
        "total_forks": 110
      },
      "star_history": {
        "days": [
          {
            "date": "2026-07-02",
            "count": 145
          },
          {
            "date": "2026-07-03",
            "count": 487
          },
          {
            "date": "2026-07-04",
            "count": 94
          },
          {
            "date": "2026-07-05",
            "count": 43
          },
          {
            "date": "2026-07-06",
            "count": 65
          },
          {
            "date": "2026-07-07",
            "count": 41
          },
          {
            "date": "2026-07-08",
            "count": 31
          },
          {
            "date": "2026-07-09",
            "count": 11
          },
          {
            "date": "2026-07-10",
            "count": 16
          },
          {
            "date": "2026-07-11",
            "count": 9
          },
          {
            "date": "2026-07-12",
            "count": 9
          },
          {
            "date": "2026-07-13",
            "count": 8
          },
          {
            "date": "2026-07-14",
            "count": 10
          },
          {
            "date": "2026-07-15",
            "count": 5
          },
          {
            "date": "2026-07-16",
            "count": 5
          },
          {
            "date": "2026-07-17",
            "count": 3
          },
          {
            "date": "2026-07-18",
            "count": 7
          },
          {
            "date": "2026-07-19",
            "count": 4
          },
          {
            "date": "2026-07-20",
            "count": 4
          },
          {
            "date": "2026-07-21",
            "count": 2
          },
          {
            "date": "2026-07-22",
            "count": 1
          }
        ],
        "complete": false,
        "collected": 1000,
        "total_stars": 1104
      },
      "open_issues_and_prs": 89
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "internal/agenteval/testdata/fixtures/zero-mini/go.mod",
        "internal/perfbench/testdata/edit/go.mod",
        "internal/perfbench/testdata/fix/go.mod",
        "internal/perfbench/testdata/nav/go.mod",
        "internal/perfbench/testdata/refactor/go.mod"
      ],
      "largest_source_bytes": 217150,
      "source_files_sampled": 1231,
      "oversized_source_files": 16,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 3827
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 104,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "charm.land/bubbles/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "charm.land/bubbletea/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.8"
        },
        {
          "name": "charm.land/lipgloss/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.5"
        },
        {
          "name": "github.com/alecthomas/chroma/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.27.0"
        },
        {
          "name": "github.com/atotto/clipboard",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/aymanbagabas/go-udiff",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.1"
        },
        {
          "name": "github.com/charmbracelet/colorprofile",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.3"
        },
        {
          "name": "github.com/charmbracelet/x/ansi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.11.7"
        },
        {
          "name": "github.com/charmbracelet/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.2"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.15"
        },
        {
          "name": "github.com/ledongthuc/pdf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250511090121-5959a4027728"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.47.0"
        },
        {
          "name": "mvdan.cc/sh/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.13.1"
        },
        {
          "name": "agent-browser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.30.1"
        },
        {
          "name": "tuistory",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.10.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "charm.land/bubbles/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "charm.land/bubbletea/v2",
            "direct": true,
            "version": "v2.0.8",
            "ecosystem": "go"
          },
          {
            "name": "charm.land/lipgloss/v2",
            "direct": true,
            "version": "v2.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecthomas/chroma/v2",
            "direct": true,
            "version": "v2.27.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/atotto/clipboard",
            "direct": true,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-udiff",
            "direct": true,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": true,
            "version": "v0.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": true,
            "version": "v0.11.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": true,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ledongthuc/pdf",
            "direct": true,
            "version": "v0.0.0-20250511090121-5959a4027728",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "mvdan.cc/sh/v3",
            "direct": true,
            "version": "v3.13.1",
            "ecosystem": "go"
          },
          {
            "name": "agent-browser",
            "direct": true,
            "version": "0.30.1",
            "ecosystem": "npm"
          },
          {
            "name": "tuistory",
            "direct": true,
            "version": "0.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "github.com/charmbracelet/ultraviolet",
            "direct": false,
            "version": "v0.0.0-20260703014108-f5a850f9c2b7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/exp/golden",
            "direct": false,
            "version": "v0.0.0-20260615092313-b57e5e6d29bb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/termios",
            "direct": false,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/windows",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/displaywidth",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-quicktest/qt",
            "direct": false,
            "version": "v1.102.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.24",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/cancelreader",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rogpeppe/go-internal",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260611194520-c48552f49976",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "@clack/core",
            "direct": false,
            "version": "1.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@clack/prompts",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-ws",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-darwin-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-darwin-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-linux-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-linux-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-win32-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-win32-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/react",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@resvg/resvg-wasm",
            "direct": false,
            "version": "2.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "@sec-ant/readable-stream",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sindresorhus/merge-streams",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "bun-ffi-structs",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "clone",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "defaults",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "errore",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "figures",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-them-args",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ghostty-opentui",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "goke",
            "direct": false,
            "version": "6.12.3",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.27",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "kill-port-process",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "marked",
            "direct": false,
            "version": "17.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse-ms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "pid-port",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-ms",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-devtools-core",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-reconciler",
            "direct": false,
            "version": "0.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shell-quote",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-dedent",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "unicorn-magic",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "wcwidth",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "web-tree-sitter",
            "direct": false,
            "version": "0.25.10",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "7.5.11",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "yoctocolors",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "yoga-layout",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "zigpty",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.3.6",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 104,
        "direct_count": 15,
        "indirect_count": 89
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 43,
        "merged_prs": 531,
        "open_issues": 46,
        "closed_ratio": 0.678,
        "closed_issues": 97,
        "closed_unmerged_prs": 64
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "gnanam1990",
          "commits": 208,
          "avatar_url": "https://avatars.githubusercontent.com/u/84986124?v=4"
        },
        {
          "type": "User",
          "login": "Vasanthdev2004",
          "commits": 152,
          "avatar_url": "https://avatars.githubusercontent.com/u/148849890?v=4"
        },
        {
          "type": "User",
          "login": "anandh8x",
          "commits": 91,
          "avatar_url": "https://avatars.githubusercontent.com/u/223495731?v=4"
        },
        {
          "type": "User",
          "login": "euxaristia",
          "commits": 54,
          "avatar_url": "https://avatars.githubusercontent.com/u/25621994?v=4"
        },
        {
          "type": "User",
          "login": "PierrunoYT",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/95778421?v=4"
        },
        {
          "type": "User",
          "login": "kevincodex1",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/268502447?v=4"
        },
        {
          "type": "User",
          "login": "GautamBytes",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/161146829?v=4"
        },
        {
          "type": "User",
          "login": "Ashwinhegde19",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/107956700?v=4"
        },
        {
          "type": "User",
          "login": "KunjShah95",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/154980682?v=4"
        },
        {
          "type": "User",
          "login": "pengdst",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/40013467?v=4"
        }
      ],
      "contributors_sampled": 28,
      "top_contributor_share": 0.354
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "pr-auto-review.yml",
        "release-artifacts.yml",
        "release-please.yml",
        "zero-action-smoke.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 7,
            "reason": "SAST tool is not run on all commits -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a50574f673c3cb681937f02ce5f9be86e81beba8",
        "ran_at": "2026-07-22T02:06:55Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T01:46:47Z",
      "oldest_open_prs": [
        {
          "number": 489,
          "created_at": "2026-07-04T13:16:48Z",
          "last_comment_at": "2026-07-04T13:19:37Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 504,
          "created_at": "2026-07-05T01:50:44Z",
          "last_comment_at": "2026-07-06T06:05:09Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 532,
          "created_at": "2026-07-06T01:09:01Z",
          "last_comment_at": "2026-07-08T06:21:16Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 550,
          "created_at": "2026-07-06T08:58:17Z",
          "last_comment_at": "2026-07-11T08:37:14Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 570,
          "created_at": "2026-07-06T17:34:36Z",
          "last_comment_at": "2026-07-14T13:02:21Z",
          "last_comment_author": "pengdst"
        },
        {
          "number": 572,
          "created_at": "2026-07-06T23:40:21Z",
          "last_comment_at": "2026-07-11T15:33:05Z",
          "last_comment_author": "aitorse"
        },
        {
          "number": 590,
          "created_at": "2026-07-08T07:20:58Z",
          "last_comment_at": "2026-07-21T05:28:03Z",
          "last_comment_author": "glatinone"
        },
        {
          "number": 591,
          "created_at": "2026-07-08T08:43:15Z",
          "last_comment_at": "2026-07-14T03:28:28Z",
          "last_comment_author": "CengSin"
        },
        {
          "number": 594,
          "created_at": "2026-07-08T10:34:02Z",
          "last_comment_at": "2026-07-11T08:37:15Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 632,
          "created_at": "2026-07-10T03:44:44Z",
          "last_comment_at": "2026-07-22T00:08:29Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 640,
          "created_at": "2026-07-10T14:43:01Z",
          "last_comment_at": "2026-07-21T00:39:51Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 642,
          "created_at": "2026-07-10T14:52:42Z",
          "last_comment_at": "2026-07-20T11:08:06Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 643,
          "created_at": "2026-07-10T14:54:30Z",
          "last_comment_at": "2026-07-20T11:11:17Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 649,
          "created_at": "2026-07-10T17:03:57Z",
          "last_comment_at": "2026-07-10T17:31:44Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 668,
          "created_at": "2026-07-14T08:40:02Z",
          "last_comment_at": "2026-07-20T11:06:16Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 671,
          "created_at": "2026-07-14T10:27:53Z",
          "last_comment_at": "2026-07-20T11:07:56Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 681,
          "created_at": "2026-07-14T19:13:47Z",
          "last_comment_at": "2026-07-20T16:05:44Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 685,
          "created_at": "2026-07-14T19:43:23Z",
          "last_comment_at": "2026-07-18T09:34:06Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 686,
          "created_at": "2026-07-14T19:55:29Z",
          "last_comment_at": "2026-07-14T19:57:50Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 689,
          "created_at": "2026-07-14T20:39:03Z",
          "last_comment_at": "2026-07-18T21:19:31Z",
          "last_comment_author": "PierrunoYT"
        }
      ],
      "last_merged_pr_at": "2026-07-22T01:37:36Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 390,
          "created_at": "2026-07-02T14:11:06Z",
          "last_comment_at": "2026-07-15T19:53:20Z",
          "last_comment_author": "lfaoro"
        },
        {
          "number": 404,
          "created_at": "2026-07-02T18:58:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 446,
          "created_at": "2026-07-03T11:17:53Z",
          "last_comment_at": "2026-07-05T20:20:31Z",
          "last_comment_author": "vshuraeff"
        },
        {
          "number": 447,
          "created_at": "2026-07-03T11:55:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 454,
          "created_at": "2026-07-03T13:22:35Z",
          "last_comment_at": "2026-07-03T13:36:09Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 488,
          "created_at": "2026-07-04T13:16:40Z",
          "last_comment_at": "2026-07-04T14:09:13Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 507,
          "created_at": "2026-07-05T07:59:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 508,
          "created_at": "2026-07-05T08:33:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 514,
          "created_at": "2026-07-05T11:00:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 530,
          "created_at": "2026-07-05T23:16:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 531,
          "created_at": "2026-07-05T23:19:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 534,
          "created_at": "2026-07-06T02:52:50Z",
          "last_comment_at": "2026-07-09T16:57:58Z",
          "last_comment_author": "pengdst"
        },
        {
          "number": 554,
          "created_at": "2026-07-06T10:45:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 556,
          "created_at": "2026-07-06T11:15:22Z",
          "last_comment_at": "2026-07-06T11:29:00Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 559,
          "created_at": "2026-07-06T12:26:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 566,
          "created_at": "2026-07-06T15:45:54Z",
          "last_comment_at": "2026-07-07T11:53:39Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 569,
          "created_at": "2026-07-06T16:48:29Z",
          "last_comment_at": "2026-07-08T10:34:10Z",
          "last_comment_author": "baoyu0"
        },
        {
          "number": 579,
          "created_at": "2026-07-07T10:46:52Z",
          "last_comment_at": "2026-07-07T10:48:45Z",
          "last_comment_author": "gauravbhatia4601"
        },
        {
          "number": 584,
          "created_at": "2026-07-07T19:18:32Z",
          "last_comment_at": "2026-07-08T09:41:39Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 592,
          "created_at": "2026-07-08T09:11:40Z",
          "last_comment_at": "2026-07-08T09:41:38Z",
          "last_comment_author": "Vasanthdev2004"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Gitlawb/zero",
    "host": "github.com",
    "name": "zero",
    "owner": "Gitlawb"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 73,
      "inputs": {
        "security": 62,
        "vitality": 72,
        "community": 74,
        "governance": 73,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 587,
              "human_commit_share": 0.97,
              "days_since_last_push": 0,
              "active_weeks_last_year": 8
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "8/52 weeks with commits",
                "points": 5.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "587 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 587
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "v0.5.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 4.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 74,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "forks": 110,
              "stars": 1104,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "window_too_short"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,104 stars",
                "points": 49.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1104
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "110 forks",
                "points": 17,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 110
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "github.com/Gitlawb/zero",
                "@gitlawb/zero"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 3240
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,240 downloads/month across go, npm",
                "points": 46.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3240,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 73,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 28,
              "top_contributor_share": 0.354
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 35% of commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 35
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "28 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 531,
              "open_issues": 46,
              "closed_issues": 97,
              "issue_closed_ratio": 0.678,
              "closed_unmerged_prs": 64
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "68% of issues closed",
                "points": 31.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 68
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "531/595 decided PRs merged",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 531,
                      "decided": 595
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "followers": 932,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "Gitlawb",
              "public_repos": 17,
              "account_age_days": 127
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "932 followers of Gitlawb",
                "points": 21.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 932,
                      "login": "Gitlawb"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "17 public repos, account ~0 yr old",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 17
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/Gitlawb/zero",
                "@gitlawb/zero"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai-agent",
                "ai",
                "anthropic",
                "cli",
                "code-assistant",
                "coding-agent",
                "developer-tools",
                "gemini",
                "llm",
                "mcp",
                "ollama",
                "openai",
                "terminal"
              ],
              "has_wiki": true,
              "homepage": "https://zero.gitlawb.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://zero.gitlawb.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 104 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 104
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 104,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 104,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 86,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 3827
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.07,
              "toolchain_manifests": [
                "go.mod",
                "internal/agenteval/testdata/fixtures/zero-mini/go.mod",
                "internal/perfbench/testdata/edit/go.mod",
                "internal/perfbench/testdata/fix/go.mod",
                "internal/perfbench/testdata/nav/go.mod",
                "internal/perfbench/testdata/refactor/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "7 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 7,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 217150,
              "source_files_sampled": 1231,
              "oversized_source_files": 16
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "16/1231 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1231,
                      "oversized": 16
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "deps.dev does not index npm:@gitlawb/zero@0.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T02:07:24.060811Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/Gitlawb/zero.svg",
  "full_name": "Gitlawb/zero",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go, npm.