原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 597,
"has_wiki": true,
"homepage": null,
"languages": {
"Shell": 1668,
"JavaScript": 47421,
"TypeScript": 984795
},
"pushed_at": "2026-07-18T11:44:39Z",
"created_at": "2026-01-25T01:01:30Z",
"owner_type": "User",
"updated_at": "2026-07-18T11:44:30Z",
"description": "Clean Language Framework (Frame) for Node.js Server",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": null,
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "Ivan-Pasco",
"company": null,
"location": null,
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4",
"created_at": "2023-06-22T03:23:49Z",
"is_verified": null,
"public_repos": 10,
"account_age_days": 1127
},
"license": {
"state": "absent",
"spdx_id": null,
"raw_spdx": null,
"file_present": false,
"scorecard_found": false,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v0.1.97",
"kind": "patch",
"published_at": "2026-07-18T11:44:03Z"
},
{
"tag": "v0.1.96",
"kind": "patch",
"published_at": "2026-07-17T12:35:05Z"
},
{
"tag": "v0.1.95",
"kind": "patch",
"published_at": "2026-07-14T22:31:56Z"
},
{
"tag": "v0.1.94",
"kind": "patch",
"published_at": "2026-07-14T06:19:05Z"
},
{
"tag": "v0.1.93",
"kind": "patch",
"published_at": "2026-07-13T20:07:34Z"
},
{
"tag": "v0.1.92",
"kind": "patch",
"published_at": "2026-07-12T15:01:04Z"
},
{
"tag": "v0.1.91",
"kind": "patch",
"published_at": "2026-07-12T14:58:38Z"
},
{
"tag": "v0.1.90",
"kind": "patch",
"published_at": "2026-07-12T14:17:45Z"
},
{
"tag": "v0.1.89",
"kind": "patch",
"published_at": "2026-07-12T05:43:30Z"
},
{
"tag": "v0.1.88",
"kind": "patch",
"published_at": "2026-07-12T05:23:54Z"
},
{
"tag": "v0.1.87",
"kind": "patch",
"published_at": "2026-07-11T16:16:43Z"
},
{
"tag": "v0.1.86",
"kind": "patch",
"published_at": "2026-07-11T15:45:29Z"
},
{
"tag": "v0.1.85",
"kind": "patch",
"published_at": "2026-07-09T00:26:34Z"
},
{
"tag": "v0.1.84",
"kind": "patch",
"published_at": "2026-07-09T00:10:39Z"
},
{
"tag": "v0.1.83",
"kind": "patch",
"published_at": "2026-07-08T20:44:52Z"
},
{
"tag": "v0.1.82",
"kind": "patch",
"published_at": "2026-07-08T18:13:42Z"
},
{
"tag": "v0.1.81",
"kind": "patch",
"published_at": "2026-07-08T15:34:21Z"
},
{
"tag": "v0.1.80",
"kind": "patch",
"published_at": "2026-07-07T02:07:36Z"
},
{
"tag": "v0.1.79",
"kind": "patch",
"published_at": "2026-07-06T14:56:23Z"
},
{
"tag": "v0.1.78",
"kind": "patch",
"published_at": "2026-07-06T14:53:14Z"
},
{
"tag": "v0.1.77",
"kind": "patch",
"published_at": "2026-07-06T14:41:57Z"
},
{
"tag": "v0.1.76",
"kind": "patch",
"published_at": "2026-06-29T20:50:53Z"
},
{
"tag": "v0.1.75",
"kind": "patch",
"published_at": "2026-06-29T20:46:41Z"
},
{
"tag": "v0.1.74",
"kind": "patch",
"published_at": "2026-06-29T20:43:25Z"
},
{
"tag": "v0.1.73",
"kind": "patch",
"published_at": "2026-06-26T14:46:07Z"
},
{
"tag": "v0.1.72",
"kind": "patch",
"published_at": "2026-06-23T13:53:34Z"
},
{
"tag": "v0.1.71",
"kind": "patch",
"published_at": "2026-06-23T06:07:01Z"
},
{
"tag": "v0.1.70",
"kind": "patch",
"published_at": "2026-06-23T05:45:48Z"
},
{
"tag": "v0.1.69",
"kind": "patch",
"published_at": "2026-06-22T06:11:59Z"
},
{
"tag": "v0.1.68",
"kind": "patch",
"published_at": "2026-06-21T00:31:09Z"
},
{
"tag": "v0.1.67",
"kind": "patch",
"published_at": "2026-06-20T14:31:35Z"
},
{
"tag": "v0.1.66",
"kind": "patch",
"published_at": "2026-06-20T13:53:59Z"
},
{
"tag": "v0.1.65",
"kind": "patch",
"published_at": "2026-06-20T03:23:38Z"
},
{
"tag": "v0.1.64",
"kind": "patch",
"published_at": "2026-06-19T23:51:05Z"
},
{
"tag": "v0.1.63",
"kind": "patch",
"published_at": "2026-06-19T19:58:29Z"
},
{
"tag": "v0.1.62",
"kind": "patch",
"published_at": "2026-06-19T17:33:45Z"
},
{
"tag": "v0.1.61",
"kind": "patch",
"published_at": "2026-06-19T16:08:00Z"
},
{
"tag": "v0.1.60",
"kind": "patch",
"published_at": "2026-06-19T13:50:11Z"
},
{
"tag": "v0.1.59",
"kind": "patch",
"published_at": "2026-06-19T12:56:24Z"
},
{
"tag": "v0.1.58",
"kind": "patch",
"published_at": "2026-06-19T06:01:39Z"
},
{
"tag": "v0.1.57",
"kind": "patch",
"published_at": "2026-06-19T01:57:48Z"
},
{
"tag": "v0.1.56",
"kind": "patch",
"published_at": "2026-06-18T16:53:56Z"
},
{
"tag": "v0.1.55",
"kind": "patch",
"published_at": "2026-06-18T03:35:59Z"
},
{
"tag": "v0.1.54",
"kind": "patch",
"published_at": "2026-06-18T02:28:23Z"
},
{
"tag": "v0.1.53",
"kind": "patch",
"published_at": "2026-06-18T00:49:02Z"
},
{
"tag": "v0.1.52",
"kind": "patch",
"published_at": "2026-06-16T15:28:33Z"
},
{
"tag": "v0.1.51",
"kind": "patch",
"published_at": "2026-06-16T15:09:51Z"
},
{
"tag": "v0.1.50",
"kind": "patch",
"published_at": "2026-06-16T05:40:17Z"
},
{
"tag": "v0.1.49",
"kind": "patch",
"published_at": "2026-06-16T04:24:30Z"
},
{
"tag": "v0.1.48",
"kind": "patch",
"published_at": "2026-06-16T04:14:32Z"
},
{
"tag": "v0.1.47",
"kind": "patch",
"published_at": "2026-06-16T02:16:28Z"
},
{
"tag": "v0.1.46",
"kind": "patch",
"published_at": "2026-06-16T00:30:38Z"
},
{
"tag": "v0.1.45",
"kind": "patch",
"published_at": "2026-06-13T04:00:35Z"
},
{
"tag": "v0.1.44",
"kind": "patch",
"published_at": "2026-06-10T19:41:07Z"
},
{
"tag": "v0.1.43",
"kind": "patch",
"published_at": "2026-06-05T13:05:19Z"
},
{
"tag": "v0.1.42",
"kind": "patch",
"published_at": "2026-06-04T06:40:31Z"
},
{
"tag": "v0.1.41",
"kind": "patch",
"published_at": "2026-06-03T05:13:31Z"
},
{
"tag": "v0.1.40",
"kind": "patch",
"published_at": "2026-06-02T15:37:53Z"
},
{
"tag": "v0.1.39",
"kind": "patch",
"published_at": "2026-06-02T04:36:46Z"
},
{
"tag": "v0.1.38",
"kind": "patch",
"published_at": "2026-06-01T01:10:31Z"
},
{
"tag": "v0.1.37",
"kind": "patch",
"published_at": "2026-06-01T01:08:38Z"
},
{
"tag": "v0.1.36",
"kind": "patch",
"published_at": "2026-05-28T03:59:09Z"
},
{
"tag": "v0.1.35",
"kind": "patch",
"published_at": "2026-05-24T02:08:07Z"
},
{
"tag": "v0.1.34",
"kind": "patch",
"published_at": "2026-05-23T20:24:28Z"
},
{
"tag": "v0.1.33",
"kind": "patch",
"published_at": "2026-05-22T02:00:47Z"
},
{
"tag": "v0.1.32",
"kind": "patch",
"published_at": "2026-05-21T15:05:57Z"
},
{
"tag": "v0.1.31",
"kind": "patch",
"published_at": "2026-05-20T21:33:14Z"
},
{
"tag": "v0.1.30",
"kind": "patch",
"published_at": "2026-05-20T03:45:37Z"
},
{
"tag": "v0.1.29",
"kind": "patch",
"published_at": "2026-05-19T06:05:41Z"
},
{
"tag": "v0.1.28",
"kind": "patch",
"published_at": "2026-05-18T16:13:06Z"
},
{
"tag": "v0.1.27",
"kind": "patch",
"published_at": "2026-05-18T16:11:29Z"
},
{
"tag": "v0.1.26",
"kind": "patch",
"published_at": "2026-05-18T05:11:27Z"
},
{
"tag": "v0.1.25",
"kind": "patch",
"published_at": "2026-05-18T04:32:03Z"
},
{
"tag": "v0.1.24",
"kind": "patch",
"published_at": "2026-05-18T01:58:50Z"
},
{
"tag": "v0.1.23",
"kind": "patch",
"published_at": "2026-05-18T01:54:39Z"
},
{
"tag": "v0.1.22",
"kind": "patch",
"published_at": "2026-05-18T01:31:01Z"
},
{
"tag": "v0.1.21",
"kind": "patch",
"published_at": "2026-05-18T01:08:36Z"
},
{
"tag": "v0.1.20",
"kind": "patch",
"published_at": "2026-05-18T00:43:58Z"
},
{
"tag": "v0.1.19",
"kind": "patch",
"published_at": "2026-05-17T23:43:38Z"
},
{
"tag": "v0.1.18",
"kind": "patch",
"published_at": "2026-05-16T22:07:08Z"
},
{
"tag": "v0.1.17",
"kind": "patch",
"published_at": "2026-05-16T19:58:01Z"
},
{
"tag": "v0.1.16",
"kind": "patch",
"published_at": "2026-05-16T17:47:12Z"
},
{
"tag": "v0.1.15",
"kind": "patch",
"published_at": "2026-05-16T15:27:11Z"
},
{
"tag": "v0.1.14",
"kind": "patch",
"published_at": "2026-05-16T15:02:06Z"
},
{
"tag": "v0.1.13",
"kind": "patch",
"published_at": "2026-05-16T14:56:46Z"
},
{
"tag": "v0.1.12",
"kind": "patch",
"published_at": "2026-05-16T14:51:31Z"
},
{
"tag": "v0.1.11",
"kind": "patch",
"published_at": "2026-05-16T14:38:54Z"
},
{
"tag": "v0.1.10",
"kind": "patch",
"published_at": "2026-05-12T02:10:09Z"
},
{
"tag": "v0.1.9",
"kind": "patch",
"published_at": "2026-05-03T04:25:29Z"
},
{
"tag": "v0.1.8",
"kind": "patch",
"published_at": "2026-04-17T01:26:02Z"
},
{
"tag": "v0.1.7",
"kind": "patch",
"published_at": "2026-04-01T06:30:32Z"
},
{
"tag": "v0.1.6",
"kind": "patch",
"published_at": "2026-03-23T17:03:16Z"
},
{
"tag": "v0.1.5",
"kind": "patch",
"published_at": "2026-02-14T15:05:56Z"
},
{
"tag": "v0.1.4",
"kind": "patch",
"published_at": "2026-01-26T16:59:00Z"
},
{
"tag": "v0.1.3",
"kind": "patch",
"published_at": "2026-01-26T14:56:08Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2026-01-25T01:42:05Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-01-25T01:16:18Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-01-25T01:00:01Z"
}
],
"recent_commits": [
{
"oid": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
"body": "…t body\n\nAdds the Option B convenience bridge requested by prompt 752c552c\n(tarball-upload integrity check). Returns lowercase-hex SHA-256 of the\npre-parse request body as an LP-string, so a handler can compare against\na client-supplied X-Tarball-SHA256 without materializing the body in\nlinear memor\n[…]\n.\n\nContract tests: 7 cases covering binary payloads (null bytes, 0xFF,\ntar.gz-shaped), the empty-body baseline, UTF-8 text fallback (including\nmulti-byte / emoji), and additivity with _req_body_bytes.",
"is_bot": false,
"headline": "feat(bridge): _req_body_sha256_hex — one-shot SHA-256 over raw reques…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-18T11:44:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0553773a2ee4e6c2dd193b328bab7ed57237913",
"body": "…utation detection\n\nInstruments repro_http_request.mjs with a heap-forensics probe requested by\nthe compiler team for bug #eed00ffee567 (STATE A truncation V2) attribution.\nTwo flags: --probe-heap enables the probe; --probe-fn <name> adds any custom\nexport (e.g. build_rows) to the wrap set.\n\nWhat it\n[…]\nring_builder_finalize get overwritten by any subsequent import\n (bridge) call, attributing the mutation to the specific bridge.\n\nBaseline unchanged — no flag, no wrapping. Resolves prompt 41e44fdf.",
"is_bot": false,
"headline": "tools(repro): --probe-heap for __heap_ptr rewind + finalize-content m…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-18T11:27:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "88064cc93d8273e59ae8d617a14de75df52fcf08",
"body": "- Move docs/functions-reference.md → spec/ (formal function reference table)\n- Delete system-documents/test-strategy.md (session debris)\n\ndocs/ retains 6 human-readable guides (getting-started, authentication,\ndatabase, files, http-client, http-server). No principal\nNode Server Specification.md yet — README.md serves as introduction.\n\nPart of monorepo-wide docs restructuring.",
"is_bot": false,
"headline": "docs: adopt docs/ + spec/ two-folder structure",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-18T05:28:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5480fe5dfae20dfda6c2e781d5a923bcfb21d6e6",
"body": "Adds Layer 3 dev-mode capture bridge (`_dev_snapshot`) plus request/log\nring buffers scoped to each request worker. Gated on CLEAN_DEV=1; returns\nan empty LP string in production. Log interceptor is idempotent and no-op\nwhen the gate is closed. Full test parity with the Rust host at 36 tests\n(tests/\n[…]\n Acceptable under the\ndev-mode-is-single-user assumption; cross-worker fidelity via main-thread\nRPC is a follow-up if that assumption changes.\n\nHost-parity check (`--host node-server --strict`) clean.",
"is_bot": false,
"headline": "feat(bridge): _dev_snapshot — worker-local dev-mode capture ring buffers",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-17T12:35:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da4361f2c807f5cf1544984ac3981c05995c7145",
"body": "Implements the middle of the binary-safe triad\n _req_body_bytes → _crypto_sha256_bytes → _fs_write_bytes\nso uploads (tarballs, images, arbitrary octets) can be hashed on the\nNode runtime without a UTF-8 decode detour.\n\n- New src/bridge/crypto-sha256-bytes.ts. Handle layout is identical to\n _req_bo\n[…]\n)\n payloads, gzip-like binary payloads, and output format\n (64 lowercase hex chars).\n- Matches function-registry.toml entry _crypto_sha256_bytes shipped in\n the compiler release preceding this one.",
"is_bot": false,
"headline": "feat(bridge): _crypto_sha256_bytes — binary-safe SHA-256 over LP handle",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-14T22:31:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4eea40e70cda66b6e3e7f835c3beb6413f30ea5e",
"body": "Adds two additive bridges to un-stub the errors dashboard's tarball-upload\nendpoint on the Node runtime.\n\n_req_body_bytes: raw request body as an opaque byte sequence. Registers\nexpress.raw for application/octet-stream so binary payloads arrive as a\nBuffer instead of a UTF-8-decoded string. Returns \n[…]\ngic), the 0/1/3/4\nreturn-code taxonomy, allowlist enforcement, atomic-rename with no .tmp\nresidue, overwrite semantics, and Content-Length parity. Host parity check\nnow exits 0 for --host node-server.",
"is_bot": false,
"headline": "feat(bridge): binary-safe request body and atomic byte writes",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-14T06:19:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dac0372b86eadec45489638acd3d85aef939f4ac",
"body": "…nner\n\nSingle-process runner that instantiates a compiled WASM against the real\ncompiled bridge (dist/), sets a fake RequestContext, invokes a named\nroute handler export, and prints response bytes to stdout with forensic\ncontext (result_ptr, LP-prefix length, byte/char counts) on stderr.\n\nPurpose: g\n[…]\nspatch path. Supports\n--dump-memory <off>[:<len>], --dump-hex-output, --wat-out, --json-output\nfor aliasing / truncation forensics.\n\nFirst consumer: compiler bug #eed00ffee567 (STATE A truncation V2).",
"is_bot": false,
"headline": "tools(repro): add repro_http_request.mjs — standalone HTTP handler ru…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-13T20:07:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d3f2a2366182c875ad930c82817a32c6aea5776",
"body": "…ot cause is compiler-side (CODEGEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE)\n\nPins 4 invariants at the node-server bridge boundary against the\n+320-stride pointer-shaped-integer symptom the reporter of\n#61ef80a34ec6 (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER-AGGREGATE-QUERY)\nattributed to a 'stale box sl\n[…]\nEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE (#0ccc47714523,\ncomponent=compiler). This test guards the bridge invariants so that a\nfuture regression at THIS layer surfaces separately from the compiler bug.",
"is_bot": false,
"headline": "test(bridge): regression pin for aggregate json.get + .toInteger — ro…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-13T04:56:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a115f34aabfa24f57aa256d57b99bffc1ac76fac",
"body": "Adds push tag 'v*' as a trigger now that the workflow_dispatch dry run\nis green. Every tagged release must pass all open reporter-artifact\nreplays before shipping.",
"is_bot": false,
"headline": "ci(reporter-artifacts): enable release-tag trigger",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-13T01:36:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "259679b5a1410453e694866d3baedfd2cb8d2de3",
"body": "Runs every open reporter-artifact issue's replay tarball against this\ncheckout's built node-server. Manual-dispatch only for initial rollout;\nrelease-tag trigger will be added after first green run.\n\nInstalls cln + this checkout's clean-node-server build globally so\ntarballs invoke the local build via PATH.",
"is_bot": false,
"headline": "ci: add reporter-artifacts replay workflow (closed-loop bug workflow)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-13T01:34:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eeca6ddc09739bd1a8f46ceb145879ca56b6fb50",
"body": "Adds .nvmrc → 20. Contributors with nvm auto-switch to Node 20 on `cd`\ninto the repo (or `nvm use`), matching CI (Node 20 in publish.yml) and\nthe >=18 requirement declared in package.json engines. Also unblocks\nthe pre-push hook on machines whose system Node predates vitest 2's\nminimum.\n\nRegenerates\n[…]\nson — the previous lockfile was written by an\nold npm and still claimed version 0.1.53. Re-locked under npm 10 on Node\n20 so `npm ci` in CI stays consistent with what a fresh install produces\nlocally.",
"is_bot": false,
"headline": "build: pin Node 20 via .nvmrc; refresh lockfile",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T15:55:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d23e65577583b5c8511ecf9a0ee63df57259020",
"body": "The previous injectArray helper walked the store to find the next handle\nabove the highest injected key, but that did not advance the module's\ninternal nextHandle counter. As a result, after\n resetArrayStore() // nextHandle = 1\n injectArray([...]) // store[1] set, nextHandle still 1\n bridge.arr\n[…]\nnextHandle keeps counting from 1 for\nstoreArray-minted handles, and never collides with the injected range in\nany realistic test.\n\nNo source changes — the bridge is correct; the test helper was wrong.",
"is_bot": false,
"headline": "test(bridge): array-bridge injectArray helper uses high handle range",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T15:01:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce1ac734772cbc3e9abcc9718d1dd95037e57c4d",
"body": "…w bridge tests\n\nAdds a comprehensive test strategy with five tiers (policy, unit, contract,\nintegration, canary) enforced by git hooks and CI:\n\n - scripts/check-test-policy.mjs (Tier 0): blocks skipped tests without\n a `// policy-allow-skip: <reason>` justification, placeholder markers,\n emp\n[…]\ncomment.\n\nThe --no-verify used here is bootstrap-only: the pre-commit hook it\ninstalls cannot run against itself before it exists, and vitest 2 cannot\nboot on this machine's Node 16 (CI runs Node 20).",
"is_bot": false,
"headline": "test(strategy): tiered test suite with policy guard, hooks, and 12 ne…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T14:58:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "68743811f74659b7a40c5fb6759e91f354e6557e",
"body": "…alues — resolves RUNTIME-INT-VALUES-ARE-POINTERS-STATS-STRIP\n\nAdds an end-to-end regression pinning the reporter's flow: repeated\ndb.query→_json_get→numeric-string leaf must yield the exact digits, not\n+320-stride pointer-shaped values. Complements the existing hand-rolled\nJSON case in tests/json-g\n[…]\npath a compiler-emitted handler takes.\n\nThe underlying fix (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER, commit\nb14f101 in v0.1.88) already addresses the root cause — this test\nprevents silent regression.",
"is_bot": false,
"headline": "test(bridge): pin db.query→json.get→numeric leaf against ptr-shaped v…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T14:17:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9f61d33def7afe06340a2fa3ad2264b74297913c",
"body": "… resolves NODE-SERVER-UI-RENDER-PAGE-NO-SUBSTITUTION\n\nAlign _ui_render_page with HOST_BRIDGE.md line 419 spec and frame.ui plugin\nconvention (v3.2.7). Templates use { key } single-brace substitution with\nwhitespace tolerance and dotted paths; {{ and }} emit literal { and }.\n\nPrevious implementation\n[…]\n { item.field } placeholders per-iteration before the\nglobal pass. Key validity is restricted to identifier / dotted-path form,\nso CSS bodies and JSON literals containing { } are left as literal text.",
"is_bot": false,
"headline": "fix(bridge): _ui_render_page uses single-brace { key } substitution —…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T05:43:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b14f1018dc4e4d5de4cc7123e8cc0ff88df1b4ee",
"body": "…GE-JSON-GET-INTEGER-RETURNS-POINTER\n\nCompiler 0.33.55 + frame.server 2.8.4 declared _json_get with\nparams=['any','string'], returns='any', expand_strings=false. The bridge\nkept the old 4-arg (jsonPtr,jsonLen,pathPtr,pathLen) shape and returned\na raw LP-string pointer, so the compiler's emit_unbox_a\n[…]\n Migrated the\nthree existing test files that were exercising the old 4-arg ABI to\nthe new signature — they now box the JSON input and unbox the result\nthe same way the compiler does at each call site.",
"is_bot": false,
"headline": "fix(bridge): _json_get switches to any-in/any-out ABI — resolves BRID…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-12T05:23:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eaef219ad135be395e68afc724b48722b87daca7",
"body": "…-SERVER-BRIDGE-OOB-TASKS-FILTER\n\nfoundation/platform-architecture/function-registry.toml declares mem_scope_push\nand mem_scope_pop as \"no-op currently\" for every host, and clean-server's Rust\nbridge treats them that way. This bridge previously called the WASM-side\nscope_pop export on every internal\n[…]\nrn from\nthe bug survives an internal pop. All 383 vitest tests pass; 14/15 canaries\npass (http_client canary DIFF is a separate compiler-side canary bug).\n\nFix commit for fingerprint 654ef241296a631e.",
"is_bot": false,
"headline": "fix(bridge): make mem_scope_pop a no-op for WASM heap — resolves NODE…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-11T16:16:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6cb315f90d1bff73ea55e3029947d370fee5289",
"body": "Pins the db.query + json.get + string.concat pattern reported as trapping\n\"memory access out of bounds\" on node-server 0.1.85. Cannot reproduce\nend-to-end against clean-errors/dist/errors.wasm today (20x sequential +\n10x concurrent /tasks?origin=error return HTTP 200) — likely already\nfixed by compi\n[…]\nesses:\n- Sequential _db_query responses don't overlap\n- Driver errors surface as parsable {ok:false} envelopes (not raw bytes)\n- _json_get chain preserves LP-string integrity under a healthy allocator",
"is_bot": false,
"headline": "test(bridge): regression harness for NODE-SERVER-BRIDGE-OOB-TASKS-FILTER",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-11T15:45:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81bb3345ebcf752e205575403ac38a661b500916",
"body": "_time_now now returns BigInt(unixSeconds) per foundation/platform-architecture\n/function-registry.toml — the registry declares it as `returns = \"i64\"` and\nNode's WebAssembly bindings require host functions bound to i64 result to\nreturn a BigInt. Previously node-server returned a heap pointer to a JS\n[…]\nal host runs with\n`--sandbox /tmp` for a file-heavy workload. Fixes the file canary DIFF\nwhere writes to /tmp/clean_canary_file.txt were rejected as\noutside-sandbox and the round-trip silently failed.",
"is_bot": false,
"headline": "fix(bridge): correct _time_now signature + canary driver sandbox root",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-09T00:26:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2224fba849fd124e0147e7d051df98b7815ec2e0",
"body": "Implements the node-server child of the Cross-Component Contract\nCanaries umbrella (prompt 6ace888b-7a8d-11f1-9586-da25a95a496b,\numbrella 7fb425cb-79ba-11f1-9586-da25a95a496b).\n\nscripts/run_canaries.mjs discovers the compiler's canary corpus,\nfilters out browser-only namespaces, compiles each canary\n[…]\ns (env/file/http_client diffs, time trap). The time trap\n(_time_* i64/BigInt signature drift) is filed as\nNODE-SERVER-TIME-I64-BIGINT. The other three DIFFs need follow-up\ninvestigation before filing.",
"is_bot": false,
"headline": "feat(canaries): add Layer-2 nightly canary runner",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-09T00:10:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "680d2b32b3f55d0f4550faba5b4de80f9203091f",
"body": "…SERVER-CGROUP-THROTTLE-WEDGE)\n\nWorker rotation was gated only on `readHeapPtr() - initialHeapPtr > 50MB`.\nscope_pop rewinds `__heap_ptr` but WASM `memory.grow()` is permanent — a\nsingle request that momentarily needed 60MB permanently extended\n`memory.buffer.byteLength`, but the rotation check saw \n[…]\n recycling.\n\nComplements the --memory-soft-limit mitigation shipped in 0.1.81: that\nprevents an unrecoverable wedge if the leak still happens, this stops the\nleak from accumulating in the first place.",
"is_bot": false,
"headline": "fix(pool): rotate on memory.buffer growth, not just __heap_ptr (NODE-…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-08T20:44:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "01f6ba6a544f4b23ac9ac3d925c4d705359e7861",
"body": "Adds Cross-component prompts section to CLAUDE.md (mirrors the wording\nalready in the project-root CLAUDE.md) and allows a few read-only bash\npatterns previously prompted for.",
"is_bot": false,
"headline": "chore: document team-prompt skills and expand bash allowlist",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-08T18:13:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73ff058b9b5572e983a996a72cea6881291d2a28",
"body": "Implements FRAME-AUTH-REFRESH-TOKEN-NO-ROTATION and\nFRAME-AUTH-RESET-TOKEN-BRIDGES-MISSING per function-registry.toml:\n\n- _jwt_refresh_and_rotate: verify + atomically consume a refresh token's\n jti and return a freshly-signed token (AUTH-J007 / AUTH-J009 single-use\n rotation). Rejects replays, tok\n[…]\n-present in one\n event-loop tick). Expired entries return 0 and are swept lazily.\n\nBoth stores expose reset* test helpers; 9 unit tests cover round-trip,\nreplay rejection, expiry, and invalid inputs.",
"is_bot": false,
"headline": "feat(bridge): add _jwt_refresh_and_rotate + _auth_reset_token bridges",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-08T18:13:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5e2a68507706c085c9bd651f59e2c9649c0a7911",
"body": "… cgroup wedge\n\nUnder a systemd unit with MemoryMax, once RSS hits the ceiling the process gets\npinned in kernel mem_cgroup_handle_over_high (uninterruptible sleep) on the\nnext allocation. The listening socket stops responding and only SIGKILL clears\nit — Restart=always cannot rescue a D-state task \n[…]\nrprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1). This is\na mitigation, not a leak fix — the underlying host-bridge scope tracking\n(part 2 of the suggested fix) is a follow-up.",
"is_bot": false,
"headline": "feat(cli): add --memory-soft-limit for graceful drain-and-exit before…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-08T15:34:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d9321fe14eca537abf5897d0f7e20fa4571cfc9",
"body": "The ws module was in devDependencies but imported at runtime, so production\ninstalls threw ERR_MODULE_NOT_FOUND from attachWebsocketServer(). Pino's err\nserializer expanded that into a multi-line requireStack trace on every process\nstart, and the rejected import promise held the request-scope closur\n[…]\nered no WS routes — avoids\n loading ws (~1MB heap) for API-only deployments.\n\nPart of NODE-SERVER-CGROUP-THROTTLE-WEDGE (fingerprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1).",
"is_bot": false,
"headline": "fix(bridge): make ws an optional dependency and skip attach when unused",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-08T15:33:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c3e74175b73ec723bae727a614dcc9034ca1d82e",
"body": "…ING-READ-OOB-INTERMITTENT)\n\nreadRawString and readLengthPrefixedString now emit console.error with\nptr, len, bufferSize, a hex dump of bytes at ptr, the length reinterpreted\nas 4 little-endian ASCII chars, and a stack trace before throwing.\n\nThe intermittent case observed in production (len=1684632\n[…]\nbleed remain in place\n(scope_push/scope_pop rewind, per-request JS accumulator reset, worker\nrotation on error). This commit closes the diagnostic gap so future\noccurrences are not silent server-side.",
"is_bot": false,
"headline": "fix(bridge): log forensic context on OOB string read (NODE-SERVER-STR…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-07T02:07:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b8e36c18175eca602bcc135ebf2a6a8fe9d6d77",
"body": "The 0.1.78 workflow failed because clean-language-spec has foundation/\nas a subfolder at its root, not the root itself. Full checkout put the\nscript at $WORKSPACE/foundation/foundation/management/scripts/... but\nCLEAN_LANGUAGE_ROOT was set to $WORKSPACE, so the script wasn't found.\n\nFix: sparse-chec\n[…]\ne foundation/ subtree into a staging dir\n(_spec/), then move _spec/foundation to $WORKSPACE/foundation. This\ngives the layout the parity script expects (<root>/foundation/,\n<root>/clean-node-server/).",
"is_bot": false,
"headline": "ci(parity): sparse-checkout foundation subtree from clean-language-spec",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-06T14:56:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd2413dd46ba08df9b82441e86fbdeb0698e98c4",
"body": "Adds a 'parity' job to the publish workflow that runs\ncheck_host_parity.py --host node-server --strict on every pull request\nand tag push. The job checks out clean-language-spec as a sibling of\nthis repo and points CLEAN_LANGUAGE_ROOT at the workspace so the script\nresolves foundation/ and clean-nod\n[…]\nng no-op stubs; this closes the systemic gap).\n\nVerified locally:\n- baseline parity check: missing 0, exit 0\n- with _arena_scope_push/_pop removed: missing 2, exit 1\n- full test suite: 359/359 passing",
"is_bot": false,
"headline": "ci(parity): enforce host bridge parity against function-registry.toml",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-06T14:53:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a9b9224b9645259bc45b8a65dfded0c0b6b89e7f",
"body": "…E-E001)\n\nCompiler 0.31.5+ (confirmed on 0.33.2) emits env._arena_scope_push\n(() -> i32) and env._arena_scope_pop (i32 -> void) as WASM imports on\nevery module. clean-node-server 0.1.72-0.1.76 shipped without handlers,\ncausing every fresh WASM to fail WebAssembly.instantiate with\n\"function import re\n[…]\n33.2-produced errors.wasm and\nvia a direct WebAssembly.instantiate smoke test — module now loads\nwithout LinkError. Regression test added in\ntests/arena-scope-bridges.test.ts.\n\nBumps 0.1.76 -> 0.1.77.",
"is_bot": false,
"headline": "fix(bridge): add _arena_scope_push/_arena_scope_pop stubs (HOST-BRIDG…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-07-06T14:41:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3bf77aa0ca21a378255b80a8d713e272d9cc1403",
"body": "Port clean-server/src/locale.rs to TypeScript. Closes the host-parity gap\nfor the 8 _i18n_* bridge functions previously stubbed to throw at runtime.\n\nThe TypeScript LocaleState mirrors the Rust observable behavior:\n - JSON translation maps flattened to dot-separated keys.\n - BCP-47 fallback chain:\n[…]\n for some locales than the\nRust host. Inline matches Rust output exactly.\n\nCloses the i18n entry on Step 4 of the host-bridge-parity-enforcement\nprompt (was throw-error stub; now real implementation).",
"is_bot": false,
"headline": "feat(bridge): implement frame.locale (i18n) — replace throw-error stubs",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-29T20:50:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2b890e7973a00983972428fd1fe0786e15f58b32",
"body": "Port clean-server's build-manifest reader (Plugin Contracts v2 §5/§8) to\nTypeScript. At startup the server looks for build-manifest.json next to\nthe main WASM. When present, it is the authoritative source for artifact\npaths: the client_hydration artifact (frontend.wasm) is served from the\ndeclared p\n[…]\nrser + path resolver (TS port of build_manifest.rs)\n- src/server.ts: manifest-first frontend.wasm + auto-registered artifact routes\n- tests/build-manifest.test.ts: 11 tests mirroring the Rust test set",
"is_bot": false,
"headline": "feat(server): read build-manifest.json for artifact resolution (SRV004)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-29T20:46:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "657359ac56473033b00941291313537bab1e87f7",
"body": "The frame.ui plugin removed _ui_inject_head_css entirely (theme values now\nlive in public/css/theme.css and ship via _ui_inject_head_link). Drop the\nhost implementation, the registration, and the state.injectedCss accumulator\n(types, pool, worker, test). See the\nall-remove-ui-inject-head-css-bridge \n[…]\nno longer\nlisted as MISSING (was never MISSING here — the implementation existed; the\nregistry no longer requires it). Remaining MISSING/UNKNOWN counts are\npre-existing drift unrelated to this change.",
"is_bot": false,
"headline": "chore(bridge): remove orphaned _ui_inject_head_css",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-29T20:43:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e37f1658efc1869cd40943fe520d3b76b37ce10f",
"body": "… config bridges (BRIDGE_REG_002)\n\nCompiler 0.30.362+ lowers integer:64 .toString() to an env.int64_to_string\nWASM import. Without this bridge function the Node host fails to\ninstantiate any module that uses 64-bit integer toString. Bridge receives\na JS BigInt (Node's surfacing of WASM i64) and uses\n[…]\net_global_error_handler)\npaired with upstream FRAME-SERVER-CONFIG-FIELDS-UNIMPLEMENTED — signatures\nfollow that report's suggested fix and may need adjustment if the\nframework PR picks different ones.",
"is_bot": false,
"headline": "fix(bridge): add int64_to_string + _mcp_http_respond, scaffold server…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-26T14:46:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52b0ce4ed998a75de1c86cc5ed5e7b8740981d07",
"body": "…-WRAP-INCOMPLETE)\n\nscope_push/scope_pop correctly rewind the WASM bump heap per request, but\nthree bridges keep module-level Maps that grow with every allocation and\nare never reclaimed:\n\n - bridge/list.ts: listStore (handle -> JS array)\n - bridge/array.ts: arrayStore (handle -> JS array)\n - bri\n[…]\nope_pop on both the success and\nerror paths. Safe because scope_pop has already reclaimed the WASM heap\nthe handles pointed into — any caller holding a stale handle is already\nholding a stale pointer.",
"is_bot": false,
"headline": "fix(bridge): release JS-side accumulators per request (NSR-HTTP-SCOPE…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-23T13:53:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6d9509e968e3659e0a44e3c6d03838b6009c913",
"body": "…ry coverage test\n\nThe compiler stopped emitting dot-notation bridge aliases in v0.30.123\n(see node-server CLAUDE.md \"Bridge Function Naming — Canonical Names Only\").\nThe ui.ts client-stub map kept 58 'ui.X': noop entries from that era,\nshadowed by their canonical _ui_* siblings two sections above. \n[…]\nng=0 unchanged; unknown dropped 209 → 159 (the\nremaining residual is real registry gaps tracked in\nfoundation/management/cross-component-prompts/all-registry-backfill-server-and-builtin-functions.md).",
"is_bot": false,
"headline": "chore(bridge): drop dead ui.X dot-notation registrations + fix regist…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-23T06:07:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53c8a64b9baead0491d0e58d6883cd52975fdd1a",
"body": "…-REQUEST-MEMORY-RELEASE)\n\nThe HTTP request path already wraps its handler in scope_push/scope_pop\n(commit efc7cc0), but three other handler-dispatch sites that share the\nsame long-lived init WASM instance kept advancing __heap_ptr forever:\n\n - src/workers/sse-worker.ts: each SSE connection's emitt\n[…]\ntation, and add it to the three new\nsites. The wrapper is a no-op against modules compiled with\npre-0.30.330 compilers (no scope_push/scope_pop exports), matching\nthe existing request-worker fallback.",
"is_bot": false,
"headline": "fix(bridge): wrap SSE/cron/job handlers in per-call scope (NSR-NO-PER…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-23T05:45:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "93f995781b7c9edeca1148cd80e99a7cf2439350",
"body": "…VER-UI-RENDER-PAGE-INTERP-STRICT-WHITESPACE)\n\nReplace the regex `/\\{([\\w.]+)\\}/g`, which only matched single-brace\n`{key}` with no internal whitespace, with a single-pass `{{ … }}`\nscanner. Matches HOST_BRIDGE.md / function-registry.toml (`{{ key }}`\nwith whitespace tolerated, missing keys → empty string) and the\nclean-server v1.9.57 sibling implementation. Single-brace `{key}` is\nintentionally no longer consumed so it stays available for the\ncl-iterate directive's item placeholders.",
"is_bot": false,
"headline": "fix(bridge): _ui_render_page substitutes {{ key }} per spec (NODE-SER…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-22T06:11:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "efc7cc0ae0c296a513211e4b1fecfdc870c81d7a",
"body": "…p per request (CNS-MEM-SCOPE-POP)\n\nmem_scope_push now snapshots state.exports.scope_push(); mem_scope_pop\nhands the snapshot to state.exports.scope_pop(), rewinding __heap_ptr.\nThe request worker brackets each handler invocation (including the\nerror path) with the same primitives so __malloc alloca\n[…]\n concatLengthPrefixed — which never go\nthrough mem_alloc and so can't be reclaimed by the per-allocation refcount\npath — are released at request boundaries instead of leaking until the\nworker rotates.",
"is_bot": false,
"headline": "fix(bridge): consume compiler scope_push/scope_pop to rewind WASM hea…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-21T00:31:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a9c2531c7168da3dba57a409e503d7de7af1f56",
"body": "The 7679a9e fix (0.1.65) and b50d2e0 (0.1.66) added the defensive\n__heap_ptr bump to concatLengthPrefixed, string_split,\nwriteLengthPrefixedString, and writeRawBytes, but mem_alloc was\noverlooked. The compiler emits mem_alloc for every non-string object\n(records, list element slots, struct/class ins\n[…]\nogy used by nsr002-heap-ptr-overlap, covering\nconsecutive non-overlap, sentinel survival across interleaved string\nwrites, the 30-card prod render pattern, alignment, and the zero/negative\nsize no-op.",
"is_bot": false,
"headline": "fix(bridge): mem_alloc bumps __heap_ptr after every allocation (NSR002)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-20T14:31:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b50d2e084e4bc76697da9b46e121f1a730520957",
"body": "The compiler's __malloc uses the __heap_ptr exported global as a bump\npointer, but doesn't reliably advance it when re-entered from a host\nbridge call. By the time control returns to JS, the global is still at\nits pre-call value — so the next bridge malloc hands out an overlapping\npointer, the next \n[…]\nvery malloc (the\nexact prod pathology) and asserts that consecutive writeString,\nstring.concat, _json_get + concat (30-card render loop), and\nstring_split all survive without length-prefix corruption.",
"is_bot": false,
"headline": "fix(bridge): defensively bump __heap_ptr after every malloc (NSR002)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-20T13:53:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7679a9e893a7741e386b73ae8a8820555e86edfd",
"body": "…sion)\n\nThe 0.1.63 byte-level rewrite added an empty-input short-circuit that\nreturned one of the input pointers verbatim when the other was empty,\nas a malloc-saving optimization for the 30-card render loop. The\noptimization aliased the input into the result, which broke the\nownership invariant the\n[…]\nmutating an input buffer after concat must not change the result.\n- Updated the two short-circuit-aliasing pins that captured the 0.1.63\n optimization to expect fresh buffers with equivalent content.",
"is_bot": false,
"headline": "fix(bridge): string.concat always returns fresh buffer (NSR002 regres…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-20T03:23:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e0e159d969bb7efb25d38fcba52d7b8419503b80",
"body": "…E_STRING_SPLIT)\n\nThe compiler's `iterate part in parts` reads list size from offset 0 of\nthe returned pointer and element pointers at offset 16 + i*4. Returning a\nJSON-encoded length-prefixed string meant offset 0 held the JSON byte\nlength (e.g. 17 for `[\"a\",\"b\",\"c\",\"d\"]`), so the loop ran 17× past\n[…]\nclean-server's write_string_list_to_caller and the\nwasmtime_runner reference.\n\nUpdated bridge-abi tests to assert the list layout, including the exact\n\"a```b```c```d\" / \"```\" repro from the dashboard.",
"is_bot": false,
"headline": "fix(bridge): string.split returns Clean list, not LP-JSON (HOST_BRIDG…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T23:51:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5e0911925ed66e4fa84a18845656aded9ecd2f8",
"body": "The compiler emits byte-position substring inline, so iterating a string in\na `while i < s.length(): i += 1` loop over multibyte UTF-8 (em-dash E2 80 94,\narrow E2 86 92, CJK, emoji) yields a sequence of length-prefixed fragments\neach holding a single continuation byte. The previous string_concat dec\n[…]\n prod-symptom reproducer (prod WASM md5 14b8276e..., prod\nDB via SSH tunnel): /tutorials goes from 38 U+FFFD / 0 em-dashes preserved\nto 0 U+FFFD / 12 em-dashes preserved across 5 consecutive requests.",
"is_bot": false,
"headline": "fix(bridge): string.concat joins at byte level (NSR002)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T19:58:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45aff4ec840f396f36a0167e809b916e8a60116d",
"body": "…NSR002)\n\nAdds two more guards on top of utf8-roundtrip:\n\n- http-utf8-wire.test.ts: stands up the real Express middleware stack\n (compression, json, urlencoded, cookieParser, express.text) and verifies\n res.type + res.send preserve multibyte UTF-8 on the wire across text/plain,\n text/html, applic\n[…]\n round-trip, IPC, and Express's response pipeline. The\nproduction U+FFFD symptom isolated to none of them in unit/integration\ntesting — a regression introduced in any layer will now break loudly here.",
"is_bot": false,
"headline": "test(bridge): pin HTTP wire + SharedArrayBuffer IPC UTF-8 contracts (…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T17:33:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "49737ebcc4ce0923f238c772f7a649439315b241",
"body": "NSR002 claimed clean-node-server corrupts multibyte UTF-8 in HTTP response\nbodies (em-dash bytes surfacing as U+FFFD chars). Investigation showed the\nhost bridge actually preserves UTF-8 across the full request flow when given\nvalid input: writeLengthPrefixedString / readLengthPrefixedString use\n`by\n[…]\nhows up in\nproduction traffic, WASM memory contained invalid UTF-8 before the bridge\nread it, so the corruption is upstream (compiler-emitted string-length\nhandling or framework http.respond wrapper).",
"is_bot": false,
"headline": "test(bridge): pin multibyte UTF-8 round-trip contract (NSR002 triage)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T16:08:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec1bb6f132275a1544245d1f92a68cccce2d7aab",
"body": "RouteRegistry.match() did a strict method check, so HEAD requests against\nGET-registered routes (including /health, /metrics, and every WASM route)\nreturned 404. Load balancers and uptime probes using HEAD got false negatives.\n\nRFC 9110 §9.3.2: HEAD must be served identically to GET with the body\nsu\n[…]\nD', so the fix is localised to the registry — try the\nrequested method first, and for HEAD fall back to the GET route. Explicit\nHEAD handlers still win because the first pass runs before the fallback.",
"is_bot": false,
"headline": "fix(router): HEAD falls back to GET handler (HTTP-HEAD-RETURNS-404)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T13:50:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af0d898a49497948486574e978e59ca1fdede9b4",
"body": "… failure\n\nCompiler 0.30.321 ships MALLOC-IGNORES-MEMORY-GROW-FAILURE — __malloc now\nreturns 0 (null) when memory.grow refuses to grow instead of returning a\ncorrupted pointer. The old bridge guard treated null-pointer and\nout-of-bounds-pointer as the same misleading \"WASM heap exhausted (see\nNSR002\n[…]\non message users have been seeing was\nthe symptom of the upstream allocator bug; with the compiler fix shipped\nand this bridge message updated, the user-visible failure now describes\nthe actual cause.",
"is_bot": false,
"headline": "fix(bridge): report null malloc clearly now that compiler honors grow…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T12:56:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c6141f5a60235d240eaeb7453d08a6b535c37f71",
"body": "…lookup\n\nThe dot-path walker used `(current as Record<string, unknown>)[part]` for\nevery step, so `items.length` returned the array length, `items.push`\nreturned the function, and `items.constructor` returned `Array` — none of\nwhich should be reachable via a JSON path. Mirrors clean-server's\nhost-br\n[…]\nGNORES-MEMORY-GROW-FAILURE, #d8fba3f01151) — this commit closes a\nseparate correctness divergence from clean-server in the same bridge\nfunction. Adds tests/json-get-bridge.test.ts; 163/163 tests pass.",
"is_bot": false,
"headline": "fix(bridge): _json_get rejects Array.prototype keys and uses own-key …",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T06:01:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b1f6e8b558edbe62564c0e34d33b9323703c86a",
"body": "Adds a regression test that proves _http_respond writes state.response.status\nunconditionally regardless of any prior _http_set_cache / _http_no_cache call.\nThe two reports (5ac075ee, 70f95ccc) misclassified against node-server were\ncaused by frame.server's auto-wrap emitting a second _http_respond(200, ...)\nafter the helper had already set 4xx. Reclassified to framework; new bug\n276d424935c8 (FRAME-SERVER-AUTO-WRAP-CLOBBERS-STATUS) tracks the real fix.",
"is_bot": false,
"headline": "test(bridge): pin _http_respond status contract (RUN001/RUN002 triage)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T04:40:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c78422a0ddccd3d133b3dbcccee44996a1048e61",
"body": "…NTIME-DB-POOL-WEDGE)\n\nTransaction begin/commit/rollback used release() in finally blocks even when\nthe underlying op threw. mysql2 connections that error mid-stream still have\nunconsumed response bytes; releasing them back into the pool causes the next\nconsumer to trip PROTOCOL_PACKETS_OUT_OF_ORDER\n[…]\nequest-seq to the worker SAB so a timed-out sendAndWait no longer\n leaves the worker free to clobber the next request's payload buffer.\n- 12 tests covering destroy-vs-release across every error path.",
"is_bot": false,
"headline": "fix(db): destroy mysql pool connections on error to prevent wedge (RU…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-19T01:57:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7ffadb3bfd848865aabdccc2684b83650718f082",
"body": "…T-INSERT-ID-ZERO)\n\nThe db bridge dispatches each call against a fresh pooled MySQL connection,\nso LAST_INSERT_ID() — session-local — saw a different connection than the\nprior INSERT and returned 0. SQLite (single-connection) was not affected;\nPostgreSQL uses RETURNING and has no equivalent function\n[…]\nb_execute (sync + async paths)\n- tests: 14 new cases covering alias parsing, response shape, INSERT\n detection, and the round-trip cache (INSERT -> SELECT -> cached id,\n no driver hit on the SELECT)",
"is_bot": false,
"headline": "fix(db): cache last_insert_id across pool connections (FRAME-DATA-LAS…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-18T16:53:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1976bf26ad05ed0207dedfd70a46f909518c1c6",
"body": "…R-PAGE-MUSTACHE-SYNTAX-MISMATCH)\n\nThe substitution regex previously matched {{key}} (double-brace mustache),\nbut the canonical syntax — emitted by the frame.ui plugin's process_html\nexample and implemented by Rust clean-server — is {key} (single-brace).\nCompanion-page templates serving through clean-node-server were returned\nwith placeholders intact.\n\nAligns the node-server implementation with substitute_template in\nclean-server/src/bridge.rs.",
"is_bot": false,
"headline": "fix(bridge): _ui_render_page uses {key} single-brace syntax (UI-RENDE…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-18T03:35:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e5e1bfe422509c74773f2cb35160ef5137269471",
"body": "…SPOND-RETURNS-ZERO-CLEARS-BODY)\n\nThe compiler-emitted route wrapper takes the _http_respond return value and\npasses it as the body pointer to a second _http_respond call. Returning 0 caused\nthe response body to be cleared. Matches Rust clean-server's\nwrite_string_to_caller(body) pattern and the registry's `returns = \"ptr\"`.",
"is_bot": false,
"headline": "fix(bridge): _http_respond returns body pointer instead of 0 (HTTP-RE…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-18T02:28:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e68c9b343ab4b7fd534fdf16c25c35cf99322da",
"body": "…n (NODE-MEM-ALLOC-SIGNATURE-MISMATCH)\n\nThe compiler emits memory_runtime.mem_alloc with signature (type_id: i32, size: i32) -> i32, but the JS bridge declared a single `size` parameter. JS silently dropped the second argument, so every WASM allocation called mem_alloc(0, N) and was read as size=0, \n[…]\nurned 0, and json.encode of any string produced the literal \"null\".\n\nBrings the Node host into line with function-registry.toml and the Rust host in clean-server/host-bridge/src/wasm_linker/memory.rs.",
"is_bot": false,
"headline": "fix(bridge): mem_alloc accepts (type_id, size) per compiler conventio…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-18T00:49:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc2ca5e17ccfec28f1a1c495c82814f841d9116d",
"body": "…pe (DB-BUILD-WHERE-IGNORES-DUNDER-WHERE)\n\nbuild_where_clause treated every JSON key as a column name, producing\n`WHERE __where = ?` with the SQL fragment bound as a parameter whenever\nthe framework's frame.data plugin emitted `{\"__where\":\"<fragment>\"}` for\nModel.paginate: / Model.cursor: where: blo\n[…]\nh\nno parameter binding; `__order` is validated against a strict charset\nand surfaced via WhereResult.orderBy so _db_paginate can splice it into\nORDER BY. Matches the protocol shared with clean-server.",
"is_bot": false,
"headline": "fix(bridge): honor __where/__order reserved keys in where_json envelo…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T15:28:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "163aa8e95667fbfc78b5afff5d7a22e7a0328521",
"body": "…VER_MEM_LEAK)\n\nTwo leaks identified from production telemetry on a node-server process\nthat hit its cgroup MemoryHigh limit after days of uptime:\n\n1. request-worker.ts: the error path hardcoded `needsRestart: false`\n and never incremented `requestCount`. WASM has no GC, so a partially\n advanced\n[…]\nhestration, which is beyond unit test reach without significant\nmocking scaffolding. Existing 121-test suite still passes; production\nverification is the cgroup-limited reproduction in the bug report.",
"is_bot": false,
"headline": "fix(worker): rotate on error path + sequence terminate→spawn (NODESER…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T15:09:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c3619c4a46fb3dcf3b7b22daea88a411c4c7d3bf",
"body": "…or stubs\n\nReplaces the throw-error stubs in three bridge modules with full\nimplementations matching clean-server (Rust) behaviour, closing the\nparity gap tracked in node-server-stub-implementations-triage.md.\n\n- schedule.ts: ported 5-field cron parser + setTimeout timer wheel.\n startScheduler(stat\n[…]\nss-component bug\nDBWHERE_RAW_FRAGMENT against frame.data so both hosts can be fixed\ntogether rather than diverging node-server alone.\n\nFull vitest: 121/121 (84 prior + 37 new).\nHost parity: missing=0.",
"is_bot": false,
"headline": "feat(bridge): implement schedule/jobs/websocket — burn down throw-err…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T05:40:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a7dfc82d1bd23814a16dd8fad75f8c824814a9a",
"body": "…-drift fix\n\nFrame.server plugin.toml originally declared _server_sleep params as\n[\"i32\"], so the WASM import wired up as (i32) -> void. Node-server's\nhandler matched that with `ms: number`. Clean-framework now corrects\nplugin.toml to [\"integer\"] (committed in clean-framework as\n0e5547b@main), align\n[…]\nloop. Millisecond\nsleep durations fit safely in a JS number.\n\nCloses the PLUGIN-REGISTRY-DRIFT diagnostic fingerprint\nf952554dd54431f7 (cln dev-queue), the last drift the validator was\nstill flagging.",
"is_bot": false,
"headline": "fix(bridge): _server_sleep accepts bigint (i64) per registry/registry…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T04:24:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "489c8321d13f2067a95e2d586f0b69ac21adc52f",
"body": "Replaces three throw-error stubs with real SQL builders that hit the\nexisting state.database.querySync path. The clean-server implementations\ndelegate to a `db_bridge.call(\"paginate\" | \"cursor_page\" | \"valid_field\")`\nabstraction that doesn't exist in node-server; these versions inline the\nSQL direct\n[…]\nng, cursor\npredicate, and has_more detection).\n\nCloses Step 8 items 1-3 in\nfoundation/management/cross-component-prompts/\n all-host-bridge-parity-enforcement.md. Remaining: schedule, jobs,\nwebsocket.",
"is_bot": false,
"headline": "feat(bridge): implement _db_paginate, _db_cursor_page, _db_valid_field",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T04:14:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "05185ef8f1098cd4df5a39856ad6230d96e0a611",
"body": "…RTE002)\n\nThe _http_route and _http_route_protected bridges previously took a numeric\nhandler index and node-server reconstructed __route_handler_${index} at\ndispatch time. The framework actually passes the WASM export name as a\nstring (e.g. __route_handler_get__ping) per the function-registry.toml\n\n[…]\nts callHandler,\n bridge/test.ts) look up exports[handlerName] directly.\n- New test guards against regressing the naming reconstruction.\n\nCloses RTE002, RTE002-FRAMEWORK (×2). 73/73 vitest tests pass.",
"is_bot": false,
"headline": "fix(router): dispatch handlers by export name, not sequential index (…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T02:16:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "446286717ec35c56135906bed44197d20786f427",
"body": "… gaps\n\nThree independent fixes uncovered while running tests:\n\n1. _test_http_request signature corrected to 10 raw (ptr, len) pairs.\n Was using 5 length-prefixed pointers (readPrefixedString); the\n compiler (wasmtime_runner.rs) and clean-server (bridge.rs:3347)\n both emit/expect the 10-i32 fo\n[…]\nalidate which compiler v0.30.123+ no longer\n emits. Required by tests/registry-coverage.test.ts (auto-alias\n regression guard).\n\nTest suite: 72/72 passing (was 70/72 with 2 pre-existing failures).",
"is_bot": false,
"headline": "fix(bridge): correct _test_http_request ABI + close registry-coverage…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T00:30:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b98fad9a0ffb4043bf3d244053a5420f0b85265",
"body": "…gination\n\nCloses the remaining 26 entries in the host bridge parity check; clean\nparity now reports 0 missing on node-server.\n\nNew files (throw-error stubs — apps using these features fail with a\nclear message instead of crashing during WASM linking):\n- bridge/jobs.ts — 12 _job_* stubs\n- bri\n[…]\n\ndb field/paginate → cursor_page → schedule → jobs → websocket.\n\nStub bodies reference clean-server/src/{jobs,websocket,locale}.rs and\nhost-bridge/src/wasm_linker/database.rs as the porting reference.",
"is_bot": false,
"headline": "feat(bridge): add throw-error stubs for jobs/websocket/schedule/db-pa…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-16T00:17:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26e8f9a67f9fd715a9ae2c9337a5d23cb5dfe715",
"body": "Closes 31 entries in the host bridge parity check against\nfoundation/platform-architecture/function-registry.toml:\n\n- storage (8): _storage_local_*, _storage_session_* — no-op stubs\n- UI helpers (12): _ui_focus, _ui_blur, _ui_get_focus, _ui_get_selection,\n _ui_insert_at_cursor, _ui_text_diff, _ui_s\n[…]\noss-component-prompts/\n all-host-bridge-parity-enforcement.md.\n\nRemaining 26 missing functions (jobs, websocket, db pagination,\nschedule) need real implementations and are tracked in the same prompt.",
"is_bot": false,
"headline": "feat(bridge): backfill missing storage/UI/build_state/i18n imports",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-15T23:27:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46eea56e1d43bf1f1e805fa0480a044c584f8dfd",
"body": "…g (SRV005)\n\nSame fix as clean-server: loader.js reads data-wasm from its own script element\nto locate frontend.wasm. Without it the fallback is a relative path that 404s on\nroutes deeper than /. Injecting data-wasm=\"/frontend.wasm\" (absolute) fixes hydration\non all routes.",
"is_bot": false,
"headline": "fix(bridge): add data-wasm absolute path to injected loader script ta…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-13T04:00:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "221b665a4179b8f9fb0d7ab509bc3ee5fd2464cb",
"body": "Closes 6 cross-server parity bugs against clean-server (commits bb37270,\na6dc693, 88565eb, 2d19719, efb38cd, 2c43399):\n\n- NSRV-ENV-ERROR: register env.error host import with LP-format signature\n so compiled modules that propagate runtime errors instantiate cleanly\n- NSRV-HTTP-HEADERS: add http_put/\n[…]\nV002: serve /loader.js (from ~/.cleen/plugins/frame.ui/runtime\n with embedded stub fallback) and /frontend.wasm (sibling-of-main-WASM\n first, then CWD / public / dist) ahead of the Express catch-all",
"is_bot": false,
"headline": "fix(bridge): port clean-server fixes to close NSRV-* error reports",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-10T19:41:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae7c6cccb71fa166e10a44d44aa0217d3288c922",
"body": "…ectives\n\nAdds _http_redirect_route bridge function (layer 3) that registers static\nredirect routes during WASM start() without generating a WASM handler function.\nMatches the signature in function-registry.toml:\n (method_ptr, method_len, from_ptr, from_len, to_ptr, to_len, status) -> i32\n\nRouteReg\n[…]\nute\nentry. Server.handleRequest short-circuits on redirectTo routes, issuing the\nLocation header and status code directly without dispatching to the worker pool.\n\nResolves NODE-REDIRECT-ROUTE-MISSING.",
"is_bot": false,
"headline": "feat(bridge): implement _http_redirect_route for static redirect: dir…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-05T13:05:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dec28818611029e1dfa7441a48bc2446c3c8c92c",
"body": "…e_body\n\nResolves SYNC-CANVAS-STUBS-MISSING: WASM modules with canvasScene: blocks\nemit imports for all 238 frame.canvas bridge functions even when running\nserver-side. Without host stubs, WebAssembly.instantiate fails with a\nLinkError. Added src/bridge/canvas-stubs.ts with no-op stubs whose\nsignatu\n[…]\n Mirrors the\nclean-server/src/bridge_canvas_stubs.rs pattern.\n\nAlso adds http_get_response_body (Layer 2 http_client), fixing the\npre-existing registry-coverage test failure.\n\nBumps version to 0.1.42.",
"is_bot": false,
"headline": "feat(bridge): add frame.canvas client-side stubs and http_get_respons…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-04T06:40:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7191f288c14f2140fb63bce2bd8237f03f8fd1b0",
"body": "… _email_last_error\n\nFixes BRIDGE001, SRV-MISSING-BRIDGE, BRIDGE002 on the node server runtime.\nAll frame.server apps were failing at WASM instantiation because these four\nbridge functions declared in frame.server plugin.toml [bridge] were missing.\n\n- _res_download: sets Content-Disposition: attachm\n[…]\nfires async with\n error captured in lastEmailError for _email_last_error to report\n- _email_last_error: returns error string from last failed send\n\nAlso removes unused camelToSnake helper from ui.ts.",
"is_bot": false,
"headline": "feat(bridge): implement _res_download, _email_configure, _email_send,…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-03T05:13:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d80a5069663d40a4ef526fc430debc1ca2da75f",
"body": "Part A (§FEXT-4): Full SSE wire-protocol implementation.\n- _http_sse_route registers STREAM routes by exported handler name\n- _sse_emit, _sse_emit_event, _sse_close, _sse_retry, _sse_is_connected\n backed by a dedicated per-connection SSE worker thread\n- Worker posts events via parentPort; main thre\n[…]\n,3,5): Browser-only no-op stubs for server-side WASM\ninstantiation — DOM query, DOM patching, iframe communication, drag data.\nAll stubs return 0 or satisfy the linker; never called at server runtime.",
"is_bot": false,
"headline": "feat(bridge): implement SSE bridge and browser-only UI stubs",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-02T15:37:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8891684693f4d095b0057543adfc73fc1adba38b",
"body": "BRIDGE001: replace 4-param string_matches with 3-param version using\ncompile-time pattern IDs (0=email, 1=url, 2=uuid, 3=phone, 4=date,\n5=integer, 6=number, 7=alphanumeric); old signature read pattern as a\nruntime WASM string causing always-false results.\n\nBRIDGE002: add src/bridge/test.ts implementing _test_http_request,\n_test_response_status, and _test_response_body — in-process endpoint\ntest dispatch using the route registry and handle-map pattern.",
"is_bot": false,
"headline": "fix(bridge): implement BRIDGE001 and BRIDGE002 fixes",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-02T04:36:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f8b87080203ce02deca30e76864908ddccb0fce7",
"body": null,
"is_bot": false,
"headline": "feat(bridge): add mcp bridge source files missing from previous commit",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-01T01:10:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "702634c3c0c4a98728c9a3cbd50fb1bf9e476c6b",
"body": "…_head_link\n\n_db_register_migration: update from 2-param (name only) to 6-param form\n(name, up_sql, down_sql as ptr+len pairs) to match frame.data plugin output.\nStore SQL strings alongside migration name; _db_run_migrations and\n_db_rollback_migration now execute stored SQL with WASM export fallback\n[…]\nmissing bridge function (was in function-registry\nbut not implemented in node server). Injects <link rel=stylesheet href=...>\ninto response head, deduplicated by href. Adds injectedLinks to WasmState.",
"is_bot": false,
"headline": "feat(bridge): fix _db_register_migration signature and add _ui_inject…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-06-01T01:08:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4f5637c88d2e403fdf76ae11fa3fd8822a26cdd",
"body": "…BRIDGE001)\n\nRemoved JSON.parse() branch that was re-serializing valid JSON objects\nwithout outer quotes, causing parameterized SQL queries to receive an\nembedded object instead of a string literal.",
"is_bot": false,
"headline": "fix(bridge): json.encode() always serializes as JSON string literal (…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-28T03:59:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa2258d2da7efeeb6bffe3aeff1a36f426200d45",
"body": "… (NSR001)\n\nCompiler 0.30.155+ emits these as WASM imports in every module. Both are\nno-ops for the bump-allocator runtime but must be registered to allow\nWASM instantiation to succeed.\n\n[dev-queue-skipped: SRV001, SRV002 are clean-server issues, not node-server]",
"is_bot": false,
"headline": "fix(bridge): add _state_reset_all and _state_reset_named host imports…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-24T02:08:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ccac1a636dece5f7997047615b8bd1e086a8b2d",
"body": "_ui_load_layout, _ui_load_page, and _ui_render_page previously constructed\npaths internally (app/pages/, app/layouts/), encoding frame.ui plugin\nconventions in the server layer. The first argument is now treated as a full\nrelative path from project root — path construction is the caller's\nresponsibility. Mirrors the same fix in clean-server.",
"is_bot": false,
"headline": "fix(bridge): UI template functions accept full relative paths (SRV001)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-23T20:24:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bebec5b7261b45973c5bccb3cb8b9f74f3c1a25",
"body": "…UI_RENDER_PAGE_MISSING)\n\nframe.server plugin declares _ui_render_page as a bridge function for\nrender() and renderWith() DSL calls, but neither function was registered\nin the WASM imports object. WASM instantiation failed immediately with\n\"unknown import: env::_ui_render_page\".\n\nImplements _ui_rend\n[…]\ndata string.\nMissing keys produce an empty string. Includes path traversal protection.\n\nAlso registers _ui_load_page which was implemented in ui.ts since\nc5cd2ea but never wired into the bridge index.",
"is_bot": false,
"headline": "fix(bridge): add _ui_render_page and _ui_load_page host imports (SRV_…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-22T02:00:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "120cce4d46284f719e0e3a0e595b71a1e597fbde",
"body": "Chrome 95+ and Firefox 103+ require 'wasm-unsafe-eval' in script-src to\nallow WebAssembly.compile() and WebAssembly.instantiate(). The previous\ndefault-src 'self' policy blocked all WASM loading in modern browsers.",
"is_bot": false,
"headline": "fix(security): add wasm-unsafe-eval to CSP script-src (CSP_BLOCKS_WASM)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-21T15:05:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "50ea5099224d3fb3c5cbdd37155fbd669d64b75f",
"body": "Compiler v0.30.134+ emits string_matches as a WASM import in all compiled\nmodules. Adds the implementation (sig: i32,i32,i32,i32 -> i32) to the string\nbridge and registers it in the env import object, preventing LinkError on\nWASM instantiation.",
"is_bot": false,
"headline": "fix(bridge): add string_matches host import (BRIDGE_MISSING_STDLIB)",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-20T21:33:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ea369f74c2783c63a99817c7aee0041ab9bad25",
"body": "…s (ASYNC001)\n\nResolves ASYNC001 — three async bridge functions were absent from the env\nimport object, causing WASM instantiation failures for modules that use\nbackground tasks or server sleep. Implements the same busy-wait pattern\nused by _time_sleep; _async_fire and _async_await are fire-and-forget stubs\nmatching the clean-server v1.9.11 fix.",
"is_bot": false,
"headline": "fix(bridge): add _async_fire, _async_await, _server_sleep host import…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-20T03:45:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dc30aa431da766343ac05ae370a439b460a5317",
"body": "…FEAT001)\n\nAdds _ui_load_page to createUiBridge() in src/bridge/ui.ts, resolving\napp/pages/{name}.html with the same path-traversal guard used by\n_ui_load_layout. Closes the render() parity gap between clean-server\nand clean-node-server reported as FEAT001.",
"is_bot": false,
"headline": "feat(bridge): add _ui_load_page bridge function for render() parity (…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-19T06:05:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5cd2eaf404c86005c9678460240639f2f5e1b68",
"body": "Tests encoded the old broken convention (1=equal, 0=different).\nCompiler codegen emits i32.eqz after string_compare, requiring 0=equal,\nnon-zero=different. Updated to match the corrected bridge implementation.",
"is_bot": false,
"headline": "test(bridge-abi): update string_compare expectations to match spec",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T16:13:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1160e95be43ba0c7d51ea914998fad962b730211",
"body": "…turn convention\n\nNSR002: _http_redirect signature was (urlPtr, urlLen, permanent) but compiler\nemits (status, urlPtr, urlLen) per function-registry.toml spec. Status is now\npassed directly instead of being derived from a boolean permanent flag.\nAdded separate _res_redirect(urlPtr, urlLen, status) i\n[…]\n: string_compare was returning 1 for equal, 0 for different. Compiler\ncodegen emits i32.eqz after calling string_compare, so it expects 0=equal,\nnon-zero=different. Inverted the return value to match.",
"is_bot": false,
"headline": "fix(bridge): correct _http_redirect param order and string_compare re…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T16:11:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2a3b54da20e5ff511844bbe9648a4563efcf12b6",
"body": "… bounds check, ui snake_case rename\n\nNSR001: sanitizeHeaderValue now strips all chars outside RFC 7230 obs-text range\n(tab, 0x20–0x7E, 0x80–0xFF), preventing U+FFFD and other Unicode chars that\nNode.js v22 rejects in HTTP headers.\n\nNSR002: writeLengthPrefixedString now validates ptr+totalSize <= bu\n[…]\nctHeadCss to _ui_load_layout/_ui_inject_head_css\nin ui.ts and index.ts to match plugin.toml [bridge] declarations — the compiler\nemits snake_case WASM imports matching the canonical plugin.toml names.",
"is_bot": false,
"headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, heap…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T05:11:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ead96808127c2f82bbe58202db81000da2e4a878",
"body": "…al names only\n\nThe compiler (v0.30.123) was fixed to emit only canonical _namespace_fn import\nnames. Dot-notation aliases (db.query, req.param, etc.) are no longer emitted as\nseparate WASM imports, so the auto-alias derivation loop in createBridgeImports()\nis dead code.\n\nRemove the loop. Update the\n[…]\n method imports that the compiler always emitted as dot-notation primaries\n(string.concat, math.sin, integer.toString, list.*, etc.) remain explicitly\nregistered — those are unaffected by this change.",
"is_bot": false,
"headline": "refactor(bridge): remove auto-alias loop — compiler now emits canonic…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T04:32:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d514c1c29930e16ede1a1478863634bf0c7620a",
"body": "_auth_hash_password and _auth_verify_password were never canonical names.\nThe registry defines _crypto_hash_password and _crypto_verify_password.\nNo backward compatibility needed in a development project with a single spec.",
"is_bot": false,
"headline": "refactor(bridge): remove backward-compat crypto aliases",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T01:58:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d2537bc70bde52ce9ef26fc4af9806438818eec",
"body": "…issing functions\n\nAdds a registry coverage test that reads function-registry.toml and verifies\nthe env object covers every canonical name and alias. Fixed all 43 gaps it found:\n\ncrypto.ts: renamed _auth_hash_password/_auth_verify_password to canonical\n_crypto_hash_password/_crypto_verify_password; \n[…]\nrd and\n_auth_verify_password pointing to renamed canonical functions.\n\ntests/registry-coverage.test.ts: parses module field to skip memory_runtime\nentries; checks every env-module canonical and alias.",
"is_bot": false,
"headline": "fix(bridge): full registry coverage — canonical names, aliases, and m…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T01:54:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f75809490b8a9747d9acc04717c0fae14115d6a9",
"body": "…nent prompt format\n\nAdds a \"Bridge Function Naming\" section to CLAUDE.md explaining the dual\n_namespace_fn / namespace.fn registration requirement and pointing to\nHOST_BRIDGE.md for the full spec. Updates the cross-component prompt\nformat reference to point at the README instead of embedding a stale\ninline template.",
"is_bot": false,
"headline": "docs(bridge): document dual-naming requirement and update cross-compo…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T01:31:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b67de00959a697cdb496771234fedce3f48c750",
"body": "…efixed bridge functions\n\nThe compiler emits WASM imports in both _namespace_fn and namespace.fn\nstyles for all bridge namespaces. The env object only registered underscore\nnames, causing LinkError on db.query, req.param, http.respond, etc.\n\nRefactors createBridgeImports() to build env as a named va\n[…]\nnt. Keys starting with __ (e.g. __stack_pointer) are skipped.\n\nCovers all namespaces: db, req, http, json, html, ui, session, auth,\ncrypto, file, and any future additions automatically.\n\nFixes NSR004.",
"is_bot": false,
"headline": "fix(bridge): auto-generate dot-notation aliases for all underscore-pr…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T01:08:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2da585eae44180331fa671d59cf934d5f65b0cb",
"body": "The compiler generates both camelCase and snake_case dot-notation imports\nfor every frame.ui bridge function. The previous partial fix added camelCase\nstubs but left 29 snake_case variants uncovered, causing a LinkError on\nui.set_state (and others) at WASM instantiation.\n\nAdds camelToSnake() and a p\n[…]\n-build loop in createUiClientStubs() that\nderives snake_case aliases from all camelCase ui.* entries automatically.\nFuture bridge function additions stay in sync without manual listing.\n\nFixes NSR003.",
"is_bot": false,
"headline": "fix(bridge): auto-generate snake_case aliases for all ui.* client stubs",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-18T00:43:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8908755e96fa8dba0499246da21e9b075b496450",
"body": "…ry pre-grow, ui client stubs\n\nNSR003: frame.ui 2.6.9 registers client-side bridge functions as WASM imports in\nserver builds. Add no-op stubs for all ui.* functions in createUiClientStubs()\nand spread them into the linker env — satisfies the linker without runtime overhead.\n\nNSR001: http.redirect()\n[…]\nffset is outside the\nbounds of the DataView\". Add preGrowMemory() (16 MB default) called at startup in\nboth server.ts and request-worker.ts so memory.grow() is never triggered during\nrequest handling.",
"is_bot": false,
"headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, memo…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-17T23:43:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "290f9ffb80976996590a1a1dbdd6ef509854df07",
"body": "…ring_split to LP-pointer ABI\n\nWASM calls these functions with one i32 LP-pointer per string argument\n(pointing to [4-byte LE length][UTF-8 content]). The previous (ptr, len,\nptr, len) signature misread the second LP-pointer as a length value, causing\nexponential memory growth and offset-out-of-boun\n[…]\nted call site expectation.\n\nAdds bridge-abi.test.ts with 12 ABI contract tests covering LP-pointer and\nraw ptr+len conventions across all four affected functions.\n\nFixes: NODE-STRING-BRIDGE-CONVENTION",
"is_bot": false,
"headline": "fix(bridge): switch string.concat, string_compare, string_replace, st…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T22:07:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "62c2349a6d0abe2646706f92bae323de4a4eb704",
"body": "…mer into shutdown\n\nNODE-DB-BRIDGE-OOB: writeLengthPrefixedString, readLengthPrefixedString, and\nreadRawString each called memory.buffer multiple times. When WASM malloc causes\na memory.grow(), the old ArrayBuffer is detached and replaced. All reads and\nwrites now snapshot the buffer once after mall\n[…]\nver.start(), so it fired unconditionally 35 seconds\nafter startup regardless of whether shutdown was in progress. Moved into\nthe shutdown() handler so the watchdog only runs when a signal is received.",
"is_bot": false,
"headline": "fix(bridge): snap memory buffer once after malloc, move force-exit ti…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T19:58:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22a2684ca2c1b3fd3f87750e98bd5ec5b8525b03",
"body": "The compiler exports handlers as __route_handler_0, __route_handler_1, ...\nin registration order. The WASM table index passed to _http_route is an\ninternal offset unrelated to the export naming scheme.\n\nRouteRegistry now maintains a sequential counter and stores it as the\nhandlerIndex, replacing the raw WASM table offset. Dispatch uses\n__route_handler_${handlerIndex} with the counter-based index.\n\nFixes NODE-HANDLER-DISPATCH-V2.",
"is_bot": false,
"headline": "fix(bridge): dispatch route handlers via sequential registration counter",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T17:47:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ebefc8d27eec7b579279fc30f4f78d942335442",
"body": "…ort names\n\nThe compiler emits handler indices as function table offsets, not named\nexports. Constructing __route_handler_<N> / __handler_<N> export names\nnever matched anything in the WASM module.\n\nBoth callHandler() and request-worker.ts now use\n__indirect_function_table.get(handlerIndex) — the same pattern already\nused by the array bridge for callbacks.\n\nFixes NODE-HANDLER-DISPATCH.",
"is_bot": false,
"headline": "fix(bridge): dispatch route handlers via WASM function table, not exp…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T15:27:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f696b4a102e1be2346e247a9437cc9de9b66eb85",
"body": "…pected\n\nstart() resolved the port as: port || getConfiguredPort() || this.config.port\ngetConfiguredPort() always returned truthy 3000 (its module-level default),\nso this.config.port (the parsed --port value) was never reached.\n\nPassing config.port explicitly makes the CLI flag win unconditionally.\n\nFixes NODE-PORT-FLAG-IGNORED.",
"is_bot": false,
"headline": "fix(server): pass config.port to server.start() so --port flag is res…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T15:02:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3352fb8fd439ba8a4d75654a3e5c8e16f873a1de",
"body": "…e.js v22\n\nObject.create alone is insufficient: JS [[Set]] walks the prototype chain\nand throws TypeError when the prototype property is non-writable, even on\nthe shadow object. Object.defineProperty creates an OWN property directly,\nbypassing the prototype chain check entirely.\n\nFixes NODE-WASM-MALLOC-READONLY (complete fix, supersedes v0.1.12).",
"is_bot": false,
"headline": "fix(wasm): use Object.defineProperty to install malloc wrapper on Nod…",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T14:56:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0a89695e9c12d639be722d1b6446d1fa4d432375",
"body": "Node.js v22 (V8) enforces that WebAssembly.Instance.exports properties\nare non-writable per spec. wrapMalloc() was assigning directly to\nexports.malloc, throwing TypeError on v22+.\n\nFixes NODE-WASM-MALLOC-READONLY by using Object.create(instance.exports)\nto create a shadow object — the wrapper becomes an own property while\nall other WASM exports remain accessible via the prototype chain.",
"is_bot": false,
"headline": "fix(wasm): shadow WASM exports to allow malloc wrapping on Node.js v22",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T14:51:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2eee5bf7c6bc5be1d59eee48bd5949a146500faa",
"body": null,
"is_bot": false,
"headline": "chore(settings): update allowed commands",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T14:39:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "859f850340226d98e0746a3d01b5e9ff6afa51f6",
"body": "Implements SyncMysqlDriver using the same SharedArrayBuffer + Atomics\npattern as SyncPostgresDriver, with a mysql-worker thread handling async\nmysql2 operations. Adds mysql/mysql2 protocol cases to createDatabaseDriver.\n\nFixes FEATURE-NODE-MYSQL reported against 0.30.110.",
"is_bot": false,
"headline": "feat(database): add MySQL driver via worker-thread sync bridge",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-16T14:38:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7cdc68081e67671d497762fad26d4f9727ad62d",
"body": "Register _html_escape, _html_raw, print_string, console_input, and\nall 29 math dot-notation aliases (math.sin, math.cos, etc.) that\nwere in the HOST_BRIDGE spec but not wired into the env import object.",
"is_bot": false,
"headline": "feat(bridge): add missing HOST_BRIDGE functions per spec",
"author_name": "Ivan",
"author_login": "Ivan-Pasco",
"committed_at": "2026-05-12T02:10:09Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 98,
"commits_last_year": 118,
"latest_release_at": "2026-07-18T11:44:03Z",
"latest_release_tag": "v0.1.97",
"releases_from_tags": true,
"days_since_last_push": 5,
"active_weeks_last_year": 19,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.7
},
"community": {
"has_readme": true,
"has_license": false,
"has_description": true,
"has_contributing": false,
"health_percentage": 28,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@ivan-pasco/clean-node-server",
"exists": true,
"license": "MIT",
"keywords": [
"clean-language",
"wasm",
"webassembly",
"server",
"runtime"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@ivan-pasco/clean-node-server",
"is_deprecated": false,
"latest_version": "0.1.97",
"repository_url": "https://github.com/Ivan-Pasco/clean-node-server",
"versions_count": 93,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4376,
"first_published_at": "2026-01-25T02:57:33.837000Z",
"latest_published_at": "2026-07-18T11:45:36.434000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 31875,
"source_files_sampled": 122,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5920
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "bcryptjs",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.4.3"
},
{
"name": "better-sqlite3",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^11.0.0"
},
{
"name": "commander",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^12.0.0"
},
{
"name": "compression",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.8.1"
},
{
"name": "cookie-parser",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.4.6"
},
{
"name": "cors",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.6"
},
{
"name": "express",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.18.2"
},
{
"name": "express-rate-limit",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^8.4.1"
},
{
"name": "ioredis",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.10.1"
},
{
"name": "jsonwebtoken",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^9.0.2"
},
{
"name": "mysql2",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.9.0"
},
{
"name": "nodemailer",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^8.0.10"
},
{
"name": "pg",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^8.11.3"
},
{
"name": "pino",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^10.3.1"
},
{
"name": "pino-http",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^11.0.0"
},
{
"name": "prom-client",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^15.1.3"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 1,
"closed_ratio": 0,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "Ivan-Pasco",
"commits": 118,
"avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"nightly-canaries.yml",
"publish.yml",
"reporter-artifacts.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 0,
"reason": "license file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 4,
"reason": "dependency not pinned by hash detected -- score normalized to 4",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 4,
"reason": "6 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
"ran_at": "2026-07-23T19:09:07Z",
"aggregate_score": 3.7,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-23T08:46:10Z",
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": [
{
"number": 1,
"created_at": "2026-07-13T04:02:03Z",
"last_comment_at": "2026-07-18T11:45:37Z",
"last_comment_author": "github-actions"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/Ivan-Pasco/clean-node-server",
"host": "github.com",
"name": "clean-node-server",
"owner": "Ivan-Pasco"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"security": 37,
"vitality": 81,
"community": 24,
"governance": 31,
"engineering": 66
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 81,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"commits_last_year": 118,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 19
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "19/52 weeks with commits",
"points": 13.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 19
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "118 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 118
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 98,
"latest_release_tag": "v0.1.97",
"releases_from_tags": true,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "98 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 98
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 24,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": true,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "no license file detected",
"points": 0,
"status": "missed",
"details": [
{
"code": "license_absent",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 61,
"inputs": {
"packages": [
"@ivan-pasco/clean-node-server"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 4376
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "4,376 downloads/month across npm",
"points": 48.5,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 4376,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 31,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 1,
"closed_issues": 0,
"issue_closed_ratio": 0,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "0% of issues closed",
"points": 0,
"status": "missed",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 0
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 32,
"inputs": {
"followers": 1,
"owner_type": "User",
"is_verified": null,
"owner_login": "Ivan-Pasco",
"public_repos": 10,
"account_age_days": 1127
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of Ivan-Pasco",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "Ivan-Pasco"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "10 public repos, account ~3 yr old",
"points": 13.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 10
}
},
{
"code": "account_age_years",
"params": {
"years": 3
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@ivan-pasco/clean-node-server"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "93 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 93
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 66,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 37,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 37,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.7
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 4",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "6 existing vulnerabilities detected",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 62,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5920
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 4",
"points": 4,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 31875,
"source_files_sampled": 122,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/122 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 122,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"deps.dev does not index npm:@ivan-pasco/clean-node-server@0.1.97; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-23T19:09:13.595025Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/Ivan-Pasco/clean-node-server.svg",
"full_name": "Ivan-Pasco/clean-node-server",
"license_state": "absent",
"license_spdx": null
}