原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"ai-security",
"cli",
"devsecops",
"golang",
"mcp",
"sarif",
"sbom",
"scanner",
"security",
"static-analysis",
"cosign",
"llm-security",
"plugin-marketplace",
"sigstore",
"supply-chain-security"
],
"is_fork": false,
"size_kb": 18020,
"has_wiki": false,
"homepage": "https://nox-hq.dev",
"languages": {
"Go": 5126613,
"HTML": 43326,
"Shell": 20710,
"Kotlin": 2460,
"Python": 4364,
"Makefile": 1146,
"Dockerfile": 1404,
"TypeScript": 1578,
"Go Template": 3246
},
"pushed_at": "2026-07-24T13:57:26Z",
"created_at": "2026-02-08T21:10:43Z",
"owner_type": "Organization",
"updated_at": "2026-07-24T13:58:08Z",
"description": "Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Nox",
"type": "Organization",
"login": "Nox-HQ",
"company": null,
"location": "Germany",
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/260249483?v=4",
"created_at": "2026-02-08T15:06:36Z",
"is_verified": null,
"public_repos": 26,
"account_age_days": 166
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1",
"kind": "other",
"published_at": "2026-06-05T19:52:02Z"
},
{
"tag": "v1.14.0",
"kind": "minor",
"published_at": "2026-07-22T13:06:28Z"
},
{
"tag": "v1.13.6",
"kind": "patch",
"published_at": "2026-07-21T16:21:19Z"
},
{
"tag": "v1.13.5",
"kind": "patch",
"published_at": "2026-07-21T07:51:34Z"
},
{
"tag": "v1.13.4",
"kind": "patch",
"published_at": "2026-07-21T05:41:30Z"
},
{
"tag": "v1.13.3",
"kind": "patch",
"published_at": "2026-07-20T23:41:54Z"
},
{
"tag": "v1.13.2",
"kind": "patch",
"published_at": "2026-07-20T22:58:13Z"
},
{
"tag": "v1.13.1",
"kind": "patch",
"published_at": "2026-07-20T19:38:31Z"
},
{
"tag": "v1.13.0",
"kind": "minor",
"published_at": "2026-07-20T11:55:42Z"
},
{
"tag": "v1.12.2",
"kind": "patch",
"published_at": "2026-07-19T20:24:04Z"
},
{
"tag": "v1.12.1",
"kind": "patch",
"published_at": "2026-07-19T19:46:41Z"
},
{
"tag": "v1.12.0",
"kind": "minor",
"published_at": "2026-07-19T18:48:05Z"
},
{
"tag": "v1.11.0",
"kind": "minor",
"published_at": "2026-07-19T14:47:09Z"
},
{
"tag": "v1.10.0",
"kind": "minor",
"published_at": "2026-07-19T11:21:15Z"
},
{
"tag": "v1.9.2",
"kind": "patch",
"published_at": "2026-07-18T21:38:11Z"
},
{
"tag": "v1.9.1",
"kind": "patch",
"published_at": "2026-07-18T20:10:41Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2026-07-18T19:11:17Z"
},
{
"tag": "v1.8.0",
"kind": "minor",
"published_at": "2026-07-10T20:14:11Z"
},
{
"tag": "v1.7.1",
"kind": "patch",
"published_at": "2026-07-06T11:21:06Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2026-07-06T08:36:34Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-07-05T11:58:07Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-07-05T10:03:55Z"
},
{
"tag": "v1.4.2",
"kind": "patch",
"published_at": "2026-07-04T13:02:30Z"
},
{
"tag": "v1.4.1",
"kind": "patch",
"published_at": "2026-07-03T13:13:03Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-07-03T11:32:12Z"
},
{
"tag": "v1.3.1",
"kind": "patch",
"published_at": "2026-06-20T14:34:31Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2026-06-20T13:45:11Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-06-20T13:04:35Z"
},
{
"tag": "v1.1.5",
"kind": "patch",
"published_at": "2026-06-20T12:37:53Z"
},
{
"tag": "v1.1.4",
"kind": "patch",
"published_at": "2026-06-20T11:53:52Z"
},
{
"tag": "v1.1.3",
"kind": "patch",
"published_at": "2026-06-17T20:33:32Z"
},
{
"tag": "v1.1.2",
"kind": "patch",
"published_at": "2026-06-09T05:42:10Z"
},
{
"tag": "v1.1.1",
"kind": "patch",
"published_at": "2026-06-08T20:48:06Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-06-08T19:53:20Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-06-05T19:20:58Z"
},
{
"tag": "v0.10.2",
"kind": "patch",
"published_at": "2026-06-02T15:23:29Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-05-23T15:35:19Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-05-10T09:48:15Z"
},
{
"tag": "v0.9.5",
"kind": "patch",
"published_at": "2026-05-09T13:27:15Z"
},
{
"tag": "v0.9.4",
"kind": "patch",
"published_at": "2026-05-09T13:09:46Z"
},
{
"tag": "v0.9.3",
"kind": "patch",
"published_at": "2026-05-09T11:20:12Z"
},
{
"tag": "v0.9.2",
"kind": "patch",
"published_at": "2026-05-09T10:50:30Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2026-05-03T16:44:49Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-05-03T15:29:27Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-02-25T23:58:36Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-02-24T17:02:19Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-02-18T08:59:12Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2026-02-17T11:53:51Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2026-02-17T10:48:17Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2026-02-17T09:43:47Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-02-17T09:12:22Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-02-15T21:13:32Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-02-15T16:57:22Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-02-14T11:52:08Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-02-13T21:58:34Z"
}
],
"recent_commits": [
{
"oid": "abc7930e4dd40b421264b8596b4fe5e3599ab7b8",
"body": "…(closes #312) (#314)\n\nCloses #312. Companion to #311, which fixed the Dockerfile instances by\nanchoring instruction properties to line start. This handles the wider\nclass **anchoring can't** reach: a file-span absence rule whose property\nis a *free keyword*, satisfied by that keyword appearing in a\n[…]\ner reword was a\nband-aid; it's gone.\n- Grade A holds on nox's repo, zero new findings from stripping.\n- Full `./core/...` + `./cli/...` suites pass; precision harness\nunchanged; `golangci-lint` clean.",
"is_bot": false,
"headline": "fix(iac): a comment keyword can't satisfy an absence rule's property …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-24T13:57:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9612c13e17802dbb2a26076b4a67427f9c3cdb8f",
"body": "Regenerated from a self-scan of current `main`.\n\nThe committed badge read **C** (critical: 1), from a scan predating the\nself-scan hardening. The repo now scores **0 across every severity —\ngrade A** — after #308–#311 closed out the real findings and the\nfalse-positive/negative rule bugs behind them\n[…]\ngh / medium / low | — | 0 / 0 / 0 |\n\nSupersedes #270, which was generated at grade E and can never merge —\nits required checks can't run on a `GITHUB_TOKEN`-authored PR. I'll\nclose it once this lands.",
"is_bot": false,
"headline": "ci: refresh security badges to grade A (#313)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-24T13:33:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cef3d72caa49d24f745b99ec1142b2f7a3f5b1a4",
"body": "…ank lines (#311)\n\nTwo false-behaviours in the Dockerfile \"missing instruction\" rules,\nfound while getting nox's own repo to badge grade A. Both explain why a\nbatch of `nox:ignore` waivers appeared to suppress nothing — **nox's\nunused-waiver report was correct; the rules were the problem.**\n\n## 1. A\n[…]\nis **not fixed here**. I\nreworded the reason to avoid the trigger and will file the YAML\ntrailing-comment variant as a follow-up.\n\nFull `./core/...` and `./cli/...` suites pass; `golangci-lint` clean.",
"is_bot": false,
"headline": "fix(iac): Dockerfile absence rules no longer fooled by comments or bl…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-24T13:05:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92f6411bd9a42dd81c14fc57e0bf46627c725fc5",
"body": "…trate (#310)\n\nPR 3 of 3. Clears `examples/` down to info-severity (0-point) findings\nonly, with no unused waivers.\n\nSplit by **what each example is for**, rather than waiving the tree:\n\n## Fixed — because these are templates people copy\n\nAn example that pins `nox-hq/nox@v1` teaches a mutable ref: t\n[…]\n, so it does not include #308 or #309. Its\nstandalone score (27) reflects that. **The final grade should be read\nfrom merged `main`, not from any one branch** — I'll verify there after\nall three land.",
"is_bot": false,
"headline": "fix(examples): pin the actions examples teach, waive what they demons…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-23T14:55:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d7561d71bcc1d51e2f377a8e8d635a74040a192e",
"body": "…ate (#309)\n\nPR 2 of 3 toward getting nox's own badge back to A. Clears **everything\noutside `examples/`**.\n\n| | Score | Grade |\n|---|---|---|\n| before | 49 | E |\n| after | **22** | **D** |\n\nThe remaining 22 points are all in `examples/`, handled in PR 3.\n\n## Real fixes\n\n**`actions/remediate/action.\n[…]\nld have tried to copy files literally named `#` and `nox:ignore`.\nCaught by actually building rather than by reading the diff.\n- All edited YAML parses.\n- `go test ./...` green, `golangci-lint` clean.",
"is_bot": false,
"headline": "fix(ci): harden nox's own workflows and images, waive what is deliber…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-23T14:50:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cdb362462ae73d2ec8adfad3cb5f45adac2f6798",
"body": "First of three PRs toward getting nox's own badge back to A. This one is\na **product fix**, not a score fix — see the honest note at the bottom.\n\n## The bug\n\n`server/dashboard/dashboard.html` carries a base64 PNG logo on a single\n28,818-character line. Every self-scan reported **8 high-severity vend\n[…]\nnot move the badge grade** — still 49/E. Those 8 findings were\nnot contributing to the score. The grade work is the remaining findings\nin `.github/`, `actions/` and `examples/`, coming in PRs 2 and 3.",
"is_bot": false,
"headline": "fix(secrets): a data: URI payload is not a credential (#308)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-23T14:37:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea3c1761ac79fbb2d1f9f23f801d8192dd898ccd",
"body": "There was no release checklist, so the steps lived in whoever last cut\none. Two of them are easy to miss and both have already bitten:\n\n**Verifying the release rather than the workflow.** v1.9.0 published\n*unsigned* because `sign`, `docker` and `update-major-tag` all declare\n`needs: release`, and a \n[…]\nnpm run\nsync:changelog`, and nothing runs it automatically. v1.14.0 shipped\nyesterday and the page went on saying \"Latest v1.13.6\" — see\nNox-HQ/nox-hq.dev#12.\n\nDocumentation only; no behaviour change.",
"is_bot": false,
"headline": "docs: write down the release procedure, including the site sync (#307)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-23T08:52:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "774d22ac2c0b83692802729163f848c7596d2460",
"body": "Stamps the Unreleased section as 1.14.0.\n\nMinor rather than patch: #304 adds a user-facing Action input\n(`fail-on-degraded`), which is a new interface, not a fix.\n\nAlso records the dependency upgrades from #303 —\n`google.golang.org/grpc` 1.82.0→1.82.1 and `golang.org/x/text`\n0.38.0→0.39.0. They arri\n[…]\nnyone auditing what changed.\n\nThe other six commits in the range touch only\n`.github/workflows/remediation.yml`, `docs/`, and `.gitignore` — nox's\nown CI and repo hygiene, nothing a consumer receives.",
"is_bot": false,
"headline": "docs(changelog): 1.14.0 (#306)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-22T13:00:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fdba8a4a2403b5895524090bece4616e7058baab",
"body": "An MCP server launched from this directory writes SHA-named idempotency\nmarkers (`session` / `durable`, 7 bytes each) into `./data/cache/`. It\nis not produced by nox and is not project data, but it left 90 untracked\nfiles in `git status` on every session.\n\nScoped to `/data/cache/` rather than `/data/` so a future real `data/`\ndirectory would still be tracked.",
"is_bot": false,
"headline": "chore: ignore the local tool cache that dirties the worktree (#305)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-22T11:53:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d969637762339f10a68715e4cf7b6f0d2979891",
"body": "… (#304)\n\nnox has had `--fail-on-degraded` since 1.11.0, but the GitHub Action\nnever mapped it. A workflow could not make \"a check did not complete\"\nfail the build without dropping to a raw `run` step — so the gate most\nlikely to depend on it was the one that could not reach it. Without it,\nan OSV o\n[…]\n test ./cli/...` — pass\n- `golangci-lint run ./cli/...` — 0 issues\n- `bash -n action.sh`, `action.yml` parses\n- New test fails without the `action.yml`/`action.sh` change (checked\nbefore implementing)",
"is_bot": false,
"headline": "feat(action): expose fail-on-degraded, and test that inputs are wired…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-22T11:53:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4e813d9f8d858e413be60d5db6b17f0ef4790ec",
"body": "Automated remediation by `nox fix --actions`: OSV-vulnerable dependency\nupgrades, plus outdated and mutable GitHub Actions pins rewritten to\ntheir SHA-pinned latest release. Verified with `go test ./... -count=1`\nbefore opening.\n\nCo-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#303)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-22T08:11:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "208ae52e3a2552168e30241f6815c5a418ba75e7",
"body": "The `fix` section lists the three passes it performs and says nothing\nabout the boundary — leaving a reader free to assume a clean run covered\neverything the scan reported. It doesn't: **taint flows and the\ncode-level `SEC-*` rules are reported and left alone.**\n\nSays so, and gives the reason.\n\nRemo\n[…]\nnox-plugin-remediate` currently *does* rewrite\nhardcoded secrets without mentioning rotation, which contradicts the\nprinciple core states here.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs: state what `nox fix` does not remediate (#302)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T21:53:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "225891fca6e8da2d0aa003aac9b69c083470875f",
"body": "…ining it (#301)\n\nReplaces the repo-local remediation job with a thin caller of\n[Nox-HQ/.github#1](https://github.com/Nox-HQ/.github/pull/1).\n\nThe pinned nox version, the scan/fix/verify sequence and the token\nfallback now live in **one place**, so a bump happens once rather than\nin 21 repos. That's\n[…]\nrify-cmd`; now standard for every\ncaller).\n\nSelf-scan: 2 active findings, both pre-existing by-design\n(`workflow_dispatch`, `contents: write`).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "refactor(ci): call the org-wide nox-remediate workflow instead of inl…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T18:19:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ab43b8e18cbf7b46d256fe7ac683208e3ccb700",
"body": "… exists (#300)\n\n`GITHUB_TOKEN` **cannot modify workflow files.** The remediation run\nresolved the pins correctly, then failed at the push:\n\n```\n! [remote rejected] refusing to allow a GitHub App to create or update\n workflow `.github/workflows/ci.yml` without `workflows` permission\n```\n\nThat scope\n[…]\nrite**,\nstore it as a secret, pass it as `github-token`, and flip\n`upgrade-actions` back to `'true'`. The comment in the workflow records\nthis.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(ci): disable action-pin upgrades until a token that can push them…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T16:49:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53aeb004086f9ed5a054e2aa871a6ee767403988",
"body": "…eaders (#299)\n\nThe first remediation run that actually **had something to do** failed\nat the PR step:\n\n```\nremote: Duplicate header: \"Authorization\"\nfatal: unable to access 'https://github.com/Nox-HQ/nox/': ... error: 400\n```\n\n`actions/checkout` persists an `AUTHORIZATION` extraheader, and\n`create-\n[…]\nng half was permanently skipped.\n\nThe rest of the run worked: `--actions` executed, and `has-updates`\ncorrectly went true off the `plan:` line.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(ci): stop the remediation PR failing on duplicate Authorization h…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T16:42:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63a11966d8ad47fdbf8bcbfda391752a6b18f3b8",
"body": "…#298)\n\nFinal step of the Dependabot switch. nox has **no `dependabot.yml`**,\nand `nox-remediate-action` only ran nox's *package* pass — so nothing\nupgraded nox's own GitHub Action pins. **Eight were stale.**\n\nEnables the `upgrade-actions` input added in [nox-remediate-action\nv1.0.2](https://github.\n[…]\nan: the high-severity IAC-013 mutable-tag\nfinding is gone; the 2 remaining are pre-existing by-design\n(`workflow_dispatch`, `contents: write`).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "feat(ci): let the remediation action upgrade GitHub Action pins too (…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T16:33:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a5c803199bc923421be07bd99795aab162e4648b",
"body": "Release notes for **1.13.6**, covering everything merged since 1.13.5:\n\n**Fixed**\n- `nox fix --actions` could pin a GitHub Action **backward** to an older\ncommit than the one running (#296)\n- Scanning a single file ignored that file's `nox:ignore` comments\n(#295)\n- `brace-expansion` DoS in the VS Co\n[…]\nole 1.13.x series, which\nstopped at 1.12.2, and repoints `[Unreleased]` from its stale v1.12.2\nbase. All six referenced tags verified to exist.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.6 (#297)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T16:15:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc449e53d1702bee5927a520a2e7def6486416a6",
"body": "`nox fix -actions` could rewrite an action pin to an **older commit than\nthe one already running**, and say nothing about it.\n\n`latestTag` asked `/releases/latest` and returned, consulting tags only\nas a fallback *\"for repos without GitHub Releases\"*. That precedence is\nwrong: a Release is an **anno\n[…]\n0.0\", want v1.0.1`.\n\nUnblocks replacing Dependabot with `nox-remediate-action` — see the\nfollow-up to make the action actually pass `-actions`.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(fix): stop pinning GitHub Actions backward to a stale release (#296)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T15:56:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29a07b828899427e75296b9c1f42b078e730f639",
"body": ".nox.yaml excluded `.github/workflows/*.yml` for one narrow reason, recorded in\nits comment: pinned commit SHAs and GITHUB_TOKEN references read as\nhigh-entropy secrets. But the entry sat in scan.exclude, which drops the FILE,\nso it silenced every analyzer on those files rather than the one that was\n[…]\nr the change: 25 findings visible under .github (17 active), zero of them\nfrom the secrets analyzer, and zero high or critical.\n\nClaude-Session: https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix: stop excluding nox's own CI workflows from its own scan",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T12:46:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a86c06c53ac220f4b3bd6a4b03795cf80170656",
"body": "…et is a file (#295)\n\n`nox scan main.go` joined every relative lookup onto the target **as if\nit were a directory**:\n\n```\n[degraded] app.py/.nox/baseline.json could not be loaded: ... not a directory\n[degraded] app.py could not be re-read to apply inline suppressions: open app.py/app.py: not a direc\n[…]\nreen: with\nthe fix reverted it fails on the unapplied waiver *and* both\ndegradations.\n\nFound while scanning a single workflow file during #294.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(scan): resolve relative paths against the directory when the targ…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T10:45:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2df97a0de10a7d03c37a9e6f5f0175e3a2c13e49",
"body": "Follow-up to #292, which fixed the three Windows failures. This fixes\n**why nobody saw them for 100+ runs.**\n\nThe matrix was chosen by *event*: ubuntu-only on `pull_request`, all\nthree on push to main. The intent was cost (macOS 10x, Windows 2x\nActions minutes). The effect was that a Windows regress\n[…]\nreports and PRs stay mergeable.\n\n**This PR is its own test case:** it changes a workflow file, not docs,\nso it should run all three OSes below.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "ci: test cross-OS before merge, not after (#294)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T10:37:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59cd49822f750ac075b3527413d5853abc2762a3",
"body": "… since June (#293)\n\nThe scheduled **dependency-CVE audit has failed every run for at least\nfive weeks**:\n\n```\nfailure 2026-07-20 failure 2026-07-13 failure 2026-07-06\nfailure 2026-06-29 failure 2026-06-22\n```\n\non **GHSA-3jxr-9vmj-r5cp** — exponential-time expansion of consecutive\nnon-\n[…]\norts.\n\n**Verified:** a full `nox scan` of the repo now reports **0** dependency\nCVE findings, where it previously reported this one as fixable.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(deps): patch the brace-expansion DoS the weekly audit has flagged…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T10:23:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2d81e3ce145a555e39f2916f949be6205d65ae6b",
"body": "**CI on main has not passed in over 100 consecutive runs.** Lint, macOS,\nUbuntu and the fuzz job are green every time; only `Test\n(windows-latest)` fails — on three tests that are wrong about Windows,\nnot on anything the product does wrong.\n\nA gate that is permanently red reports nothing. Five relea\n[…]\n— the auth boundary\nwas unverified on that platform.\n\nVerified locally on macOS (all three pass); the real proof is the\nWindows job on this PR.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "test: fix the three Windows-only failures that have kept main red (#292)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T10:11:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bcd53db63f8861af27f67db9475e26697d137020",
"body": "Changelog for 1.13.5 — the GitHub Action retries throttled asset\ndownloads instead of failing the scan (#290).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.5 (#291)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T07:46:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "936416eef43bbc9d6b6564170075eb3812e93c9c",
"body": "…can (#290)\n\n## Problem\n\nThe action fetched the nox binary and `checksums.txt` in a **single\nunauthenticated attempt**. GitHub throttles release-asset downloads when\nmany jobs pull at once, returning **HTTP 403**, and that failed the\nentire step:\n\n```\ncurl: (22) The requested URL returned error: 403\n[…]\nt (18s → 0.1s); unset in normal use, keeping the\n3s/6s spacing a throttle actually needs.\n\nFull suite 51/51, precision 1.000/1.000, lint clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(action): retry throttled asset downloads instead of failing the s…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T07:07:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48b8e65de148b4b36542fbce18281243d4858d53",
"body": "Changelog for 1.13.4 — cosign v4 bundle name in `nox plugin entry`\n(#288) and SARIF `security-severity` (#287).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.4 (#289)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T05:35:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5e1f0e68c85a398e0adabc7f294f377c96e0d56b",
"body": "`nox plugin entry` generates the registry entry that **every plugin\nrelease publishes**, and it wrote the cosign **v3** names: a detached\n`checksums.txt.sig` plus `checksums.txt.sig.bundle`.\n\nThe plugin release workflows sign with cosign **v4**, which writes a\nsingle `checksums.txt.sigstore.json` an\n[…]\nrl`.\n- Guard test pins the v4 name and fails if the v3 names or\n`CosignSigURL` reappear.\n- Full suite 51/51, precision 1.000/1.000, lint clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin entry): emit the cosign v4 bundle name (#288)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T05:29:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b48b51d735c771c92cd19b2a52e8439f64bca26e",
"body": "…rts (#287)\n\n## Problem\n\nSARIF `level` only distinguishes error/warning/note. **GitHub Code\nScanning classifies alerts by the `security-severity` property**, and\nnox emitted none — so all **388 nox alerts across the plugin fleet**\narrived with no security severity. The Code Scanning UI can't filter \n[…]\nerty,\ncorrectly correlated with level (8.0↔error, 5.5↔warning); the one\nwithout is info.\n- Full suite 51/51, precision 1.000/1.000, lint clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "feat(sarif): emit security-severity so Code Scanning can classify ale…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T05:15:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3975f6befb355b6b6ec73cb63e4b59a2ab79c774",
"body": "Changelog for 1.13.3 — doc examples are no longer reported as unused\nwaivers (#284).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.3 (#286)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T23:37:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d91398452c821c86edb47d9db1499d4ff8b183b9",
"body": "Reporting unused waivers (#282) immediately caught two in **this**\nrepository.\n\n### `aibom_polyglot.go` — a waiver that never worked\n\nThe directive above the detector-pattern block spanned four comment\nlines, so it applied to the *second comment line* and waived nothing.\nAll **14 SEC-161/SEC-163 fin\n[…]\n to exactly the 4 lines that fire (confirmed by scan,\nnot guessed) — no blanket waiving.\n- Full suite 51/51, precision 1.000/1.000, lint clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix: repair two of nox's own nox:ignore waivers (#285)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T23:33:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48b51b9cb48c75abfc5f3823a78dbbd2ae7e37e5",
"body": "Reporting unused waivers (v1.13.2, #282) flagged **documentation that\ndemonstrates the syntax**. nox's own README shows `nox:ignore` inside\nfenced code blocks whose sample secrets are deliberately too short to\nmatch a rule, so every example waived nothing and got reported:\n\n```\n[degraded] README.md:\n[…]\n\n- The genuine signal is intact — the wrapped-reason and typo'd-rule\ncases still report.\n- Full suite 51/51, precision 1.000/1.000, lint clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(suppress): do not report doc examples as unused waivers (#284)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T23:20:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1544606dc8bda2e11d7c276aeda5ad37a7baa8d7",
"body": "Changelog for 1.13.2 — a `nox:ignore` that suppresses nothing is now\nreported (#282).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.2 (#283)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T22:52:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "995cc0f570c18620c261959e707674171e0cbf56",
"body": "## Problem\n\nA dedicated `nox:ignore` applies to the **next non-blank line**. If the\nreason wraps onto a second comment line, the waiver lands on that\ncontinuation comment — the finding below stays reported, and **nothing\nindicates the suppression missed**:\n\n```go\n// nox:ignore SEC-001 -- this reason\n[…]\n, not noisy.\n- Full suite 51/51, precision 1.000/1.000, lint clean.\n\nFollows #281, which documented this footgun; this makes it\nself-reporting.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(scan): report a nox:ignore that suppresses nothing (#282)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T22:42:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4fb32f54a1d44f03720c2abd7110ab1abdfd7097",
"body": "A dedicated `nox:ignore` applies to the **next non-blank line**. If the\nreason wraps onto a second comment line, the waiver targets that\ncontinuation comment rather than the code — the finding is still\nreported, and **nothing indicates the suppression missed**.\n\n```go\n// nox:ignore SEC-001 -- this r\n[…]\ny identical, so silently\nretargeting could break valid waivers. `suppress.go` already skips\n*stacked* directives, which the note also mentions.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs: warn that a dedicated nox:ignore must stay on one line (#281)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T22:29:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c7eefe4ec928d78e6b7c6ae5edf5d9a6afa4fdd",
"body": "…I flake) (#280)\n\n`TestCycloneDX_SharedCVEDeterministic` asserts 100 `Generate` calls are\nbyte-identical but didn't set `SOURCE_DATE_EPOCH`. The CycloneDX\nmetadata timestamp is `report.GeneratedAt()`, which falls back to\nwall-clock `time.Now()` (second resolution) when `SOURCE_DATE_EPOCH` is\nunset —\n[…]\ns `t.Parallel`, so the test is no longer parallel.\n\nVerified stable across **300 in-process iterations and 20 separate\nprocesses**, 0 failures.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "test(sbom): freeze the clock in the CycloneDX determinism test (fix C…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T19:21:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7bcfd503985c86f71172cd43ad515befdd4256d",
"body": "…#278)\n\n## Problem\n\nThe action counted findings with:\n```bash\nfindings_count=$(grep -c '\"RuleID\"' findings.json 2>/dev/null || echo \"0\")\n```\n`grep -c` prints the count but **exits 1** when there are zero matches,\nso on a clean scan the `|| echo \"0\"` fallback fired *on top of* grep's\nown `0`, making \n[…]\nat fails against the old `|| echo \"0\"` form and checks the\ncorrected pipeline emits one valid `findings-count=N` line for a\nzero-findings file.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(action): stop the GitHub Action failing on a zero-findings scan (…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T18:56:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d2cd4a790788efb152adf22e2cf2482c7f6b23c8",
"body": "Changelog for the 1.13.0 security-hardening + correctness release (PRs\n#255–#276).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.13.0 (#277)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T11:50:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b59531ce6c827fe404b2dbbbe0ad5f8f26ecea77",
"body": "## Problem\n\nThe three MCP dashboard handlers bypassed the 1MB output cap that every\nother text handler enforces:\n\n- `handleDashboard` (dashboard tool)\n- `handleResourceDashboard` (read of `nox://dashboard`)\n- `handleProjectResourceDashboard` (per-project dashboard resource)\n\nAll three returned `Gene\n[…]\nrds return\nreal HTML.\n\n## Verification\n\n- `go build ./...` clean\n- `go test ./server/...` passing\n- `golangci-lint run ./server/...` — 0 issues\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(server): enforce output-size cap on MCP dashboard handlers (#276)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T10:14:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0670a9b9ad97450113bbde8cf58f789fae4b08ba",
"body": "…bombs (#275)\n\n## Problem\n\n`ExtractTarGz` (registry/oci/extract.go) extracted gzip tar archives\nwith **no bound on uncompressed output**:\n\n- `extractFile` did `io.Copy(f, r)` with no `LimitReader`.\n- The extraction loop had no cumulative byte accounting and no\nentry-count cap.\n\n`download()` caps the\n[…]\non\n\n- `go build ./...` — clean\n- `go test ./...` — pass\n- `go test ./registry/oci -race` — pass\n- `golangci-lint run ./registry/...` — 0 issues\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(registry): cap tar.gz extraction to defend against decompression …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T10:10:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3f41264036079c3bf8011cdc96bdcdbb1ab0679",
"body": "…cible HTML (#274)\n\n## Summary\n\nFixes three confirmed defects in nox's report emitters (`core/report/`),\neach covered by a red→green test.\n\n### DEFECT 1 (HIGH) — CycloneDX SBOM non-deterministic when one CVE\naffects multiple packages\n`CycloneDXReporter.Generate` built vulnerability entries by rangin\n[…]\nte clean\n- `golangci-lint run ./core/report/...` — 0 issues\n- `go run ./cli bench --precision testdata/precision-suite` — OVERALL\n1.000 / 1.000\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(report): deterministic SBOM ordering, valid SPDX license, reprodu…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T10:04:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7481da8a25d821164bf5ce311d55420b6cf26898",
"body": "## Problem\n\n`yamlBlockSpan` (core/rules/matcher.go), reached via\n`AbsenceMatcher.Match` for `absence_span: yaml-block`, terminated a\nblock only at a shallower line or a same-indent **mapping key**. It\ntreated every same-indent sequence entry (`- ...`) as a child of the\nblock.\n\nThat is correct when t\n[…]\n1.000**\n- `go test ./core/rules/... ./core/analyzers/iac/...` pass\n- `go build ./...` and `golangci-lint run ./core/rules/...` clean (0\nissues)\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(rules): stop yaml-block span absorbing sibling sequence items (#273)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T10:00:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6af39aa22fe75adb4b67b6ef8f8d3a2773672310",
"body": "## Problem\n\n`parseRequirementsTxt` (core/analyzers/deps/parsers.go) missed\ndependencies — and therefore their CVEs — when a `requirements.txt` used\nthe bare `<` or `>` PEP 508 specifiers, which are valid and common.\n\nTwo failure modes:\n\n1. **Dropped package** — the operator set was `{\"==\", \">=\", \"<=\n[…]\nan\n- `golangci-lint run ./core/analyzers/deps/...` — 0 issues\n- `go run ./cli bench --precision testdata/precision-suite` — OVERALL\n1.000/1.000\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(deps): parse requirements.txt strict < and > bounds correctly (#272)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T09:52:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44e1de27ed1ddf654f960bf2fe268a1657a3470a",
"body": "## Problem\n\nThe plugin policy gate **failed open** on non-canonical `risk_class`\nvalues.\n\n`validateSafety` compared risk classes by ordinal via\n`riskClassLevel(rc) > riskClassLevel(policy.MaxRiskClass)`.\n`riskClassLevel` returns `-1` for any unrecognized value, and `-1 > 0`\n(passive ceiling) is `fal\n[…]\nngci-lint run ./plugin/...` → 0 issues\n- `go run ./cli bench --precision testdata/precision-suite` → OVERALL\nprecision/recall **1.000 / 1.000**\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin): fail closed on unrecognized plugin risk_class (#271)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T09:47:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e2e21b56ed2bf017f7f942e9e53f83372da9c7ea",
"body": "…OSV (#269)\n\n## Problem\n\nCycloneDX (`bom.json`) and SPDX (`sbom.json`) are first-class scan\ninputs. `ecosystemFromPurl` returned the raw purl **type**, but purl\ntypes differ from nox's internal ecosystem names for two ecosystems:\npurl uses `golang` and `gem` where nox (and `osvEcosystem`) use `go` a\n[…]\ne component is no longer silently dropped.\n\nFull suite green, lint clean.\n\nFound by a fresh adversarial audit of the hardened main; 4 of 4 PRs.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(deps): normalize purl types so Go and Ruby SBOM components reach …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T07:57:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dfcb6d248702a5a419d1151a8f5e9e6908a7a1e3",
"body": "…n family (#268)\n\n## Problem\n\nTwo secret-leak gaps in the plugin output redactor:\n\n**1. Structured fields bypassed redaction entirely.** `RedactResponse`\nonly scanned free-text fields (messages, metadata, enrichment\ntitle/body, graph labels). It copied `Finding.Location.FilePath`,\n`AIComponent.Name/\n[…]\n positional fields survive.\n\nFull suite green, `-race` clean, lint clean.\n\nFound by a fresh adversarial audit of the hardened main; 3 of 4 PRs.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin): redact structured plugin fields and the full GitHub toke…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T07:53:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "659da2eafc79bf53585b423307dc1eb0457f56b2",
"body": "… not AIComponent (#267)\n\n## Problem\n\n`isAIComponent` claimed **any** file whose path contained a `prompts` or\n`agents` directory segment as an AI component, regardless of file type.\nThe taint, SAST, agentflow, slop, and variants analyzers all early-skip\nany artifact whose `Type != Source`, so every\n[…]\nh directions.\n\nFull suite 51/51, precision suite 1.000/1.000, lint clean.\n\nFound by a fresh adversarial audit of the hardened main; 2 of 4 PRs.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(discovery): classify source under prompts/ and agents/ as Source,…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T07:48:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8fcb1f78356eb202e3108d78d948135f44865803",
"body": "…s (#266)\n\n## Problem\n\n`Store.Fetch` is **fail-open** by contract — it records trust-policy\nviolations in `VerifyResult` but still returns a runnable `BinaryPath`,\nleaving enforcement to the caller. Only `runPluginInstall` honored that.\nTwo other callers did not:\n\n- **`runPluginUpdate`** used the pe\n[…]\ne again.\n\nBuild clean, `cli` tests pass, lint clean.\n\nFound by a fresh adversarial audit of the hardened main; 1 of 4 PRs.\nRelated: #264, #265.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin): enforce trust policy on update and required-install path…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T07:44:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c9dd9c61fa3ee189fbffd9bcf63cb55fc0b6c2c",
"body": "## Problem\n\nThe scan path trusted `~/.nox/state.json` wholesale.\n`installedPluginBinaries` loaded a plugin's `BinaryPath` and `Track`,\ndid nothing but `os.Stat` the file, and launched it — with **no re-check\nthat the binary is the one verified at install**. Verification runs only\nat install time; `s\n[…]\n_HOME`.\n\nFull suite 51/51, `-race` clean on `cli`, lint clean.\n\nSecond of the two plugin trust-boundary fixes (first: #264, gRPC channel\nauth).\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin): re-verify plugin binary integrity at scan time (#265)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T06:13:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0d9c44f3e52ced70a3bedb29eb26b8253ebbf40b",
"body": "…token (#264)\n\n## Problem\n\nA plugin subprocess binds an **unauthenticated** gRPC server on a\nloopback TCP port (`sdk.Serve`: `net.Listen(\"tcp\", \"127.0.0.1:0\")` +\n`grpc.NewServer()` with no credentials/interceptor) and advertises its\naddress on stdout. The host dialled it with `insecure.NewCredential\n[…]\nn trust-boundary fixes; the second\n(scan-time re-verification of plugin provenance instead of trusting\n`~/.nox/state.json`) follows separately.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(plugin): authenticate host↔plugin gRPC channel with a per-launch …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T06:01:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cfb5b485651d0dea97e8397b96ed6b2795a523c7",
"body": "SEC-430 (a bare `postgres://` scheme rule) was retired in the secrets\nrebuild (#259). Its detection is fully subsumed by **SEC-073**, the\ncredential-aware DB connection-string rule, which is already present in\n`ephemeralTestDBRules`. The leftover `\"SEC-430\": true` key could never\nmatch a finding aft\n[…]\nwngraded via SEC-073.\n\nVerified: `go build ./...`, `go test ./core/analyzers/iac/`, and\n`golangci-lint run ./core/analyzers/iac/...` all clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "chore(iac): drop dead SEC-430 key from GHA services downgrade set (#263)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T22:31:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f94913bff9a8bf98f6c097e6be70be70e170c71d",
"body": "…se positives (#262)\n\n## Summary\n\nThe taint/SAST engine had five reproduced recall holes (audited against\nthe live engine). Each is now fixed with a **positive test** (the flow\nis detected) and a **negative test** (the sanitized version is NOT\nflagged — existing sanitizers like `shlex.quote`, `escap\n[…]\nreq,res) => { ... })`),\nbecause the paren-merging line pipeline collapses it into one logical\nline — a pre-existing limitation, unchanged here.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(taint): close five confirmed SAST recall holes without adding fal…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T22:24:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6545be2e4b0b30e81507a7d0741a3b922ce789fd",
"body": "…er (#261)\n\n## Problem\n\n65 IaC rules **never fired**. They express \"resource present but\nhardening property absent\" using RE2-incompatible negative lookahead\n`(?!...)`. Go's `regexp` is RE2 and rejects lookahead; the matcher\nsilently swallowed the compile error. Whole categories were dead: most\nAzur\n[…]\n- `golangci-lint run` — 0 issues\n- `go run ./cli bench --precision testdata/precision-suite` — **1.000 /\n1.000** (0 false positives), unchanged\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(iac): restore 57 dead IaC rules with a block-scoped absence match…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T22:19:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f93521e5720770e3809a753b64c5e7b6f7cc56e",
"body": "…260)\n\n## Problem\n\nThe MCP detectors **MCP-015** (rug-pull, `core/mcppin`) and\n**MCP-023/024** (server/tool shadowing, `core/mcpshadow`) were fully\nwritten and unit-tested but **never called in the scan path**. Meanwhile\n`core/compliance/owaspmcp.go` maps MCP-015→MCP04 and MCP-023/024→MCP09,\nso nox \n[…]\ndegradation paths.\n\n`go build ./...`, `go test ./...` (51 packages), `-race` on touched\npackages, and `golangci-lint run ./core/...` all clean.\n\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(mcp): wire rug-pull and shadowing detectors into the scan path (#…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T22:13:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a6495eb78189ee4f758c9a532a4a89c8a202a12",
"body": "…lues (#259)\n\n269 vendor secret rules (SEC-556..SEC-950) matched the config key NAME, not the credential value: they false-positived on documentation, missed the real secret, and were case-inverted (missed UPPERCASE_ENV=). Converted each to capture the high-entropy value next to the key, case-insens\n[…]\n detects a realistic value line), precision suite holds 1.000/1.000. Counts: secrets 932->913, catalog 1547->1528. Verified independently: 0 uncompilable patterns, converted rules fire on real values.",
"is_bot": false,
"headline": "fix(secrets): rebuild vendor name-only rules to capture credential va…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T22:05:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d297e364d058b79a690b55ddd05e3dc2fd3c196c",
"body": "…ead (#258)\n\nFrom the core audit: **65 of 500 IaC rules never fire.** They use\nRE2-incompatible negative lookahead `(?!...)` for \"resource present but\nhardening property absent\"; Go's regexp rejects lookahead and the\nmatcher swallows the compile error. Whole categories are silently\ndisabled — most A\n[…]\n's real follow-on work and will be done as such rather than\nhacked.\n\nBuild/test/lint clean. Fourth batch from the core audit (#255–257\nprecede). https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "test(iac): guard against uncompilable rules; track the 65 currently d…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T21:40:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "28a5b14de05481cc0f03e08e2798d834b97731a1",
"body": "…cope (#257)\n\nThird batch from the core audit — the output boundary, where a security\ntool fails silently because a malformed artifact is rejected by the\nconsumer, not by nox.\n\n- **SARIF referenced rules absent from its own catalog.** Plugin\nfindings (taint, reachability) carry rule IDs the RuleSet-\n[…]\nd by new regression\ntests; each fix confirmed against the invalid pre-fix output.\nBuild/test/-race/lint clean.\n\nBatches #255, #256 precede this.\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(core): emit valid SARIF/SBOM; stop --tracked-only inverting its s…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T21:40:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2950203d04956cd8f29a88e72932a0f0f06b898c",
"body": "…I inventory (#256)\n\nSecond batch from the core adversarial audit. Three defects, all on the\nscan hot path, each verified.\n\n**Findings shared one metadata map.** The engine assigned\n`rule.Metadata` (one instance) to every finding of a rule; downstream\nper-finding writes (GHA context, the severity-do\n[…]\nte-identical\nacross runs.\n\nRed-to-green tests for all three. Build/test/-race/lint clean.\n\nPart of a multi-batch core audit; #255 was the first.\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(core): isolate per-finding metadata, drop double GHA pass, sort A…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T21:40:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c3fbb6a8e78e8815b85005d3567e7dfdd93ef7d",
"body": "…t findings (#255)\n\nFirst batch from a comprehensive adversarial audit of the core. Two\nspine defects, both in the \"reports success while a real finding is not\ncounted\" class, both verified end-to-end.\n\n**Invalid `fail_on` silently disabled the CI gate.** `meetsThreshold`\nreturns false for any unrec\n[…]\ne line-independent\nfingerprint.\n\nBoth covered by red-to-green tests. Build/test/-race/lint clean.\n\nMore batches from the same audit will follow.\nhttps://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "fix(core): validate policy gate keywords; stop dedup dropping distinc…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T21:40:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c04ce874c29773f9067ab6094aafa32583d6b58",
"body": "Five vendors had byte-for-byte duplicate secret rules that reported the same\ncredential multiple times under different IDs. Merged, with no loss of\ndetection, and guarded by two tests against recurrence.\n\nClaude-Session: https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.12.2",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T20:18:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c85f5ba6b6f6b691efbee4baaa870736d3f3eaf",
"body": "… (#254)\n\nFive vendors had byte-for-byte duplicate secret rules — same description, same pattern — that each reported the same credential twice under different rule IDs (Bugsnag as three findings, Heroku as two). The six redundant IDs are retired (SEC-152, SEC-451, SEC-452, SEC-470, SEC-558, SEC-673\n[…]\nn identical finding set. Two invariants now prevent recurrence. The anchorless-pattern audit was extended across every analyzer; only secrets had bare character-class patterns (IaC/AI/data have none).",
"is_bot": false,
"headline": "fix(secrets): merge six functionally-identical duplicate secret rules…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T20:17:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ded1bc92aad921485b5dfc988c809275c240477",
"body": "129 anchorless vendor secret rules fired on ordinary code — comments,\nidentifiers, JSON values — because they were gated by keyword at file level.\nNow gated by proximity and credential shape. Self-scan SEC-* findings drop from\n45 to 12 with the precision suite holding 1.000/1.000.\n\nClaude-Session: https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.12.1",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T19:40:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ac8b807afa814d006c827d0e31306c9d38938d6",
"body": "129 of 938 built-in secret rules match only a character class and a length, with no literal anchor of their own, gated by keyword at file level. One vendor mention anywhere in a file turned every run of characters of that length into a high-severity credential finding — 34 from SEC-652 on nox's own \n[…]\nd all 129 rules still detect a credential-grade token. The 9 residual are hostname-shaped and bounded by a test rather than chased with a heuristic that would create false negatives on lowercase keys.",
"is_bot": false,
"headline": "fix(secrets): gate anchorless secret rules by proximity and shape (#253)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T19:40:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "854f43a66ca3225c73caff66d276bb2f2ff6ca76",
"body": "…, parse yarn/pnpm/poetry (#252)\n\nCloses a bypass of nox's never-auto-applies-fixes guarantee: InvokePostScan called the gRPC client directly with no policy, no rate limit, no timeout and no secret redaction, and nox/remediate ships a non-read-only apply_code tool with requires_scan_context. All thr\n[…]\ner the default passive policy until an operator sets plugin_policy.max_risk_class: active. Plugin fingerprints change value; anything baselined against a 1.11.x plugin fingerprint needs re-baselining.",
"is_bot": false,
"headline": "feat: enforce policy on post-scan plugins, fix silent enrichment loss…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T18:42:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "871f3fdf3e65abb50d7bce39a52fa5b2fb22873f",
"body": "A post-release review found that three of v1.11.0's promises did not hold, each with full unit-test coverage of the function involved while the defect sat at the call site.\n\nOSV advisory hydration dropped database_specific, so the CVSS-v4 severity fallback never received data and CRITICAL advisories\n[…]\nsuppression with an unparseable expiry date became a permanent silent waiver, --fail-on-degraded discarding all reports, and silent embedded-dataset failures in supply-chain and CVE-variant detection.",
"is_bot": false,
"headline": "fix: close the silent-failure gaps v1.11.0 left open (#251)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T17:02:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "90e5dfba9ec1ac425f35b68583aa5d1048819663",
"body": "Leads with a BREAKING CHANGES section. This ships breaking changes under a\nminor version deliberately: the module path stays github.com/nox-hq/nox\nbecause a v2 tag would break `go get` for library consumers without a /v2\npath rename, so the breaks are signalled in the changelog rather than by the\nve\n[…]\ned, which\nloosens the default posture for tracked plugins; several plugin-host\nsignatures changed; ScanOptions.NoCache is gone.\n\nClaude-Session: https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "docs(changelog): 1.11.0",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T14:42:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b15d1eb76012a2bcd98f8c15b23c04afbe59c10",
"body": "…dary, enforced track profiles (#250)\n\nChasing a severity bug surfaced a systematic asymmetry: nox failed loudly on file I/O but silently on nearly everything optional. A firewalled OSV, a dead plugin, a typo'd --vex path or an unparseable lockfile all exited 0, indistinguishable from a clean scan. \n[…]\nck read from the registry — never self-declared — and a strict fallback for unverifiable provenance.\n\nHonours context cancellation in every analyzer, and makes the registry deprecated flag functional.",
"is_bot": false,
"headline": "fix: make core scan reliable — visible degradation, plugin trust boun…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T14:39:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6acdc5b45d8cb495c01b32064b8ed5cdf1252b12",
"body": "Written by hand: 'relicta notes' exits 1 with no output because the AI path\nis enabled in .relicta.yaml with model gpt-4, and the failure is swallowed.\n\nClaude-Session: https://claude.ai/code/session_01QaHY7x5xKyZWP3RVQ4AgpH",
"is_bot": false,
"headline": "docs(changelog): 1.10.0",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T10:34:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c3888c09f643dca63e0d61b47effc7079d9757b",
"body": "Three independent bugs meant Go dependency scanning reported mostly wrong\nversions, at uniformly wrong severity, with no way to act on the result.\nEach one hid the others.\n\n1. Versions came from go.sum, which hashes the entire module graph rather\n than the build. Across 28 repositories 5,263 findi\n[…]\nium.\n\nBEHAVIOUR CHANGE: repositories with high/critical dependency vulnerabilities\nwill start failing their enforcing gate. Those vulnerabilities were always\npresent and were being reported as medium.",
"is_bot": false,
"headline": "fix(deps): make Go dependency scanning actually work (#248)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T10:21:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "272ada8df3779541eb34ad5d830759c938c14c8b",
"body": "nox keeps **three** caches under `~/.nox/cache`, and `cache clear` only\never touched one — despite its name.\n\n| cache | before | now |\n|---|---|---|\n| scan | cleared | cleared |\n| **registry** | **not cleared** | **cleared** |\n| artifacts | not cleared | still not cleared — deliberately |\n\n## The tr\n[…]\n Verification\n\nVerified by hand as well as by test: after `cache clear`, the artifacts\ncache is untouched and an installed plugin still runs. `go build`, `go\nvet`, all tests, `golangci-lint` 0 issues.",
"is_bot": false,
"headline": "fix(cli): cache clear now clears the registry cache too (#246)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T06:46:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e384ed58e8be5c876fce0c77e68a08f9737ec188",
"body": "The index, sync tool and marketplace builder move to\n**[Nox-HQ/registry](https://github.com/nox-hq/registry)**.\n\n## Why\n\nCore had no business cataloguing seven other repositories. It needed a\nGitHub token, knew every plugin's release cadence, and **failed CI when\nan unrelated repository published a \n[…]\ne run**\n\nThree tests cover it: migration happens, custom URLs are left alone, and\nit's idempotent.\n\n## Verification\n\n`go build`, `go vet`, **49 test packages**, `golangci-lint` 0 issues,\n`make build`.",
"is_bot": false,
"headline": "chore: extract the plugin registry into its own repository (#245)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T05:22:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1bc5c866b3d447d821d62da4c0577d4ea325f430",
"body": "Seven of its nine rules **duplicated core's taint engine** under a\nsecond rule-ID namespace, so enabling it reported every SQLi, XSS, path\ntraversal, command injection, deserialization, SSRF and SSTI **twice** —\nonce as `TAINT-*`, once as `SAST-*`.\n\nIts two additive rules are now in core:\n\n| plugin \n[…]\nis uninstalled, the\nplugin is simply no longer offered.\n\nArchiving the `nox-plugin-sast` repository is left to you: that's a\nGitHub-side action on a separate repo, and not something I'd do\nunprompted.",
"is_bot": false,
"headline": "chore(registry): retire nox/sast (#244)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T05:01:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "067fff74346fe55dad3d88574c30876d440a64f4",
"body": "… (#243)\n\nAdds `VulnOpenRedirect` and sinks for **Go** (`http.Redirect`),\n**Python** (Flask `redirect`, Django `HttpResponseRedirect`),\n**JavaScript** (`res.redirect`), **Java** (`sendRedirect`), **PHP**\n(`header`) and **Ruby** (`redirect_to`).\n\n## An upgrade, not a port\n\nThis is the second half of \n[…]\n coverage.\n\n## Verification\n\n`go build`, `go vet`, all test packages, `golangci-lint` 0 issues, and\nthe SAST precision gate. Catalogue tests assert the class, CWE and rule\nID across all six languages.",
"is_bot": false,
"headline": "feat(taint): open redirect as a taint-gated sink (TAINT-007, CWE-601)…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-19T04:57:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f096cc1d7443f6cf6ec03baab38f699254f1aa8c",
"body": "Flags construction of **MD5, SHA-1, DES and RC4** across Go, Python,\nJavaScript/TypeScript and Java.\n\n## Why a new analyzer\n\nNothing in core had a home for this. It **isn't a taint flow** — MD5 is\nunsafe for a digest regardless of where its input came from, so there's\nno source to track — and it **i\n[…]\nan hidden.\n\n## Verification\n\n**0 findings scanning nox itself** — the real false-positive check. Plus\n`go build`, `go vet`, **50 test packages**, `golangci-lint` 0 issues,\nand the SAST precision gate.",
"is_bot": false,
"headline": "feat(core): detect broken cryptographic primitives (CRYPTO-001) (#242)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T22:53:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9827faed9f9eaeea9af00c908de85f5c878f656e",
"body": "`go build ./cmd/registry-sync` writes its binary to the working\ndirectory, and it was swept into #240 by a `git add -A`. **A\ndarwin/arm64 Mach-O executable reached main** in a cross-platform repo —\nuseless to every other platform, and permanently in clone history.\n\n`.gitignore` listed `/nox` but nee\n[…]\ny ~9 MB extra until then; the practical cost is\nsmall and the remedy is disruptive, so it's flagged rather than\nperformed.\n\nMy error, caught from the merge output (`create mode 100755\nregistry-sync`).",
"is_bot": false,
"headline": "fix: remove an 8.9 MB binary committed to the repository (#241)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T22:10:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a105e2d6ea260890414365dbad9c3ede18c38df3",
"body": "## The gap\n\nThe CLI resolves plugins from\n`raw.githubusercontent.com/nox-hq/nox/main/registry-scaffold/index.json`,\nso **a published GitHub release is not installable until the index lists\nit**. That step was manual and nothing detected it: seven plugins were\nrecently released, signed, and completel\n[…]\nages**, `golangci-lint` 0 issues.\nTests cover repo parsing and — importantly — that the artifact matcher\nrejects `checksums.txt`, signature bundles and SBOMs, which must never\nenter the artifact list.",
"is_bot": false,
"headline": "feat(registry): detect and reconcile unpublished plugin releases (#240)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T22:06:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db6bcbcdbede4c083cfc0a14d9b0f48dfa643565",
"body": "The CLI resolves plugins from\n`raw.githubusercontent.com/nox-hq/nox/main/registry-scaffold/index.json`,\nso **a GitHub release alone is not installable** — updating the index is\na separate step that nothing automates.\n\nAll seven plugins were released today carrying reconciled work, and\n**none were re\n[…]\n in-tree copy → standalone\nrepo → GitHub release → registry index — and now the only one still\nmanual. A release that doesn't reach the index is invisible to users,\nand nothing currently catches that.",
"is_bot": false,
"headline": "chore(registry): publish the reconciled plugin releases (#239)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T21:39:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a19793399928aa09c221edb8737832a184ef2b3d",
"body": null,
"is_bot": false,
"headline": "docs(changelog): 1.9.2",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T21:33:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a45e8d0ad79f3e030d660ea728b8541fb2f607a",
"body": "Every plugin under `plugins/` also exists as its own repository, and\n**those repositories are what release**. The two copies had forked — not\nas stale leftovers, but **in both directions**, with real work living\nonly in-tree:\n\n| plugin | work that existed only in `plugins/` |\n|---|---|\n| reachabilit\n[…]\nbuild`, `go vet`, **48 test packages**, `golangci-lint` 0 issues,\n`make build`, the SAST precision gate, and `go install\ngithub.com/nox-hq/nox-plugin-reachability@v0.7.0` producing the bundled\nbinary.",
"is_bot": false,
"headline": "chore: remove the duplicated plugins/ tree (#238)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T21:06:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0d3d60444d1ab3bb1b4ca61fb2cfd1af037837bc",
"body": "… stale",
"is_bot": false,
"headline": "docs(changelog): 1.9.1 — release completes even when the tap token is…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T20:05:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37dca7dbc5bdeeb4db3846319b1ecb5664023d40",
"body": "## What happened on v1.9.0\n\nBinaries and SBOMs published, but the artifacts were left **unsigned**,\nno container image was pushed, and the floating `v1` tag wasn't moved.\n\n**Cause:** the Homebrew tap formula update runs inside the same\ngoreleaser invocation as everything else. An expired `TAP_GITHUB\n[…]\nsilently shipping unsigned artifacts.\n\n## Follow-up, deliberately not folded in\n\n`goreleaser check` reports `brews` as deprecated in favour of\n`homebrew_casks`. Pre-existing, and a separate migration.",
"is_bot": false,
"headline": "fix(release): a stale tap token must not skip cosign signing (#237)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T20:05:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14dd633998583b67f44a4f394ab91ca802cd3041",
"body": "v1.8.0 was tagged and released with no CHANGELOG entry. Reconstructed from\nthe commits in v1.7.1..v1.8.0 and marked as such, rather than presented as\na contemporaneous record.",
"is_bot": false,
"headline": "docs(changelog): prepare 1.9.0 and backfill the missing 1.8.0 entry",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T19:06:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5dc0e8d4a0c17701ce72db7629ee55f9179a41ab",
"body": "…nstall (#236)\n\nThree problems that together made the per-tool safety work (#234)\nunusable in practice. Found by actually trying to run it.\n\n## 1. Five of seven plugin modules did not build from `main`\n\nEach plugin under `plugins/` is a **separate Go module** with `replace\ngithub.com/nox-hq/nox => .\n[…]\nt tests only, and problem (2) meant it would not have worked.\n\n## Verification\n\n`golangci-lint` 0 issues · root suite **48 packages** · **all 7 plugin\nmodules** build+test · SAST precision gate clean.",
"is_bot": false,
"headline": "fix(plugin): repair plugin-module drift, add CI coverage, add local i…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T18:56:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "71ce7ef1cc0453d374eda79932efddbc34886983",
"body": "…rs) (#233)\n\n## Summary\n\nIAC-351 (\"CI variable with hardcoded secret\") was misfiring as\n**critical** on standard GitHub Actions OIDC permission lines\n(`id-token: write`), because the unanchored `TOKEN` pattern matched as a\nsuffix of the YAML key `id-token`. Found during the 2026-07-15 scan of\n`model\n[…]\naking changes to IAC-351 semantics for legitimate uses\n- [x] Regression test covers both TP and FP\n\n---\n\n**Companion blog post PR:** Nox-HQ/nox-hq.dev#8\n\nCo-authored-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(iac): anchor IAC-351 to line start; advance sotw queue (mcp-serve…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T17:31:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0d5d1eb6cf794f2998b6055942e5d5113fe52e11",
"body": "Clears the lint backlog. **None of these were bugs** — the suite passed\nthroughout. They accumulated invisibly because CI's Lint job reports\nonly issues on changed lines, so a clean PR check never surfaced them.\n\nEvery instance was reviewed individually rather than mechanically\nsilenced.\n\n## Fixed (\n[…]\nnst a profile rather than rediscovered.\n\n## Verification\n\n`golangci-lint` **0 issues**, plus `go build`, `go vet`, `go test` (**48\npackages**), `make build`, and the **SAST precision gate** all clean.",
"is_bot": false,
"headline": "chore(lint): clear the 45 pre-existing golangci-lint issues (#235)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T17:20:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c13e0aa7d8e988bc639ecb1e82bfad76d7bc23f",
"body": "Automated refresh of `.github/nox-badge.svg` and the\nper-severity variants from the latest self-scan.\n\nGenerated by `.github/workflows/badge.yml`. Auto-merge\npicks this up once required checks pass.\n\nCo-authored-by: felixgeelhaar <6020564+felixgeelhaar@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: refresh security badges (#225)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-18T17:02:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0c9b048130681536246bc73cb2790ebe486362d",
"body": "## Problem\n\nSafety was declared **per-plugin** and validated at **registration**. A\nplugin bundling tools with different needs had to declare the union —\nthe strictest requirement of any single tool — and that union then gated\n*every* tool it ships.\n\nConcretely: `nox/red-team` could not run its read\n[…]\nated with protoc-gen-go v1.36.11 to match\nthe existing generated code, and I reverted an unrelated `protoc\n(unknown)` → `v7.35.0` version-comment churn from my local toolchain to\nkeep the diff honest.",
"is_bot": false,
"headline": "feat(plugin): per-tool safety requirements (#234)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-18T17:02:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f6ca131697a9722460dd15f24d1e92481e297095",
"body": "Upgrades mcp-go v1.22.0 → v1.24.0 (deps-only). stdio server — unaffected\nby the v1.24 stateless Streamable-HTTP default. Rebased onto current\norigin/main (supersedes stale-base PR #231).\n\nhttps://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "chore(deps): bump mcp-go to v1.24.0 (#232)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T11:24:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "447c45f37e18f308f1ca17822f8ebdd195da2746",
"body": "Adopts mcp-go's **structured-output** API (`OutputSchema` +\n`StructuredResult`) — an un-used capability across the fleet — for the\nfour nox read/report tools whose results are inherently structured data.\n\n## What changed\n`summary`, `list_findings`, `baseline_status`, and\n`data_sensitivity_report` no\n[…]\n\n\n**Verification:** `go build ./...`, `go vet ./server/`, `gofmt`, and `go\ntest ./server/` all pass; `golangci-lint` clean on the changed code.\n\nhttps://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): return structured content from read/report tools (#230)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T20:00:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9baa04fcda33d5fd30e84cf8600998565dd598a4",
"body": "Bumps the MCP framework to **v1.22.0**.\n\nAll changes across this range are additive / opt-in, so no source\nchanges are required. Free wins:\n- Deterministic `tools/list` ordering\n- Full JSON Schema 2020-12 for `inputSchema`/`outputSchema`\n- Modern MCP error codes and `server/discover` stateless foundation\n(opt-in)\n\n**Verification:** `go mod tidy`, `go build ./...`, and `go test ./...`\nrun locally.\n\nhttps://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "chore(deps): bump go.klarlabs.de/mcp to v1.22.0 (#229)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T19:51:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d75e6e26ce0a297c164491dd4a27bfc757b6e1e4",
"body": "…nox-plugin-grc (#228)\n\nBumps [golang.org/x/net](https://github.com/golang/net) from 0.54.0 to\n0.55.0.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/golang/net/commit/7770ec48d03fec35e378665337b4faca93c38423\"><code>7770ec4</code></a>\ngo.mod: update golang.org/x dependenci\n[…]\nage](https://github.com/Nox-HQ/nox/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T14:20:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d3112f55e43db84eecca7e93e7e92b10ac1aa30",
"body": "Bumps `go.klarlabs.de/mcp` to **v1.21.0** — the secure-by-default\nhardening release (panic-recovery on by default, transport\nOrigin/session/limit hardening, protocol correctness, deterministic\ndispatch, bounded lifecycle). Behavior-compatible for well-behaved\ncallers.\n\nVerified locally: `go build ./...` + `go test ./...` green; no `go`\ndirective change.\n\nhttps://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "chore(deps): bump go.klarlabs.de/mcp to v1.21.0 (#227)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T14:14:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f432fad83ab0d0a783509f8aba7c3d31a569158e",
"body": "Patch release. Restores `nox scan --baseline <path>` (removed in 1.7.0)\nas an optional override, plus a friendly unknown-flag error. See\nCHANGELOG. Tag `v1.7.1` on merge triggers GoReleaser.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "chore(release): 1.7.1 — restore --baseline override flag (#226)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T11:15:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8082b46b7debac25261e0b069ede57ec682a864f",
"body": "…rror (#224)\n\nRestores `nox scan --baseline <path>` as an optional override\n(auto-discovery of `.nox/baseline.json` stays the default; an explicit\nflag beats `policy.baseline_path`), and replaces the bare `flag provided\nbut not defined` error with an actionable hint.\n\n**Why:** removing the flag was \n[…]\ntRunScanWithOptions_BaselinePathOverride` (override\nsuppresses from a non-default path; control proves it doesn't leak into\ndefault discovery).\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(scan): restore --baseline override flag + friendly unknown-flag e…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T11:06:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "68b3f1ccf2e4bc28868253a656d0c6f17b012514",
"body": "…→1.00 (#223)\n\nPrepares the v1.7.0 release. See CHANGELOG.md for the full entry.\n\n**Headline:** SAST taint analysis across **21 languages** (up from 3),\nmeasured **precision 0.30 → 1.00** on an honest self-defending corpus,\ninterprocedural (same-file) taint, the `agentflow` agentic-dataflow\nanalyzer\n[…]\n.\n\nTag `v1.7.0` will be pushed on merge to trigger the GoReleaser release\n(binaries, GitHub release, cosign/SBOM, Homebrew tap, floating `v1`).\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "chore(release): 1.7.0 — 21-language SAST taint engine, precision 0.30…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T08:30:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "740b885a86ff2c59594e3b253820f3e1a983d8a9",
"body": "… (#222)\n\n## Summary\n\nEnd-to-end **Groovy** SAST support for the nox scanner, following the\npure-Go, no-CGo, line/statement-recognizer architecture used by the\nother JVM languages (Java/Kotlin). Covers `.groovy`, `.gradle`, and the\nextension-less `Jenkinsfile`.\n\n### Part 1 — lexctx (`scan_groovy.go`\n[…]\nhe engine's structural/interproc dataflow core was **reused\nunchanged**; only the documented per-language sink-arg extension point\nwas touched.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Groovy SAST support (lexctx + taint + honest corpus)…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T08:07:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ae29d535f1da4d5d2c303637dac2a9b9cdb9fd4",
"body": "…) (#221)\n\n## Summary\n\nEnd-to-end **Clojure** SAST support for the nox taint scanner: lexical\nclassifier, s-expression taint extractor, catalog block, discovery\nwiring, and an\nhonest precision corpus. Pure-Go, no CGo/tree-sitter/new deps — the\nengine is\nreused unchanged.\n\nClojure is a **Lisp** (pref\n[…]\n conflicts in lang.go\n/\nlexctx.go / extract.go / recognize.go / catalog.json / discovery.go /\nci.yml /\n .nox.yaml; catalog JSON re-validated).\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Clojure SAST support (lexctx + taint + honest corpus…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:58:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "06be616ab9a53291385a55849dd58d2a59767efd",
"body": "… (#219)\n\n## Summary\n\nEnd-to-end **Elixir** SAST support for the nox scanner, following the\nestablished pure-Go line/statement-recognizer architecture (no CGo, no\ntree-sitter, no new deps). Elixir reuses the shared taint engine\n(`structural.go` + `interproc.go`) unchanged; only the lexer, extractor,\n[…]\nalog.json\nre-validated as valid JSON with both `lua` and `elixir` blocks. Edits at\nthe shared dispatch/keyword/exclude points are append-style.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Elixir SAST support (lexctx + taint + honest corpus)…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:50:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad822e289064b547471d69500c4ebe552325f12a",
"body": "…rpus) (#218)\n\n## Summary\n\nEnd-to-end **Objective-C / Objective-C++** SAST taint support, following\nthe established per-language pattern (Swift/C++/PowerShell/Shell).\nPure-Go, no CGo/tree-sitter/new deps: Objective-C uses the shared\nline/statement recognizer and reuses the taint engine **unchanged**\n[…]\nquired. 5 sibling agents touch the same\ndispatch points concurrently; edits here are localized/append-style and\nthe catalog remains valid JSON.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Objective-C SAST support (lexctx + taint + honest co…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:37:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a600f329906196f7cedb08b3bae0b56b33eff59",
"body": "…#220)\n\n## Summary\n\nEnd-to-end **Dart** SAST support for the nox taint substrate — pure Go,\nno CGo / tree-sitter / new deps. Dart uses the shared line/statement\nrecognizer, emits the shared `unitDraft` IR, and reuses the taint engine\nunchanged.\n\n### Part 1 — lexctx (`scan_dart.go`)\n`LangDart`, `.dar\n[…]\nd\nas valid JSON; Lua gate unaffected.\n\nEdits kept localized/append-style at the shared dispatch points;\ncatalog.json re-validated after rebase.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Dart SAST support (lexctx + taint + honest corpus) (…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:21:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eac6b1092f5b8314bde5d7410c7de5f0184dfc7c",
"body": "…217)\n\nEnd-to-end **Lua** SAST support, following the same pure-Go, no-CGo,\nline/statement-recognizer pattern the other languages use. The shared\ntaint\nengine (`structural.go` / `interproc.go`) is reused **unchanged**.\n\n## What landed\n\n- **lexctx (`scan_lua.go`)** — `LangLua`, `.lua` mapping, `Class\n[…]\nnot modified.\n\nTDD throughout; the engine was verified to catch the corpus without any\nchange to\nthe shared structural/interproc dataflow core.\n\nhttps://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "feat: end-to-end Lua SAST support (lexctx + taint + honest corpus) (#…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:10:54Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 55,
"commits_last_year": 539,
"latest_release_at": "2026-06-05T19:52:02Z",
"latest_release_tag": "v1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 14,
"days_since_latest_release": 49,
"mean_days_between_releases": -4.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/nox-hq/nox",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/nox-hq/nox",
"is_deprecated": false,
"latest_version": "v1.14.0",
"repository_url": "https://github.com/nox-hq/nox",
"versions_count": 56,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-22T13:00:48Z",
"latest_version_yanked": null,
"days_since_latest_publish": 2
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"example",
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [
"proto/nox/plugin/v1/plugin.proto",
"proto/nox/plugin/v1/types.proto"
],
"has_devcontainer": false,
"typecheck_configs": [
"editors/vscode/tsconfig.json"
],
"toolchain_manifests": [
"editors/jetbrains/build.gradle.kts",
"examples/multi-stack/api/go.mod",
"go.mod"
],
"largest_source_bytes": 403688,
"source_files_sampled": 734,
"oversized_source_files": 6,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3371
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 60,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 6,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.1"
},
{
"name": "github.com/openai/openai-go/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.39.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.0"
},
{
"name": "golang.org/x/term",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.44.0"
},
{
"name": "golang.org/x/time",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.15.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.82.1"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "go.klarlabs.de/mcp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.24.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/charmbracelet/bubbles",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": true,
"version": "v1.3.10",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": true,
"version": "v1.10.1",
"ecosystem": "go"
},
{
"name": "github.com/openai/openai-go/v3",
"direct": true,
"version": "v3.39.0",
"ecosystem": "go"
},
{
"name": "go.klarlabs.de/mcp",
"direct": true,
"version": "v1.24.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": true,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.44.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": true,
"version": "v0.15.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": true,
"version": "v1.82.1",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": true,
"version": "v1.36.11",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "github.com/anthropics/anthropic-sdk-go",
"direct": false,
"version": "v0.0.0",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.4.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.11.6",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.15",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/displaywidth",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/stringish",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/uax29/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/websocket",
"direct": false,
"version": "v1.5.3",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.19",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/gjson",
"direct": false,
"version": "v1.18.0",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/match",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/pretty",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/sjson",
"direct": false,
"version": "v1.2.5",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "go.klarlabs.de/fortify",
"direct": false,
"version": "v1.8.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.56.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.46.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.39.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260630182238-925bb5da69e7",
"ecosystem": "go"
},
{
"name": "@types/node",
"direct": false,
"version": "20.19.43",
"ecosystem": "npm"
},
{
"name": "@types/vscode",
"direct": false,
"version": "1.125.0",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "5.1.9",
"ecosystem": "npm"
},
{
"name": "openai",
"direct": false,
"version": "^4.0.0",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.5",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "6.21.0",
"ecosystem": "npm"
},
{
"name": "vscode-jsonrpc",
"direct": false,
"version": "8.2.0",
"ecosystem": "npm"
},
{
"name": "vscode-languageclient",
"direct": false,
"version": "9.0.1",
"ecosystem": "npm"
},
{
"name": "vscode-languageserver-protocol",
"direct": false,
"version": "3.17.5",
"ecosystem": "npm"
},
{
"name": "vscode-languageserver-types",
"direct": false,
"version": "3.17.5",
"ecosystem": "npm"
},
{
"name": "flask",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "langchain",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "openai",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pinecone",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 66,
"direct_count": 12,
"indirect_count": 54
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 240,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 32,
"closed_unmerged_prs": 42
},
"bus_factor": 1,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "felixgeelhaar",
"commits": 472,
"avatar_url": "https://avatars.githubusercontent.com/u/6020564?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"badge.yml",
"ci.yml",
"dependabot-auto-merge.yml",
"release.yml",
"remediation.yml",
"slsa-provenance.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json",
"pnpm-lock.yaml",
"poetry.lock",
"yarn.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 9,
"reason": "dependency not pinned by hash detected -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 8,
"reason": "4 out of the last 5 releases have a total of 4 signed artifacts.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 8,
"reason": "2 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "abc7930e4dd40b421264b8596b4fe5e3599ab7b8",
"ran_at": "2026-07-24T21:52:24Z",
"aggregate_score": 7.3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T14:02:00Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-24T13:57:25Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/Nox-HQ/nox",
"host": "github.com",
"name": "nox",
"owner": "Nox-HQ"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"security": 78,
"vitality": 84,
"community": 43,
"governance": 54,
"engineering": 96
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 84,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"commits_last_year": 539,
"human_commit_share": 0.98,
"days_since_last_push": 0,
"active_weeks_last_year": 14
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "14/52 weeks with commits",
"points": 9.7,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 14
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "539 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 539
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"releases_count": 55,
"latest_release_tag": "v1",
"releases_from_tags": false,
"days_since_latest_release": 49,
"mean_days_between_releases": -4.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "55 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 55
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 49 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 49
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~-4.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": -4.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "4 out of the last 5 releases have a total of 4 signed artifacts.",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 43,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"merged_prs": 240,
"open_issues": 0,
"closed_issues": 32,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 42
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "240/282 decided PRs merged",
"points": 32.6,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 240,
"decided": 282
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 41,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "Nox-HQ",
"public_repos": 26,
"account_age_days": 166
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of Nox-HQ",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "Nox-HQ"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "26 public repos, account ~0 yr old",
"points": 11.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 26
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/nox-hq/nox"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 2
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 2 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 2
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "56 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 56
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 96,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"ai-security",
"cli",
"devsecops",
"golang",
"mcp",
"sarif",
"sbom",
"scanner",
"security",
"static-analysis",
"cosign",
"llm-security",
"plugin-marketplace",
"sigstore",
"supply-chain-security"
],
"has_wiki": false,
"homepage": "https://nox-hq.dev",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://nox-hq.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "15 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 15
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 78,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 7.3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "4 out of the last 5 releases have a total of 4 signed artifacts.",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "2 existing vulnerabilities detected",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 60 resolved dependencies against OSV; 6 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 60
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 6
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 60,
"unassessed_packages": 6,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 60,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 92,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3371
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "98 of 98 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 98,
"sampled": 98
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 91,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json",
"pnpm-lock.yaml",
"poetry.lock",
"yarn.lock"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"editors/vscode/tsconfig.json"
],
"agent_commit_share": 0.01,
"toolchain_manifests": [
"editors/jetbrains/build.gradle.kts",
"examples/multi-stack/api/go.mod",
"go.mod"
],
"dependency_bot_commit_share": 0.01
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "editors/vscode/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "editors/vscode/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "1 of the last 100 commits agent-authored or agent-credited",
"points": 2,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "1 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 9,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 403688,
"source_files_sampled": 734,
"oversized_source_files": 6
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "6/734 source files over 60KB",
"points": 54.6,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 734,
"oversized": 6
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "excellent",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"example_dirs": [
"example",
"examples"
],
"has_mcp_signal": true,
"api_schema_files": [
"proto/nox/plugin/v1/plugin.proto",
"proto/nox/plugin/v1/types.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "proto/nox/plugin/v1/plugin.proto, proto/nox/plugin/v1/types.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "proto/nox/plugin/v1/plugin.proto, proto/nox/plugin/v1/types.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "example, examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "example, examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-24T21:52:43.487691Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/Nox-HQ/nox.svg",
"full_name": "Nox-HQ/nox",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}