, which accepts ANY workflow in the opuspopuli\nrepo that ever obtained a Fulcio cert — over-broad. Pin it to the actual\npublishing workflow so verify only trusts images signed by it.\n\n- Pin the workflow FILE: `.../release\\.\n[…]\ncts a different workflow\n(ci.yml), a spoofed owner/repo, and a tag ref.\n\nAdvisory-only for now (verify); no bootstrap behavior change. Refs #34\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(cosign): ref-pin the signature identity to release.yml", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T03:52:54Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "52fa99184f84fd45a58a4e4bf80833ce99c149a9", "body": "…--components--create-op-node\n\nchore(main): release 0.10.16", "is_bot": false, "headline": "Merge pull request #69 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:20:50Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "6e36b8e536d959d76b58eaff694b39b8d4d0232e", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.16", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:18:54Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "2a1d8efe9e348f30b4d3874c6e99945faaef17b1", "body": "fix(init): seed repo secrets via Octokit + libsodium under the PAT", "is_bot": false, "headline": "Merge pull request #68 from OpusPopuli/fix/seed-secrets-via-octokit-32", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:18:39Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ec084b945d4c9010b16170eee5d8043402602c07", "body": "Issue #32: repo-secret seeding shelled out to `gh secret set` (ambient gh\nCLI auth), while every sibling init call used the explicit --gh-token PAT\nvia Octokit. A PAT identity that differed from the gh login seeded to the\nwrong account, and the \"PAT-only, may not have gh\" escape hatch the doc\nclaime\n[…]\necryptable (and plaintext-free), public-key-fetch failure,\nmid-batch PUT failure with correct seeded/pending split, malformed slug.\n\nCloses #32\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(init): seed repo secrets via Octokit + libsodium under the PAT", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T03:16:56Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "40d0d20b0d98da4211c0019629a2b3396c1d6a20", "body": "…--components--create-op-node\n\nchore(main): release 0.10.15", "is_bot": false, "headline": "Merge pull request #67 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:52:16Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "63cbac754e1e77e1809b540ce7613c9a975eeb17", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.15", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:51:17Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "291ad49d5175078e3a0889e0d19f802df650c186", "body": "…ep-35\n\nfix(polling): check workspace before sleeping in the discovery loop", "is_bot": false, "headline": "Merge pull request #66 from OpusPopuli/fix/discovery-check-before-sle…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:51:04Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4d0da6456bb96fbf78875c4e19e91a2c3aa2e6c1", "body": "waitForApply's discovery loop slept a full poll interval before its first\nfindWorkspace call, so a run that already existed was found one interval\nlate, and with pollMs >= discoveryMs the budget could be spent before a\nuseful check. Move the sleep to the end of the loop body (check, then\nsleep): fin\n[…]\n t=0 without\nsleeping) and the pollMs >= discoveryMs edge case. All existing discovery /\ntimeout / resilience tests pass unchanged.\n\nCloses #35\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(polling): check workspace before sleeping in the discovery loop", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:49:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "932aa74ab008ffca67217374c09b121035eb0e2f", "body": "…--components--create-op-node\n\nchore(main): release 0.10.14", "is_bot": false, "headline": "Merge pull request #65 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:42:01Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4fd8b3855e648ec59982188a489fc8f1cbb9ad95", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.14", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:40:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "52e8fb1b7a6fa6212d3c7d0d4d89e7e5ac86ff87", "body": "fix(ollama): add request timeouts to health + warm probes", "is_bot": false, "headline": "Merge pull request #64 from OpusPopuli/fix/network-timeouts-ollama-31", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:40:33Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "8d1ff58e5fa2ab7f91ce2310416b340f9b597aac", "body": "Final slice of #31 (Ollama). Both checkOllamaHealth and warmModel already\nhad try/catch (Ollama never crashed), but their fetch calls had no\ntimeout, so a hung daemon (accepts the connection, never responds) would\nstall bootstrap forever.\n\n- checkOllamaHealth: AbortController + 5s timeout — a metada\n[…]\nboth timeouts via fake timers + an abort-aware fetch stub, plus a\nnon-timeout warm failure case so both catch branches are covered.\n\nCloses #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(ollama): add request timeouts to health + warm probes", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:39:07Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "a0094db32a45ba9dd2cae7d03383beaa06c46851", "body": "…--components--create-op-node\n\nchore(main): release 0.10.13", "is_bot": false, "headline": "Merge pull request #63 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:30:49Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ba48de76b3fa61f91be292fbb9d7be5c7c90b9d3", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.13", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:29:50Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b4aa09632481f61a77572205eed2fecdd20fa210", "body": "…e-31\n\nfix(cloudflare): add request timeout + degrade network failures gracefully", "is_bot": false, "headline": "Merge pull request #62 from OpusPopuli/fix/network-timeouts-cloudflar…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:29:35Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "3075c6a67a6ac485819af31d6eb00ee250a7e17a", "body": "…fully\n\nSecond slice of #31 (Cloudflare), mirroring the TFC fix. The Cloudflare\n`get` helper had no timeout and only wrapped `.json()` in try/catch, so a\nstalled connection could hang `init` (probeCloudflareToken makes 6\nsequential calls) and a transient fetch throw could reject out of the\nwizard.\n\n\n[…]\net to a\nnetwork-error message) + added probeCloudflareToken network-error and\ntimeout-abort (fake timers) cases.\n\nOllama is Subtask 3. Refs #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(cloudflare): add request timeout + degrade network failures grace…", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:26:51Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "7c3840742961a87a4281a93c87bb6bc311c9bd37", "body": "…--components--create-op-node\n\nchore(main): release 0.10.12", "is_bot": false, "headline": "Merge pull request #61 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T01:19:30Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "123314fa53c96fb08261d9c388da48ef11f0c6c3", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.12", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:53:37Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "7159518eaf98aea1f67b460ff7a472a4ac9f40c2", "body": "fix(tfc): add request timeouts + degrade network failures gracefully", "is_bot": false, "headline": "Merge pull request #60 from OpusPopuli/fix/network-timeouts-31", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:53:22Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b9a0aa0cfa043ddc5fece473412905e090cc4634", "body": "First slice of #31 (TFC). Native `fetch` has no default timeout and the\nTFC helpers had no try/catch around the fetch itself, so a stalled\nconnection could hang `init` indefinitely and a transient network throw\ncould reject out of the ~10-minute apply-wait and crash the wizard.\n\n- constants.ts: add \n[…]\n tracks the pre-existing output-missing misdiagnosis on a\ntransient final-output-fetch failure. Cloudflare + Ollama are Subtasks 2/3.\n\nRefs #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(tfc): add request timeouts + degrade network failures gracefully", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T00:51:36Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "8ee67ee7914d75d74f118f4dc770377fac74026b", "body": "…--components--create-op-node\n\nchore(main): release 0.10.11", "is_bot": false, "headline": "Merge pull request #58 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:03:01Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "419a478f2e474223b8a3471d4d898738e3fa8a4c", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.11", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:01:26Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "5d5913cdbd76c05779b9ef916745c44a73871186", "body": "fix(bootstrap): align llm-model docs + picker hints with actual defaults", "is_bot": false, "headline": "Merge pull request #57 from OpusPopuli/fix/llm-default-consistency-33", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:01:11Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "c1a24998464064eb0a1bf96483c9446fd1b4077c", "body": "Issue #33 asked to verify the default Ollama tag `qwen3.5:9b`. It is valid\nand pullable (confirmed against the Ollama registry manifest + the official\nQwen3.5 release announcement) — Qwen3.5 shipped after the reviewer's\nknowledge cutoff, and their review environment had the registry blocked,\nwhich i\n[…]\n36–48 GB\" hint (48 GB actually pre-selects\n 32b) to \"\u003c 48 GB\".\n\nNo behavior change; bootstrap.test.ts doesn't assert on hint text.\n\nCloses #33\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(bootstrap): align llm-model docs + picker hints with actual defaults", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T23:28:33Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "9f6bf9282926335cb98c6379daae33dad19a3640", "body": "ci(lint): enforce the sonar pass in CI and prepublishOnly", "is_bot": false, "headline": "Merge pull request #56 from OpusPopuli/ci/enforce-sonar-gate-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T04:00:03Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "cb02cec37dd0964cad2102d0935cbb54d71e5fd4", "body": "Final step of the #37 burndown. All cognitive-complexity findings are\ncleared (58 -> 0), so the second ESLint pass is now turned on as a\nblocking gate:\n\n- ci.yml: add a `Lint (sonar)` step after `Lint (eslint)`\n- package.json: restore `pnpm lint:sonar` to the prepublishOnly chain\n- eslint.sonar.conf\n[…]\nI\" deferral note\n\nThe two-pass ESLint setup (base + sonarjs cognitive-complexity \u003c= 15) now\nmirrors @opuspopuli/regions end to end.\n\nCloses #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "ci(lint): enforce the sonar pass in CI and prepublishOnly", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T03:58:44Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "23f978ec07257a1b55682d42d6e50a707e424849", "body": "…--components--create-op-node\n\nchore(main): release 0.10.10", "is_bot": false, "headline": "Merge pull request #55 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:55:43Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "aabf289e0b6251b091d02c1a03d33a20428a5db7", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.10", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:55:07Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "3b8b5337d8269729cfb173d18c9bd8c12f9596f0", "body": "refactor(lib): extract helpers to clear remaining complexity findings", "is_bot": false, "headline": "Merge pull request #54 from OpusPopuli/refactor/sonar-lib-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:54:47Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b5e61671dd4779afe6733f920b7aefb3a3c14a06", "body": "Eighth slice of the #37 burndown — clears the last 7 cognitive-complexity\nfindings across the lib + region command. No behavior change.\n\n- lib/region.ts validateRegionConfig (22): split into 4 sub-validators;\n issue-message order preserved via spread\n- lib/docker.ts waitForHealthy (16) + assessHeal\n[…]\ns, guarding the extractions.\n\nWith this, `pnpm lint:sonar` is green (0 findings) — the CI gate flip is\nthe only remaining step (#37).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(lib): extract helpers to clear remaining complexity findings", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T03:53:08Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "71f818f11dbc8566d2582b4bb6e20d32dc62c9e7", "body": "…--components--create-op-node\n\nchore(main): release 0.10.9", "is_bot": false, "headline": "Merge pull request #53 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T00:00:20Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4a7547e55666d8817803b867ea34926d0481a59a", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.9", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T22:52:59Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "202b7f926de09f76c6725e36dd55461504328670", "body": "refactor(verify): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #52 from OpusPopuli/refactor/sonar-verify-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T22:52:44Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ea4db7d1b5c825f2321729e16622af430076e67a", "body": "Seventh slice of the #37 burndown — verify had two cognitive-complexity\nfindings: runVerify (28) and the `.action` handler (28). Extract each into\n\u003c=15-CC helpers. No behavior change.\n\nrunVerify -> verifyTlsPhase / verifyHealthPhase / verifyGraphqlPhase /\nverifyCloudflarePhase / verifyCosignPhase. E\n[…]\nhe 17\nrunVerify cases; the action helpers all mix resolution with\np.cancel/process.exit, so there is no fully-pure seam to unit-test.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(verify): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T20:01:13Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bb08a88b0d70a998e38476abf900d9d73ee19d17", "body": "…--components--create-op-node\n\nchore(main): release 0.10.8", "is_bot": false, "headline": "Merge pull request #51 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:39:13Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4b14f4f60e3f824adc27519f0401504c4667dd96", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.8", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:35:48Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "dadb350bd5bc4cdbd6f03840e07ab58b58331015", "body": "refactor(reset): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #50 from OpusPopuli/refactor/sonar-reset-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:35:29Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "42804295f4bdd0b9c3e509ad759b3afcbf5628d8", "body": "Sixth slice of the #37 burndown — reset had two cognitive-complexity\nfindings: runReset (36) and the `.action` handler (50). Extract each into\n\u003c=15-CC helpers. No behavior change.\n\nrunReset -> resetStopStackPhase / resetLaunchAgentPhase /\nresetDockerLogoutPhase, each returning a ResetPhase; runReset\n[…]\n default) — mirrors the buildComposeEnv\nprecedent. Full suite 388 green, incl. the 21 existing runReset cases\n(onPhase order intact).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(reset): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T14:55:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "f61ce1912e082908843633d5c73fe9c2c38f2bca", "body": "…--components--create-op-node\n\nchore(main): release 0.10.7", "is_bot": false, "headline": "Merge pull request #49 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:24:54Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "c0d1c11fa1475db080d411de1d9575dd03047242", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.7", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:23:39Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "cc86886ee7e3df0ee67aacf6287e784a1daba1b9", "body": "refactor(init): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #48 from OpusPopuli/refactor/sonar-init-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:23:24Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "20b3dba367df1fad265e182dba8417d5b8cee619", "body": "Fifth slice of the #37 burndown — the init `.action` handler was\ncognitive-complexity 71. Extract each phase into its own \u003c=15-CC helper so\nthe handler becomes a ~45-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim, restructured \n[…]\n interactive I/O; the existing\nsuite already covers the pure seams (summarizePhases,\nlistIgnoredLocalOnlyFlags), which are untouched.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(init): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T00:16:26Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "0d85c1fc0e2e5770a4380dbdefb6b6ae4a4e468b", "body": "…--components--create-op-node\n\nchore(main): release 0.10.6", "is_bot": false, "headline": "Merge pull request #47 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:52:41Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "64738945053ff60d69af19680a56d03bcc15698e", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.6", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:51:59Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "d5799dfba567ffa36536f111921e083835407845", "body": "refactor(bootstrap): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #46 from OpusPopuli/refactor/sonar-bootstrap-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:51:44Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "407caf434a7778ccefa9bb75d625d6f289579274", "body": "Fourth slice of the #37 burndown — the bootstrap `.action` handler was\ncognitive-complexity 85. Extract each phase into its own \u003c=15-CC helper so\nthe handler becomes a ~17-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim; a Colle\n[…]\nET fallback). The\ninteractive orchestration has no unit tests (it never did) — verified via\ntypecheck, build, and `bootstrap --help`.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(bootstrap): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-05T23:48:24Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "3aba80827900f83899d9a7eb918704164cc6f626", "body": "…--components--create-op-node\n\nchore(main): release 0.10.5", "is_bot": false, "headline": "Merge pull request #45 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:18:38Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4abdd65a1921f674836a17ba8ee11a0496070957", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.5", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:18:04Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "9b5789ca38ad9bb28afd0ac4e0e13d3944326557", "body": "fix(lint): rewrite super-linear regexes in src", "is_bot": false, "headline": "Merge pull request #44 from OpusPopuli/fix/sonar-regex-backtracking-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:17:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "54ab5be40c42cfadd58e07c2824f9737bc81d6c0", "body": null, "is_bot": false, "headline": "Merge branch 'main' into fix/sonar-regex-backtracking-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:17:10Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ff66176ac4b5e8252380d3afd97c808bb3e7172c", "body": "…--components--create-op-node\n\nchore(main): release 0.10.4", "is_bot": false, "headline": "Merge pull request #43 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:16:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "84e957343b8afc0a374604a008f6387b4a2e1a14", "body": "Third slice of the #37 burndown — clears the 4 super-linear-regex\nfindings in `src/`, leaving only the 13 cognitive-complexity refactors.\nEach rewrite is backtracking-free and behavior-preserving for real\ninputs, with characterization tests locking the equivalence.\n\n- bootstrap.ts estimatedPullTime:\n[…]\n05b\nsizes) and the slugify edge trim; the existing generatePostgresPassword\n\"no + / =\" assertion already covers the base64url change.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(lint): rewrite super-linear regexes in src", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-05T23:15:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "4e0e0fada6cd3fb476d74c40477b47e7cd54ea7b", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.4", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:04:09Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "68e892131c6260d7626292ed1f1cdefb45573047", "body": "refactor(lint): clear cheap sonar findings in src", "is_bot": false, "headline": "Merge pull request #42 from OpusPopuli/refactor/sonar-cheap-src-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:53Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "845f7fee4ecf763fdbbb5c561245dd788c009932", "body": null, "is_bot": false, "headline": "Merge branch 'main' into refactor/sonar-cheap-src-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:17Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "e9cd70224a103a688a2f0e9e4c44232de2b4c926", "body": "test(lint): clear sonar findings in the test suite", "is_bot": false, "headline": "Merge pull request #40 from OpusPopuli/test/sonar-test-findings-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:02Z", "body_truncated": false, "is_coding_agent": false } ], "releases_count": 35, "commits_last_year": 187, "latest_release_at": "2026-07-19T16:13:33Z", "latest_release_tag": "v0.16.0", "releases_from_tags": false, "days_since_last_push": 5, "active_weeks_last_year": 5, "days_since_latest_release": 5, "mean_days_between_releases": 0.9 }, "community": { "has_readme": true, "has_license": true, "has_description": true, "has_contributing": false, "health_percentage": 50, "has_issue_template": false, "has_code_of_conduct": false, "has_pull_request_template": false }, "ecosystem": { "packages": [ { "name": "create-op-node", "exists": true, "license": "AGPL-3.0-or-later", "keywords": [ "opuspopuli", "civic-tech", "federation", "cli", "bootstrap", "mac-studio", "cloudflare-tunnel" ], "ecosystem": "npm", "matches_repo": true, "registry_url": "https://www.npmjs.com/package/create-op-node", "is_deprecated": false, "latest_version": "0.16.0", "repository_url": "https://github.com/OpusPopuli/create-op-node", "versions_count": 44, "total_downloads": null, "dependents_count": null, "deprecation_note": null, "maintainers_count": 1, "monthly_downloads": 5028, "first_published_at": "2026-06-18T01:59:12.555000Z", "latest_published_at": "2026-07-19T16:14:23.712000Z", "latest_version_yanked": null, "days_since_latest_publish": 5 } ] }, "popularity": { "forks": 1, "stars": 0, "watchers": 0, "fork_history": { "days": [ { "date": "2026-07-11", "count": 1 } ], "complete": true, "collected": 1, "total_forks": 1 }, "star_history": { "days": [], "complete": true, "collected": 0, "total_stars": 0, "collected_at": null }, "open_issues_and_prs": 1 }, "ai_readiness": { "has_nix": false, "example_dirs": [], "has_llms_txt": false, "has_dockerfile": false, "has_mcp_signal": false, "bootstrap_files": [], "api_schema_files": [], "has_devcontainer": false, "typecheck_configs": [ "tsconfig.json" ], "toolchain_manifests": [], "largest_source_bytes": 78214, "source_files_sampled": 58, "oversized_source_files": 1, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "dependencies": { "manifests": [ "package.json" ], "advisories": { "error": null, "scope": "published_package", "source": "osv", "findings": [], "collected": true, "malicious": [], "truncated": false, "by_severity": {}, "advisory_count": 0, "affected_count": 0, "assessed_count": 88, "malicious_count": 0, "assessed_package": "npm:create-op-node@0.16.0", "unassessed_count": 0, "direct_affected_count": 0 }, "ecosystems": [ "npm" ], "dependencies": [ { "name": "@cfworker/json-schema", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^4.1.1" }, { "name": "@clack/prompts", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^0.9.0" }, { "name": "@octokit/rest", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^22.0.0" }, { "name": "cloudflare", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^4.0.0" }, { "name": "commander", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^13.1.0" }, { "name": "execa", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^9.5.2" }, { "name": "libsodium-wrappers", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^0.8.4" }, { "name": "picocolors", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^1.1.1" }, { "name": "zod", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^3.24.1" } ], "all_dependencies": { "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository", "source": null, "packages": [], "collected": false, "truncated": false, "total_count": null, "direct_count": null, "indirect_count": null } }, "maintainership": { "issues": { "open_prs": 0, "merged_prs": 90, "open_issues": 1, "closed_ratio": 0.955, "closed_issues": 21, "closed_unmerged_prs": 2 }, "bus_factor": 1, "bot_contributors": 1, "top_contributors": [ { "type": "User", "login": "rodneygagnon", "commits": 120, "avatar_url": "https://avatars.githubusercontent.com/u/43381472?v=4" }, { "type": "User", "login": "claude", "commits": 2, "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4" } ], "contributors_sampled": 2, "top_contributor_share": 0.984 }, "quality_signals": { "has_ci": true, "has_tests": true, "ci_workflows": [ "ci.yml", "publish.yml", "release-please.yml" ], "has_docs_dir": false, "linter_configs": [ "eslint.config.mjs" ], "has_editorconfig": false, "has_linter_config": true, "has_precommit_config": false }, "security_signals": { "lockfiles": [ "pnpm-lock.yaml" ], "scorecard": { "checks": [ { "name": "Binary-Artifacts", "score": 10, "reason": "no binaries found in the repo", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts" }, { "name": "Branch-Protection", "score": null, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection" }, { "name": "CI-Tests", "score": 10, "reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests" }, { "name": "CII-Best-Practices", "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices" }, { "name": "Code-Review", "score": 0, "reason": "Found 0/25 approved changesets -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review" }, { "name": "Contributors", "score": 0, "reason": "project has 0 contributing companies or organizations -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors" }, { "name": "Dangerous-Workflow", "score": 10, "reason": "no dangerous workflow patterns detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow" }, { "name": "Dependency-Update-Tool", "score": 0, "reason": "no update tool detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool" }, { "name": "Fuzzing", "score": 0, "reason": "project is not fuzzed", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing" }, { "name": "License", "score": 10, "reason": "license file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license" }, { "name": "Maintained", "score": 0, "reason": "project was created within the last 90 days. Please review its contents carefully", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained" }, { "name": "Packaging", "score": 10, "reason": "packaging workflow detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging" }, { "name": "Pinned-Dependencies", "score": 7, "reason": "dependency not pinned by hash detected -- score normalized to 7", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies" }, { "name": "SAST", "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast" }, { "name": "Security-Policy", "score": 0, "reason": "security policy file not detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy" }, { "name": "Signed-Releases", "score": null, "reason": "no releases found", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases" }, { "name": "Token-Permissions", "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions" }, { "name": "Vulnerabilities", "score": 5, "reason": "5 existing vulnerabilities detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities" } ], "commit": "0edf6c903b9ada6a3973490465ce0de02856fc09", "ran_at": "2026-07-25T14:28:41Z", "aggregate_score": 3.9, "scorecard_version": "v5.5.0" }, "has_codeql_workflow": false, "has_security_policy": false, "has_dependabot_config": false }, "contribution_flow": { "collected": true, "ci_last_run_at": "2026-07-19T16:14:28Z", "oldest_open_prs": [], "last_merged_pr_at": "2026-07-19T16:13:23Z", "ci_last_conclusion": "SUCCESS", "oldest_open_issues": [ { "number": 114, "created_at": "2026-07-19T16:26:12Z", "last_comment_at": null, "last_comment_author": null } ] } }, "config": { "disabled_metrics": [], "disabled_categories": [], "disabled_components": {} }, "source": { "url": "https://github.com/OpusPopuli/create-op-node", "host": "github.com", "name": "create-op-node", "owner": "OpusPopuli" }, "metrics": { "overall": { "key": "overall", "band": "moderate", "name": "Overall health", "note": null, "notes": [], "value": 58, "inputs": { "security": 51, "vitality": 75, "community": 33, "governance": 54, "engineering": 70 }, "components": [] }, "categories": [ { "key": "vitality", "band": "good", "name": "Vitality", "value": 75, "weight": 0.22, "metrics": [ { "key": "development_activity", "band": "moderate", "name": "Development activity", "note": null, "notes": [], "value": 58, "inputs": { "commits_last_year": 187, "human_commit_share": 1, "days_since_last_push": 5, "active_weeks_last_year": 5 }, "components": [ { "key": "push_recency", "name": "Push recency", "detail": "last push 5 days ago", "points": 36, "status": "met", "details": [ { "code": "push_recency", "params": { "days": 5 } } ], "max_points": 36 }, { "key": "commit_cadence", "name": "Commit cadence", "detail": "5/52 weeks with commits", "points": 3.5, "status": "partial", "details": [ { "code": "commit_cadence_weeks", "params": { "weeks": 5 } } ], "max_points": 36 }, { "key": "commit_volume", "name": "Commit volume", "detail": "187 commits in the last year", "points": 18, "status": "met", "details": [ { "code": "commits_last_year", "params": { "count": 187 } } ], "max_points": 18 }, { "key": "openssf_scorecard_maintained", "name": "OpenSSF Scorecard: Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "release_discipline", "band": "excellent", "name": "Release discipline", "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "openssf_scorecard_signed_releases" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 100, "inputs": { "releases_count": 35, "latest_release_tag": "v0.16.0", "releases_from_tags": false, "days_since_latest_release": 5, "mean_days_between_releases": 0.9 }, "components": [ { "key": "ships_releases", "name": "Ships releases", "detail": "35 releases published", "points": 27, "status": "met", "details": [ { "code": "releases_published", "params": { "count": 35 } } ], "max_points": 27 }, { "key": "release_recency", "name": "Release recency", "detail": "latest release 5 days ago", "points": 36, "status": "met", "details": [ { "code": "release_recency", "params": { "days": 5 } } ], "max_points": 36 }, { "key": "release_cadence", "name": "Release cadence", "detail": "a release every ~0.9 days", "points": 27, "status": "met", "details": [ { "code": "release_cadence", "params": { "gap": 0.9 } } ], "max_points": 27 }, { "key": "openssf_scorecard_signed_releases", "name": "OpenSSF Scorecard: Signed-Releases", "detail": "no releases found", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 10 } ] }, { "key": "abandonment", "band": "excellent", "name": "Abandonment", "note": null, "notes": [], "value": 100, "inputs": { "cap": null, "state": "unverified", "guards": [], "signals": [], "red_flag": false, "multiplier_pct": 100, "declared_reason": null, "unverified_reason": "repository_too_young", "unanswered_open_prs": null, "unanswered_open_issues": null, "days_since_last_merged_pr": null, "days_since_last_human_commit": null, "days_since_last_human_commit_is_floor": false }, "components": [ { "key": "project_is_still_maintained", "name": "Project is still maintained", "detail": "maintenance record not established from the collected data", "points": 100, "status": "met", "details": [ { "code": "abandonment_unverified", "params": {} } ], "max_points": 100 } ] } ], "description": "Is the project alive — is code being written and are releases shipping?" }, { "key": "community", "band": "at_risk", "name": "Community & Adoption", "value": 33, "weight": 0.18, "metrics": [ { "key": "popularity", "band": "critical", "name": "Popularity & adoption", "note": null, "notes": [], "value": 1, "inputs": { "forks": 1, "stars": 0, "watchers": 0, "growth_state": "unverified", "growth_factor_pct": 100, "growth_unverified_reason": "no_history" }, "components": [ { "key": "stars", "name": "Stars", "detail": "0 stars", "points": 0, "status": "missed", "details": [ { "code": "stars", "params": { "count": 0 } } ], "max_points": 60 }, { "key": "forks", "name": "Forks", "detail": "1 forks", "points": 0, "status": "missed", "details": [ { "code": "forks", "params": { "count": 1 } } ], "max_points": 25 }, { "key": "watchers", "name": "Watchers", "detail": "0 watchers", "points": 0, "status": "missed", "details": [ { "code": "watchers", "params": { "count": 0 } } ], "max_points": 15 } ] }, { "key": "community_health", "band": "moderate", "name": "Community health", "note": null, "notes": [], "value": 50, "inputs": { "has_readme": true, "has_license": true, "has_contributing": false, "has_issue_template": false, "has_code_of_conduct": false, "has_pull_request_template": false }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 22.5, "status": "met", "details": [], "max_points": 22.5 }, { "key": "license", "name": "License", "detail": "recognized license (AGPL-3.0)", "points": 22.5, "status": "met", "details": [ { "code": "license_standard", "params": {} }, { "code": "license_spdx", "params": { "spdx": "AGPL-3.0" } } ], "max_points": 22.5 }, { "key": "contributing_guide", "name": "CONTRIBUTING guide", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 18 }, { "key": "code_of_conduct", "name": "Code of conduct", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 13.5 }, { "key": "issue_template", "name": "Issue template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 7.2 }, { "key": "pr_template", "name": "PR template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.3 } ] }, { "key": "ecosystem_adoption", "band": "moderate", "name": "Ecosystem adoption (downloads)", "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "registry_dependents" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 62, "inputs": { "packages": [ "create-op-node" ], "dependents": null, "ecosystems": "npm", "total_downloads": null, "monthly_downloads": 5028 }, "components": [ { "key": "monthly_downloads", "name": "Monthly downloads", "detail": "5,028 downloads/month across npm", "points": 49.4, "status": "partial", "details": [ { "code": "downloads_monthly", "params": { "count": 5028, "ecosystems": "npm" } } ], "max_points": 80 }, { "key": "registry_dependents", "name": "Registry dependents", "detail": "not reported by this ecosystem", "points": 0, "status": "excluded", "details": [ { "code": "not_reported_by_this_ecosystem", "params": {} } ], "max_points": 20 } ] } ], "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?" }, { "key": "governance", "band": "moderate", "name": "Sustainability & Governance", "value": 54, "weight": 0.24, "metrics": [ { "key": "maintainer_resilience", "band": "critical", "name": "Maintainer resilience (bus factor)", "note": null, "notes": [], "value": 12, "inputs": { "bus_factor": 1, "contributors_sampled": 2, "top_contributor_share": 0.984 }, "components": [ { "key": "bus_factor", "name": "Bus factor", "detail": "1 contributor(s) cover half of all commits", "points": 9, "status": "partial", "details": [ { "code": "bus_factor", "params": { "count": 1 } } ], "max_points": 54 }, { "key": "commit_distribution", "name": "Commit distribution", "detail": "top contributor authored 98% of commits", "points": 0.4, "status": "partial", "details": [ { "code": "top_contributor_share", "params": { "share": 98 } } ], "max_points": 22.5 }, { "key": "contributor_breadth", "name": "Contributor breadth", "detail": "2 contributors", "points": 2.7, "status": "partial", "details": [ { "code": "contributors_sampled", "params": { "count": 2 } } ], "max_points": 13.5 }, { "key": "openssf_scorecard_contributors", "name": "OpenSSF Scorecard: Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "responsiveness", "band": "good", "name": "Issue & PR responsiveness", "note": null, "notes": [], "value": 82, "inputs": { "merged_prs": 90, "open_issues": 1, "closed_issues": 21, "issue_closed_ratio": 0.955, "closed_unmerged_prs": 2 }, "components": [ { "key": "issue_resolution", "name": "Issue resolution", "detail": "96% of issues closed", "points": 44.6, "status": "partial", "details": [ { "code": "issues_closed_share", "params": { "share": 96 } } ], "max_points": 46.75 }, { "key": "pr_acceptance", "name": "PR acceptance", "detail": "90/92 decided PRs merged", "points": 37.4, "status": "partial", "details": [ { "code": "decided_prs_merged", "params": { "merged": 90, "decided": 92 } } ], "max_points": 38.25 }, { "key": "openssf_scorecard_code_review", "name": "OpenSSF Scorecard: Code-Review", "detail": "Found 0/25 approved changesets -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 15 } ] }, { "key": "stewardship", "band": "at_risk", "name": "Ownership & stewardship", "note": null, "notes": [], "value": 38, "inputs": { "followers": 0, "owner_type": "Organization", "is_verified": null, "owner_login": "OpusPopuli", "public_repos": 7, "account_age_days": 216 }, "components": [ { "key": "ownership_backing", "name": "Ownership backing", "detail": "organization-owned", "points": 30, "status": "met", "details": [ { "code": "owner_organization", "params": {} } ], "max_points": 30 }, { "key": "verified_domain", "name": "Verified domain", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 20 }, { "key": "owner_reach", "name": "Owner reach", "detail": "0 followers of OpusPopuli", "points": 0, "status": "missed", "details": [ { "code": "owner_followers", "params": { "count": 0, "login": "OpusPopuli" } } ], "max_points": 25 }, { "key": "track_record", "name": "Track record", "detail": "7 public repos, account ~0 yr old", "points": 7.8, "status": "partial", "details": [ { "code": "public_repos", "params": { "count": 7 } }, { "code": "account_age_years", "params": { "years": 0 } } ], "max_points": 25 } ] }, { "key": "package_maintenance", "band": "excellent", "name": "Package maintenance", "note": null, "notes": [], "value": 100, "inputs": { "packages": [ "create-op-node" ], "ecosystems": "npm", "any_deprecated": false, "min_days_since_publish": 5 }, "components": [ { "key": "published_resolvable", "name": "Published & resolvable", "detail": "1 package(s) on npm", "points": 25, "status": "met", "details": [ { "code": "packages_published", "params": { "count": 1, "ecosystems": "npm" } } ], "max_points": 25 }, { "key": "publish_recency", "name": "Publish recency", "detail": "latest publish 5 days ago", "points": 35, "status": "met", "details": [ { "code": "publish_recency", "params": { "days": 5 } } ], "max_points": 35 }, { "key": "version_history", "name": "Version history", "detail": "44 published versions", "points": 20, "status": "met", "details": [ { "code": "published_versions", "params": { "count": 44 } } ], "max_points": 20 }, { "key": "not_deprecated", "name": "Not deprecated", "detail": "active, not deprecated or yanked", "points": 20, "status": "met", "details": [ { "code": "package_not_deprecated", "params": {} } ], "max_points": 20 } ] } ], "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?" }, { "key": "engineering", "band": "good", "name": "Engineering Quality", "value": 70, "weight": 0.2, "metrics": [ { "key": "engineering_practices", "band": "good", "name": "Engineering practices", "note": null, "notes": [], "value": 84, "inputs": { "has_ci": true, "has_tests": true, "has_editorconfig": false, "has_linter_config": true, "has_precommit_config": false }, "components": [ { "key": "ci_workflows", "name": "CI workflows", "detail": "3 workflow(s)", "points": 24, "status": "met", "details": [ { "code": "ci_workflows", "params": { "count": 3 } } ], "max_points": 24 }, { "key": "tests_present", "name": "Tests present", "detail": null, "points": 24, "status": "met", "details": [], "max_points": 24 }, { "key": "linter_config", "name": "Linter config", "detail": "eslint.config.mjs", "points": 16, "status": "met", "details": [ { "code": "file_list", "params": { "files": "eslint.config.mjs" } } ], "max_points": 16 }, { "key": "pre_commit_hooks", "name": "Pre-commit hooks", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 9.6 }, { "key": "editorconfig", "name": ".editorconfig", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.4 }, { "key": "openssf_scorecard_ci_tests", "name": "OpenSSF Scorecard: CI-Tests", "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "points": 20, "status": "met", "details": [], "max_points": 20 } ] }, { "key": "documentation", "band": "moderate", "name": "Documentation", "note": null, "notes": [], "value": 50, "inputs": { "topics": [], "has_wiki": true, "homepage": null, "has_readme": true, "has_docs_dir": false, "has_description": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 30, "status": "met", "details": [], "max_points": 30 }, { "key": "documentation_directory", "name": "Documentation directory", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 25 }, { "key": "documentation_homepage_site", "name": "Documentation / homepage site", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "repository_description", "name": "Repository description", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "topics", "name": "Topics", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 10 }, { "key": "wiki", "name": "Wiki", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 } ] } ], "description": "Are baseline engineering and documentation practices in place?" }, { "key": "security", "band": "moderate", "name": "Security", "value": 51, "weight": 0.16, "metrics": [ { "key": "security_posture", "band": "at_risk", "name": "Security posture", "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "branch_protection", "signed_releases" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 39, "inputs": { "source": "openssf_scorecard", "checks_evaluated": 16, "scorecard_version": "v5.5.0", "checks_inconclusive": 2, "scorecard_aggregate": 3.9 }, "components": [ { "key": "binary_artifacts", "name": "Binary-Artifacts", "detail": "no binaries found in the repo", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "branch_protection", "name": "Branch-Protection", "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 7.5 }, { "key": "ci_tests", "name": "CI-Tests", "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "cii_best_practices", "name": "CII-Best-Practices", "detail": "no effort to earn an OpenSSF best practices badge detected", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "code_review", "name": "Code-Review", "detail": "Found 0/25 approved changesets -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "contributors", "name": "Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "dangerous_workflow", "name": "Dangerous-Workflow", "detail": "no dangerous workflow patterns detected", "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "dependency_update_tool", "name": "Dependency-Update-Tool", "detail": "no update tool detected", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "fuzzing", "name": "Fuzzing", "detail": "project is not fuzzed", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "license", "name": "License", "detail": "license file detected", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "maintained", "name": "Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "packaging", "name": "Packaging", "detail": "packaging workflow detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "pinned_dependencies", "name": "Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 7", "points": 3.5, "status": "partial", "details": [], "max_points": 5 }, { "key": "sast", "name": "SAST", "detail": "SAST tool is not run on all commits -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "security_policy", "name": "Security-Policy", "detail": "security policy file not detected", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "signed_releases", "name": "Signed-Releases", "detail": "no releases found", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 7.5 }, { "key": "token_permissions", "name": "Token-Permissions", "detail": "detected GitHub workflow tokens with excessive permissions", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "vulnerabilities", "name": "Vulnerabilities", "detail": "5 existing vulnerabilities detected", "points": 3.8, "status": "partial", "details": [], "max_points": 7.5 } ] }, { "key": "dependency_advisories", "band": "excellent", "name": "Dependency advisories", "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-op-node@0.16.0 runtime dependency closure — what installing the published package pulls in — 88 packages. Reachability is not analyzed.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "no_advisories_left_outstanding" ] } }, { "code": "weights_renormalized", "params": {} }, { "code": "advisories_scope_published", "params": { "package": "npm:create-op-node@0.16.0", "assessed": 88 } }, { "code": "advisories_reachability", "params": {} } ], "value": 100, "inputs": { "source": "osv", "advisories": 0, "affected_packages": 0, "assessed_packages": 88, "unassessed_packages": 0, "affected_by_severity": "none", "direct_affected_packages": 0 }, "components": [ { "key": "direct_dependencies_free_of_known_advisories", "name": "Direct dependencies free of known advisories", "detail": "no direct dependency carries a known advisory", "points": 35, "status": "met", "details": [ { "code": "no_direct_advisories", "params": {} } ], "max_points": 35 }, { "key": "indirect_dependencies_free_of_known_advisories", "name": "Indirect dependencies free of known advisories", "detail": "no indirect dependency carries a known advisory", "points": 25, "status": "met", "details": [ { "code": "no_indirect_advisories", "params": {} } ], "max_points": 25 }, { "key": "no_advisories_left_outstanding", "name": "No advisories left outstanding", "detail": "no advisory carries a publication date", "points": 0, "status": "excluded", "details": [ { "code": "advisories_no_publication_date", "params": {} } ], "max_points": 40 } ] }, { "key": "malicious_dependencies", "band": "excellent", "name": "Malicious dependencies", "note": null, "notes": [], "value": 100, "inputs": { "source": "osv", "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored", "packages": [], "red_flag": false, "assessed_packages": 88, "malicious_packages": 0, "direct_malicious_packages": 0, "withdrawn_malicious_packages": 0, "installable_malicious_packages": 0 }, "components": [ { "key": "no_dependency_reported_as_a_malicious_package", "name": "No dependency reported as a malicious package", "detail": "no dependency is reported as a malicious package", "points": 100, "status": "met", "details": [ { "code": "no_malicious_dependencies", "params": {} } ], "max_points": 100 } ] }, { "key": "high_risk_jurisdiction_exposure", "band": "excellent", "name": "High-Risk Jurisdiction Exposure", "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.", "notes": [ { "code": "jurisdiction_evidence_limits", "params": {} } ], "value": 100, "inputs": { "meaning": "self-published location evidence; not nationality or citizenship", "red_flag": false, "exposures": [], "policy_countries": [ "Russia", "Iran", "North Korea" ], "review_only_matches": 0, "assessed_self_published_locations": 2 }, "components": [ { "key": "policy_exposure_multiplier", "name": "Policy exposure multiplier", "detail": "no confirmed policy-scope location match", "points": 100, "status": "met", "details": [ { "code": "jurisdiction_no_match", "params": {} } ], "max_points": 100 } ] } ], "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?" }, { "key": "ai_readiness", "band": "moderate", "name": "AI Readiness", "value": 65, "weight": 0, "metrics": [ { "key": "ai_agent_context", "band": "at_risk", "name": "Agent context & guidance", "note": null, "notes": [], "value": 40, "inputs": { "has_llms_txt": false, "legible_history_share": 0.98, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "components": [ { "key": "agent_instructions", "name": "Agent instructions", "detail": "no CLAUDE.md / AGENTS.md / editor rules", "points": 0, "status": "missed", "details": [ { "code": "no_agent_instructions", "params": {} } ], "max_points": 45 }, { "key": "machine_readable_docs_llms_txt", "name": "Machine-readable docs (llms.txt)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "legible_commit_history", "name": "Legible commit history", "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)", "points": 40, "status": "met", "details": [ { "code": "legible_history", "params": { "legible": 98, "sampled": 100 } } ], "max_points": 40 } ] }, { "key": "ai_verify_loop", "band": "good", "name": "Verify loop (build / test / typecheck)", "note": null, "notes": [], "value": 71, "inputs": { "has_nix": false, "has_tests": true, "lockfiles": [ "pnpm-lock.yaml" ], "has_dockerfile": false, "typed_language": true, "bootstrap_files": [], "has_devcontainer": false, "has_linter_config": true, "typecheck_configs": [ "tsconfig.json" ], "agent_commit_share": 0.29, "toolchain_manifests": [], "dependency_bot_commit_share": 0 }, "components": [ { "key": "one_command_bootstrap", "name": "One-command bootstrap", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 18 }, { "key": "automated_tests", "name": "Automated tests", "detail": null, "points": 22, "status": "met", "details": [], "max_points": 22 }, { "key": "lint_format_config", "name": "Lint / format config", "detail": "eslint.config.mjs", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "eslint.config.mjs" } } ], "max_points": 11 }, { "key": "static_type_checking", "name": "Static type checking", "detail": "tsconfig.json", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "tsconfig.json" } } ], "max_points": 11 }, { "key": "reproducible_environment", "name": "Reproducible environment", "detail": "lockfile", "points": 10, "status": "met", "details": [ { "code": "file_list", "params": { "files": "lockfile" } } ], "max_points": 10 }, { "key": "demonstrated_agent_practice", "name": "Demonstrated agent practice", "detail": "29 of the last 100 commits agent-authored or agent-credited", "points": 10, "status": "met", "details": [ { "code": "agent_authored_commits", "params": { "count": 29, "sampled": 100 } } ], "max_points": 10 }, { "key": "automated_maintenance", "name": "Automated maintenance", "detail": "no automated dependency updates observed", "points": 0, "status": "missed", "details": [ { "code": "no_dependency_automation", "params": {} } ], "max_points": 8 }, { "key": "openssf_scorecard_pinned_dependencies", "name": "OpenSSF Scorecard: Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 7", "points": 7, "status": "partial", "details": [], "max_points": 10 } ] }, { "key": "ai_code_legibility", "band": "excellent", "name": "Code legibility for models", "note": null, "notes": [], "value": 99, "inputs": { "primary_language": "TypeScript", "largest_source_bytes": 78214, "source_files_sampled": 58, "oversized_source_files": 1 }, "components": [ { "key": "type_checkable_code", "name": "Type-checkable code", "detail": "TypeScript (statically typed)", "points": 45, "status": "met", "details": [ { "code": "statically_typed_language", "params": { "language": "TypeScript" } } ], "max_points": 45 }, { "key": "manageable_file_sizes", "name": "Manageable file sizes", "detail": "1/58 source files over 60KB", "points": 54.1, "status": "partial", "details": [ { "code": "oversized_source_files", "params": { "kb": 60, "sampled": 58, "oversized": 1 } } ], "max_points": 55 } ] } ], "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score." } ], "metrics_version": "1.13.0" }, "warnings": [ "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository" ], "report_type": "repository", "generated_at": "2026-07-25T14:28:58.849025Z", "schema_version": "0.27.0", "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpusPopuli/create-op-node.svg", "full_name": "OpusPopuli/create-op-node", "license_state": "standard", "license_spdx": "AGPL-3.0" }, "repoMeta": null, "notFound": false, "related": [ { "id": 139, "full_name": "apache/superset", "url": "https://github.com/apache/superset", "description": "Apache Superset is a Data Visualization and Data Exploration Platform", "ecosystem": "npm", "ecosystems": [ "npm", "pypi" ], "primary_language": "TypeScript", "languages": [ "TypeScript", "Python", "Jupyter Notebook" ], "topics": [ "superset", "apache", "apache-superset", "data-visualization", "data-viz", "analytics", "business-intelligence", "data-science", "data-engineering", "asf", "bi", "business-analytics", "data-analytics", "data-analysis", "python", "react", "sql-editor", "flask", "extensions", "visualization", "embed", "embedded", "sdk", "iframe", "dashboard", "chart", "cli", "development-tools" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 73846, "forks": 17889, "watchers": 1535, "monthly_downloads": 1098754, "latest_score": 97, "latest_band": "excellent", "latest_scanned_at": "2026-07-15T20:41:37.957488Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 14587, "full_name": "angular/angular-cli", "url": "https://github.com/angular/angular-cli", "description": "CLI tool for Angular", "ecosystem": "npm", "ecosystems": [ "npm" ], "primary_language": "TypeScript", "languages": [ "TypeScript" ], "topics": [ "angular", "cli", "angular-cli", "typescript" ], "license_spdx": "MIT", "license_state": "standard", "stars": 27021, "forks": 11859, "watchers": 966, "monthly_downloads": null, "latest_score": 90, "latest_band": "excellent", "latest_scanned_at": "2026-07-17T10:03:23.149200Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 28919, "full_name": "decidim/decidim", "url": "https://github.com/decidim/decidim", "description": "The participatory democracy framework. A generator and multiple gems made with Ruby on Rails", "ecosystem": "rubygems", "ecosystems": [ "rubygems", "npm" ], "primary_language": "Ruby", "languages": [ "Ruby", "HTML" ], "topics": [ "decidim", "democracy", "community", "government", "civic-tech", "civictech", "ideation", "collective-intelligence", "participation", "citizen-participation", "govtech", "stakeholder-engagement", "digital-public-goods", "digital-public-infrastructure", "dpg" ], "license_spdx": "AGPL-3.0", "license_state": "standard", "stars": 1791, "forks": 474, "watchers": 54, "monthly_downloads": null, "latest_score": 89, "latest_band": "excellent", "latest_scanned_at": "2026-07-20T16:15:15.791801Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 107, "full_name": "n8n-io/n8n", "url": "https://github.com/n8n-io/n8n", "description": "Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.", "ecosystem": "npm", "ecosystems": [ "npm" ], "primary_language": "TypeScript", "languages": [], "topics": [ "ai", "apis", "automation", "cli", "data-flow", "development", "integration-framework", "integrations", "ipaas", "low-code", "low-code-platform", "mcp", "mcp-client", "mcp-server", "n8n", "no-code", "self-hosted", "typescript", "workflow", "workflow-automation" ], "license_spdx": null, "license_state": "custom", "stars": 196209, "forks": 59293, "watchers": 1138, "monthly_downloads": 0, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-13T01:46:04.380428Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 26684, "full_name": "netlify/cli", "url": "https://github.com/netlify/cli", "description": "Netlify Command Line Interface", "ecosystem": "npm", "ecosystems": [ "npm" ], "primary_language": "TypeScript", "languages": [ "TypeScript" ], "topics": [ "netlify", "cli", "api", "static" ], "license_spdx": "MIT", "license_state": "standard", "stars": 1893, "forks": 465, "watchers": 53, "monthly_downloads": 1062880, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-19T23:05:20.811730Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 1871, "full_name": "nrwl/nx", "url": "https://github.com/nrwl/nx", "description": "The Monorepo Platform that amplifies both developers and AI agents. Nx optimizes your builds, scales your CI, and fixes failed PRs automatically. Ship in half the time.", "ecosystem": "crates", "ecosystems": [ "crates", "maven", "npm" ], "primary_language": "TypeScript", "languages": [], "topics": [ "angular", "build", "build-system", "build-tool", "building-tool", "cli", "cypress", "hacktoberfest", "javascript", "monorepo", "nextjs", "nodejs", "nx", "nx-workspaces", "react", "storybook", "typescript" ], "license_spdx": "MIT", "license_state": "standard", "stars": 29170, "forks": 2930, "watchers": 264, "monthly_downloads": 0, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-14T00:35:50.135644Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" } ] } }
Interactive bootstrap CLI for an Opus Populi federation node — from sealed-box Mac Studio + a Cloudflare account to a live public API in one command.
OpusPopuli/create-op-node 的健康指数为 100 分中的 58 分,处于「中等」区间。 其得分最高的类别是Vitality(75/100),最低的是Community & Adoption(33/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。
指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。
每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。
| 注册表 | 软件包 | 版本 | 月下载量 | 版本数 | 最近发布 | 标签 |
|---|---|---|---|---|---|---|
| npm | create-op-node | 0.16.0 | 5,028 | 44 | 5 天前 | opuspopulicivic-techfederationclibootstrapmac-studiocloudflare-tunnel |
项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?
| 36/36 | 推送新近度 — 最近一次推送于 5 天前 |
| 3.5/36 | 提交节奏 — 52 周中有 5 周有提交 |
| 18/18 | 提交量 — 最近一年 187 次提交 |
| 0/10 | OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully |
| commits_last_year | 187 |
| human_commit_share | 1 |
| days_since_last_push | 5 |
| active_weeks_last_year | 5 |
| 27/27 | 有发布版本 — 已发布 35 个发布版本 |
| 36/36 | 发布时效 — 最近一次发布版本于 5 天前 |
| 27/27 | 发布节奏 — 约每 0.9 天发布一次 |
| 0/10 | OpenSSF Scorecard:Signed-Releases — 无数据 |
| releases_count | 35 |
| latest_release_tag | v0.16.0 |
| releases_from_tags | 否 |
| days_since_latest_release | 5 |
| mean_days_between_releases | 0.9 |
项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?
| 0/60 | 星标 — 0 个星标 |
| 0/25 | 复刻 — 1 个复刻 |
| 0/15 | 关注者 — 0 位关注者 |
| forks | 1 |
| stars | 0 |
| watchers | 0 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 22.5/22.5 | 许可证 — 可识别的许可证(AGPL-3.0) |
| 0/18 | CONTRIBUTING 指南 |
| 0/13.5 | 行为准则 |
| 0/7.2 | 议题模板 |
| 0/6.3 | PR 模板 |
| has_readme | 是 |
| has_license | 是 |
| has_contributing | 否 |
| has_issue_template | 否 |
| has_code_of_conduct | 否 |
| has_pull_request_template | 否 |
| 49.4/80 | 月度下载量 — npm 合计每月 5,028 次下载 |
| 0/20 | 注册表被依赖数 — 该生态系统不报告此项 |
| packages | create-op-node |
| dependents | — |
| ecosystems | npm |
| total_downloads | — |
| monthly_downloads | 5,028 |
项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?
| 9/54 | 巴士系数 — 1 位贡献者贡献了半数提交 |
| 0.4/22.5 | 提交分布 — 头号贡献者编写了 98% 的提交 |
| 2.7/13.5 | 贡献者广度 — 2 位贡献者 |
| 0/10 | OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0 |
| bus_factor | 1 |
| contributors_sampled | 2 |
| top_contributor_share | 0.984 |
| 44.6/46.8 | 议题解决 — 96% 的议题已关闭 |
| 37.4/38.3 | PR 接受 — 已裁定的 PR 中 90/92 已合并 |
| 0/15 | OpenSSF Scorecard:Code-Review — Found 0/25 approved changesets -- score normalized to 0 |
| merged_prs | 90 |
| open_issues | 1 |
| closed_issues | 21 |
| issue_closed_ratio | 0.955 |
| closed_unmerged_prs | 2 |
| 30/30 | 所有权背书 — 组织持有 |
| 0/20 | 已验证域名 |
| 0/25 | 所有者影响力 — OpusPopuli 有 0 位关注者 |
| 7.8/25 | 既往记录 — 7 个公开仓库,账户约 0 年 |
| followers | 0 |
| owner_type | Organization |
| is_verified | — |
| owner_login | OpusPopuli |
| public_repos | 7 |
| account_age_days | 216 |
| 25/25 | 已发布且可解析 — npm 上有 1 个软件包 |
| 35/35 | 发布时效 — 最近一次发布于 5 天前 |
| 20/20 | 版本历史 — 44 个已发布版本 |
| 20/20 | 未被弃用 — 活跃,未被弃用或撤回 |
| packages | create-op-node |
| ecosystems | npm |
| any_deprecated | 否 |
| min_days_since_publish | 5 |
基础的工程与文档实践是否到位?
| 24/24 | CI 工作流 — 3 个工作流 |
| 24/24 | 存在测试 |
| 16/16 | Linter 配置 — eslint.config.mjs |
| 0/9.6 | Pre-commit 钩子 |
| 0/6.4 | .editorconfig |
| 20/20 | OpenSSF Scorecard:CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| has_ci | 是 |
| has_tests | 是 |
| has_editorconfig | 否 |
| has_linter_config | 是 |
| has_precommit_config | 否 |
| 30/30 | README |
| 0/25 | 文档目录 |
| 0/15 | 文档 / 主页站点 |
| 10/10 | 仓库描述 |
| 0/10 | 主题标签 |
| 10/10 | Wiki |
| topics | — |
| has_wiki | 是 |
| homepage | — |
| has_readme | 是 |
| has_docs_dir | 否 |
| has_description | 是 |
可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?
| 7.5/7.5 | Binary-Artifacts — no binaries found in the repo |
| 0/7.5 | Branch-Protection — 无数据 |
| 2.5/2.5 | CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 0/7.5 | Code-Review — Found 0/25 approved changesets -- score normalized to 0 |
| 0/2.5 | Contributors — project has 0 contributing companies or organizations -- score normalized to 0 |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 0/7.5 | Dependency-Update-Tool — no update tool detected |
| 0/5 | Fuzzing — project is not fuzzed |
| 2.5/2.5 | 许可证 — license file detected |
| 0/7.5 | Maintained — project was created within the last 90 days. Please review its contents carefully |
| 5/5 | Packaging — packaging workflow detected |
| 3.5/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7 |
| 0/5 | SAST — SAST tool is not run on all commits -- score normalized to 0 |
| 0/5 | Security-Policy — security policy file not detected |
| 0/7.5 | Signed-Releases — 无数据 |
| 0/7.5 | Token-Permissions — detected GitHub workflow tokens with excessive permissions |
| 3.8/7.5 | Vulnerabilities — 5 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 16 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 2 |
| scorecard_aggregate | 3.9 |
| 35/35 | 直接依赖不含已知公告 — 没有直接依赖携带已知公告 |
| 25/25 | 间接依赖不含已知公告 — 没有间接依赖携带已知公告 |
| 0/40 | 没有长期未处理的公告 — 没有公告带有发布日期 |
| source | osv |
| advisories | 0 |
| affected_packages | 0 |
| assessed_packages | 88 |
| unassessed_packages | 0 |
| affected_by_severity | none |
| direct_affected_packages | 0 |
该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。
| 0/45 | 代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则 |
| 0/15 | 机器可读文档(llms.txt) |
| 40/40 | 可读的提交历史 — 100 次人类提交中有 98 次说明了意图(结构化标题或解释性正文) |
| has_llms_txt | 否 |
| legible_history_share | 0.98 |
| agent_instruction_files | — |
| agent_instruction_max_bytes | — |
| 0/18 | 一条命令的引导启动 |
| 22/22 | 自动化测试 |
| 11/11 | Lint / 格式化配置 — eslint.config.mjs |
| 11/11 | 静态类型检查 — tsconfig.json |
| 10/10 | 可复现环境 — lockfile |
| 10/10 | 已体现的代理实践 — 最近 100 次提交中有 29 次由代理编写或署名代理 |
| 0/8 | 自动化维护 — 未观察到自动依赖更新 |
| 7/10 | OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7 |
| has_nix | 否 |
| has_tests | 是 |
| lockfiles | pnpm-lock.yaml |
| has_dockerfile | 否 |
| typed_language | 是 |
| bootstrap_files | — |
| has_devcontainer | 否 |
| has_linter_config | 是 |
| typecheck_configs | tsconfig.json |
| agent_commit_share | 0.29 |
| toolchain_manifests | — |
| dependency_bot_commit_share | 0 |
| 45/45 | 可类型检查的代码 — TypeScript(静态类型) |
| 54.1/55 | 可控的文件大小 — 采样的 58 个源文件中有 1 个超过 60KB |
| primary_language | TypeScript |
| largest_source_bytes | 78,214 |
| source_files_sampled | 58 |
| oversized_source_files | 1 |
来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。
| 10 | Binary-Artifacts | no binaries found in the repo |
| 不适用 | Branch-Protection | internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md |
| 10 | CI-Tests | 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 0 | Code-Review | Found 0/25 approved changesets -- score normalized to 0 |
| 0 | Contributors | project has 0 contributing companies or organizations -- score normalized to 0 |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 0 | Dependency-Update-Tool | no update tool detected |
| 0 | Fuzzing | project is not fuzzed |
| 10 | License | license file detected |
| 0 | Maintained | project was created within the last 90 days. Please review its contents carefully |
| 10 | Packaging | packaging workflow detected |
| 7 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 7 |
| 0 | SAST | SAST tool is not run on all commits -- score normalized to 0 |
| 0 | Security-Policy | security policy file not detected |
| 不适用 | Signed-Releases | no releases found |
| 0 | Token-Permissions | detected GitHub workflow tokens with excessive permissions |
| 5 | Vulnerabilities | 5 existing vulnerabilities detected |
| 注册表 | 软件包 | 版本约束 | 清单文件 |
|---|---|---|---|
| npm | @cfworker/json-schema | ^4.1.1 | package.json |
| npm | @clack/prompts | ^0.9.0 | package.json |
| npm | @octokit/rest | ^22.0.0 | package.json |
| npm | cloudflare | ^4.0.0 | package.json |
| npm | commander | ^13.1.0 | package.json |
| npm | execa | ^9.5.2 | package.json |
| npm | libsodium-wrappers | ^0.8.4 | package.json |
| npm | picocolors | ^1.1.1 | package.json |
| npm | zod | ^3.24.1 | package.json |
本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
安装 npm:create-op-node@0.16.0 会引入 88 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。
没有已知公告影响已评估的依赖。
公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 507,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 3464,
"TypeScript": 589418
},
"pushed_at": "2026-07-19T16:13:33Z",
"created_at": "2026-06-18T01:13:54Z",
"owner_type": "Organization",
"updated_at": "2026-07-19T16:13:26Z",
"description": "Interactive bootstrap CLI for an Opus Populi federation node — from sealed-box Mac Studio + a Cloudflare account to a live public API in one command.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "AGPL-3.0",
"default_branch": "main",
"license_spdx_raw": "AGPL-3.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": "Opus Populi",
"type": "Organization",
"login": "OpusPopuli",
"company": null,
"location": "United States of America",
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/250730830?v=4",
"created_at": "2025-12-20T17:38:32Z",
"is_verified": null,
"public_repos": 7,
"account_age_days": 216
},
"license": {
"state": "standard",
"spdx_id": "AGPL-3.0",
"raw_spdx": "AGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-07-19T16:13:33Z"
},
{
"tag": "v0.15.2",
"kind": "patch",
"published_at": "2026-07-18T02:46:06Z"
},
{
"tag": "v0.15.1",
"kind": "patch",
"published_at": "2026-07-12T23:26:59Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-07-12T22:41:15Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-07-12T21:56:27Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-07-12T21:11:26Z"
},
{
"tag": "v0.12.4",
"kind": "patch",
"published_at": "2026-07-12T00:53:11Z"
},
{
"tag": "v0.12.3",
"kind": "patch",
"published_at": "2026-07-12T00:20:28Z"
},
{
"tag": "v0.12.2",
"kind": "patch",
"published_at": "2026-07-11T23:29:11Z"
},
{
"tag": "v0.12.1",
"kind": "patch",
"published_at": "2026-07-11T23:00:57Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-07-11T22:58:47Z"
},
{
"tag": "v0.11.3",
"kind": "patch",
"published_at": "2026-07-09T01:44:08Z"
},
{
"tag": "v0.11.2",
"kind": "patch",
"published_at": "2026-07-08T22:50:43Z"
},
{
"tag": "v0.11.1",
"kind": "patch",
"published_at": "2026-07-08T20:58:47Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-07-08T16:26:18Z"
},
{
"tag": "v0.10.17",
"kind": "patch",
"published_at": "2026-07-08T04:00:32Z"
},
{
"tag": "v0.10.16",
"kind": "patch",
"published_at": "2026-07-08T03:20:59Z"
},
{
"tag": "v0.10.15",
"kind": "patch",
"published_at": "2026-07-08T02:52:26Z"
},
{
"tag": "v0.10.14",
"kind": "patch",
"published_at": "2026-07-08T02:42:11Z"
},
{
"tag": "v0.10.13",
"kind": "patch",
"published_at": "2026-07-08T02:30:58Z"
},
{
"tag": "v0.10.12",
"kind": "patch",
"published_at": "2026-07-08T01:19:41Z"
},
{
"tag": "v0.10.11",
"kind": "patch",
"published_at": "2026-07-08T00:03:10Z"
},
{
"tag": "v0.10.10",
"kind": "patch",
"published_at": "2026-07-07T03:55:52Z"
},
{
"tag": "v0.10.9",
"kind": "patch",
"published_at": "2026-07-07T00:00:30Z"
},
{
"tag": "v0.10.8",
"kind": "patch",
"published_at": "2026-07-06T15:39:22Z"
},
{
"tag": "v0.10.7",
"kind": "patch",
"published_at": "2026-07-06T00:25:04Z"
},
{
"tag": "v0.10.6",
"kind": "patch",
"published_at": "2026-07-05T23:52:49Z"
},
{
"tag": "v0.10.5",
"kind": "patch",
"published_at": "2026-07-05T23:18:49Z"
},
{
"tag": "v0.10.4",
"kind": "patch",
"published_at": "2026-07-05T23:16:59Z"
},
{
"tag": "v0.10.3",
"kind": "patch",
"published_at": "2026-07-05T23:02:07Z"
},
{
"tag": "v0.10.2",
"kind": "patch",
"published_at": "2026-06-26T17:03:27Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-06-25T22:57:26Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-06-25T19:34:05Z"
},
{
"tag": "v0.9.1",
"kind": "patch",
"published_at": "2026-06-21T15:47:03Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-06-20T23:23:12Z"
}
],
"recent_commits": [
{
"oid": "0edf6c903b9ada6a3973490465ce0de02856fc09",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.16.0 (#113)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-19T16:13:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "baca2e819d773d39de5f013ffb40949ff1113155",
"body": "…ocation (#111) (#112)\n\ndefaultComposeFiles excluded the backup overlay for --local-only nodes, so the\nreference production topology (a --local-only Mac Studio holding the real\ncorpus) shipped with no backups and no warning.\n\nBackups are now a first-class bootstrap choice:\n- enable/disable: interact\n[…]\n --backups-dir when enabled); previously backups were silently\noff for --local-only nodes.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(bootstrap)!: operator-configurable backups — on/off, schedule, l…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-19T16:07:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "64e5056729d234733c9f78d5b6658908ebac3219",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.15.2 (#110)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-18T02:45:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c994e7f963b024d3969b48f1e43ca71c931d7950",
"body": "…t (opuspopuli-node#43) (#109)\n\nThe generated op-compose wrapper exported SUPABASE_URL with a hard\nlocalhost:8000 default and ran `docker compose` with no --env-file, so an\nexported shell var overrode any .env value. Result: browser-facing auth URLs\n(API_EXTERNAL_URL, GOTRUE_JWT_ISSUER, SUPABASE_PUB\n[…]\nue breaks the managed-block validator), so both remain\nout of the managed block by design.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: single-source SUPABASE_URL via .env, stop op-compose exporting i…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-18T02:43:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8542bdf03ce4866f8da3a776e8d0a7642299f663",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.15.1 (#108)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T23:26:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4c2fb41e3c6668a6ed0873fd8c2dab7203a3543",
"body": "…ads (#107)\n\nThe generated node `.env` wrote `EMBEDDINGS_MODEL`, but no backend code reads\nthat name — packages/config-provider/src/configs/embeddings.config.ts reads\n`EMBEDDINGS_OLLAMA_MODEL` (and `EMBEDDINGS_OLLAMA_URL`). So the embeddings-model\nvalue bootstrap wrote bound to nothing: an operator \n[…]\n\ncreate-op-node doesn't need to write it.\n\nFollows #97/#98; pairs with opuspopuli-node#36.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(env-file): write EMBEDDINGS_OLLAMA_MODEL — the key the backend re…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T22:54:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "260578634cdb17fd655b180b44306ed427bd2337",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.15.0 (#106)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T22:41:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "914e3e018bd7730ae824f320b1881488e8f98bd3",
"body": "…#103) (#105)\n\n* fix(verify): collect repeated --image into an array (#103)\n\nThe --image option had a default of [] but no argParser, so commander\nstored only the last value as a string. The cosign phase then iterated\nthat string character-by-character — verifying 'g', 'h', 'c', … as image\nrefs (40 \n[…]\notstrap --local-only'.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(verify): --local-only mode + fix --image array collector (#104, …",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T22:39:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2142b5503edee3d7c116440a02b485a64fe8526f",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.14.0 (#102)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T21:56:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7756f3ad3d1e4d49da28aed0914dd260b6ec35a5",
"body": "…are pull (#101)\n\n* feat(verify): assert configured Ollama model is present + provider-aware pull\n\nCloses the config↔runtime drift that silently 404s at inference time: a node\nwhose LLM_MODEL names a model that was never pulled into the host Ollama trips\nthe circuit breaker and the job \"finishes\" wi\n[…]\nt (cosign is Phase 6).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(verify): assert configured Ollama model is present + provider-aw…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T21:52:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cae5a4b989a0d13afc1f4fd12e68214157981328",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.13.0 (#100)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T21:11:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8862610cea73a2d86edcadb0a985690b3419fd1d",
"body": "… LLM tiers (#99)\n\nModel identifiers used to be pushed into the launchd session via\n`launchctl setenv` and injected into bootstrap's compose subprocess. Both\nshadow docker compose's `.env` at `${LLM_MODEL:-…}` interpolation time\n(shell/launchd env > .env), so partial container recreates baked diverg\n[…]\nODEL from buildComposeEnv and the LaunchAgent\n so .env is authoritative.\n\nPairs with #98.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(bootstrap): single-source .env for model config + hardware-aware…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T21:07:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "197713e4aafd7c9e1e31700befeefa76e47dd01b",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.12.4 (#96)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T00:52:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c6217fbee9f56276911cd9d2f24ef6472d0a302",
"body": "…mpt-service (#95)\n\n#93: writePgsodiumKeyFile wrote the key at mode 0400, so a bootstrap re-run\nfailed EACCES reopening the read-only file (writeFile's `mode` only applies on\ncreate). rm -f before write makes it overwrite-safe across re-runs.\n\n#94: DEFAULT_IDENTITY_REGEXP pinned the cosign signer to\n[…]\npuspopuli|prompt-service) — spoofed/arbitrary org repos still fail.\n\nCloses #93\nCloses #94\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(bootstrap): idempotent key-file write + broaden cosign pin to pro…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T00:51:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4b55a34686deb72a496645d8da96a01451cd0b18",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.12.3 (#92)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T00:20:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b1420223d4780e94a13faf3658f0c9893e5de41e",
"body": "…ask (#91)\n\nTwo blockers found re-bootstrapping a region-with-prompts node from scratch.\n\nbuildComposeEnv (#90) omitted every prompt-service overlay secret\n(PROMPTS_DB_PASSWORD, PROMPT_SERVICE_API_KEY/_KEYS, admin key, URL), so\nbootstrap's own compose calls aborted interpolating ${PROMPTS_DB_PASSWOR\n[…]\nen the GUI app already exists (appPath, also\napplied to tailscale).\n\nCloses #90\nCloses #89\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(bootstrap): hydrate prompt-service env + detect existing docker c…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-12T00:17:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "40a15729c85a8bab6ad0cb70ba0d7b0391478c84",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.12.2 (#88)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-11T23:28:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32f94594e9f2180f52d9f15cbfc87429524ba107",
"body": "…R:?} vars (#87)\n\nreset ran `docker compose down` with no env, but the opuspopuli-node\ntemplate guards required secrets with `${POSTGRES_PASSWORD:?…}` etc.\nCompose interpolates the whole file even for `down`, so teardown aborted\nbefore removing anything — and continue-on-failure then deleted the\nLau\n[…]\nps it in sync with the template\nrather than drifting against a hardcoded list.\n\nCloses #85\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(reset): hydrate placeholder env so `compose down` works with ${VA…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-11T23:25:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ed8daa44bcbbccc70dfc2819fee1be0b0cdfb091",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.12.1 (#84)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-11T23:00:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "557949343fd1d08798a2034ce575475443ee83ef",
"body": "The --compose-file option on bootstrap and reset was a plain value-taking\noption with no accumulator, so commander stored it as the last string\npassed rather than an array. resolveComposeFiles() then called .map on\nthat string and threw \"inputs.map is not a function\" — so passing\n--compose-file at a\n[…]\nesolveComposeFiles tests only passed arrays, so\nthey missed the option layer).\n\nCloses #82\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): collect repeated --compose-file into an array (#83)",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-11T22:58:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f5d237ad2a6d9892ae97c0bf45ddb4834c22de21",
"body": "…--components--create-op-node\n\nchore(main): release 0.12.0",
"is_bot": false,
"headline": "Merge pull request #81 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T03:43:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "824e6a90f177a5bd41d48c4cbeaf2aa6b9bf88ba",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.12.0",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T03:42:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "628878aaa39d9f3f5362acb425ef30a6f05af15c",
"body": "feat(bootstrap): generate gateway/grafana secrets + public-profile guard (#27)",
"is_bot": false,
"headline": "Merge pull request #80 from OpusPopuli/fix/bootstrap-secret-guard-27",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T03:42:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b9fcc5b5f5f800fb7047a790c0bffd6f1c26885",
"body": "…posure\n\nThe prod compose defaults GATEWAY_HMAC_SECRET / API_KEYS to a well-known\ntemplate string and Grafana admin to admin/admin. Every checkout shares\nthose, so a Tunnel-exposed node could sign gateway<->microservice requests\nwith a publicly-known key.\n\nBootstrap now generates a per-node GATEWAY_\n[…]\nic profile when\nthose values are unset or still the well-known default; --local-only\nbootstraps (no public profile) are unaffected.\n\nCloses #27\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(bootstrap): generate gateway/grafana secrets and guard tunnel ex…",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-09T03:41:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0345fdbeb4ad83caa4504e2ab44ed288ddbf0a88",
"body": "…--components--create-op-node\n\nchore(main): release 0.11.3",
"is_bot": false,
"headline": "Merge pull request #79 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T01:43:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "012317490726aae8610ec8fc095d99c1e092573a",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.11.3",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T01:42:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ded70a7e647792a0d18c75455ebc864a43868b7a",
"body": "…ry-59\n\nfix(polling): retry a transient output fetch instead of reporting output-missing",
"is_bot": false,
"headline": "Merge pull request #78 from OpusPopuli/fix/output-fetch-transient-ret…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-09T01:42:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5d6137bb6d3cb45079b75442eb1cb11151b3549",
"body": "…put-missing\n\nIssue #59: once tfc.getJson degrades a network failure to\n{ status: 0, body: null }, fetchOutput returned null for two different\nsituations — the output being genuinely absent, and a transient blip while\nfetching it. waitForRunOutput couldn't tell them apart, so a network hiccup\non the\n[…]\n-string)/error(404)/\nerror(throw); polling transient-error-then-value => success (no\nmisdiagnosis) and persistent-error => timeout.\n\nCloses #59\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(polling): retry a transient output fetch instead of reporting out…",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-09T01:41:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f284e0745f7ffffae60c1a1e51027ac6d7c9a360",
"body": "…--components--create-op-node\n\nchore(main): release 0.11.2",
"is_bot": false,
"headline": "Merge pull request #77 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T22:50:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "da577b2e83441cea4a629f4d26eae8463e36891f",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.11.2",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T22:38:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0fe6622b3ba27edec294c98717f3730c005563a",
"body": "fix(init): query the real default branch when adopting an existing repo",
"is_bot": false,
"headline": "Merge pull request #76 from OpusPopuli/fix/init-default-branch-41",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T22:38:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "166598434c9e7c5a17ebe1d5ed494ee00e7a2666",
"body": "Issue #41: when `init` re-uses a pre-existing region repo (HTTP 422 →\nadopt), it synthesized `defaultBranch: 'main'`. A repo initialized with a\ndifferent default (master, org default) would then have its prod.tfvars\nbranch cut from — and PR based on — a branch that doesn't exist.\n\n- github.ts: add g\n[…]\nm now.\n\nTests: getRepoDefaultBranch (branch from repos.get + owner/repo split, null\non API error / missing field / malformed slug).\n\nCloses #41\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(init): query the real default branch when adopting an existing repo",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T22:27:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8c55037122598dca78d78c5848f19c5adc4e3055",
"body": "…--components--create-op-node\n\nchore(main): release 0.11.1",
"is_bot": false,
"headline": "Merge pull request #75 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T20:58:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82ee9f549819c75845aa738fc7445fe5eccff852",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.11.1",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T20:46:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a2ad94f7221b47a372c590b819d1aab39f7f08f7",
"body": "fix: cleanup nits — cat quoting, teardown ok flag, default-subcommand routing",
"is_bot": false,
"headline": "Merge pull request #74 from OpusPopuli/fix/cleanup-nits-36",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T20:45:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a354c05cfb1bc584bb6657d9948bff95818cd532",
"body": "… routing\n\nBatch of small correctness fixes from the #36 code-review (item 3,\nSAFE_URL_RE escape, was already fixed in the ESLint migration):\n\n- launchagent.ts (item 1): quote the key-file path inside `cat` —\n `\"$(cat \"${keyFilePath}\")\"`. A space-containing keyFilePath (allowed by\n SAFE_PATH_RE) p\n[…]\n test that encoded the old behavior), new\ncli-args.test.ts (no-args / flags-first / known-subcommand / global-flags /\nno-mutation).\n\nCloses #36\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: cleanup nits — cat quoting, teardown ok flag, default-subcommand…",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T20:16:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "846429522bddccca775616239e11b3a064b892f2",
"body": "…--components--create-op-node\n\nchore(main): release 0.11.0",
"is_bot": false,
"headline": "Merge pull request #73 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T16:26:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78af452ea77d7d239bb14fcd2b0693d0ea2b1dfe",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.11.0",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T16:07:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f61c0d7abeb97a580ca1c0f56a8309e7a5455501",
"body": "…es-34\n\nfeat(bootstrap): fail-closed cosign signature gate before pull",
"is_bot": false,
"headline": "Merge pull request #72 from OpusPopuli/feat/bootstrap-verify-signatur…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T16:07:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bab24b9e79b75adfda60237a852a826ceb02469",
"body": "Issue #34 (point 1): bootstrap pulled + ran images with no signature\ncheck — cosign was only invoked by the separate, optional, fail-open\n`verify`. Gate the pull path fail-closed instead.\n\n- homebrew.ts: add `cosign` to STUDIO_PACKAGES so Phase 2 installs it.\n- docker.ts: composeConfigImages (`docke\n[…]\noseConfigImages (args + parse + null on non-zero/ENOENT),\nfilterVerifiableImages (keep/drop/override/empty), cosign in the brew list.\n\nRefs #34\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(bootstrap): fail-closed cosign signature gate before pull",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T15:44:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd0e600ebc43ce6fe70ba920d7c6e0b16995c63a",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.17",
"is_bot": false,
"headline": "Merge pull request #71 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T04:00:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aed7118e60ee72292831e8e44f8ccf008c772c61",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.17",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T03:58:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97eff19fbce17f735c850138b764a020f96919c9",
"body": "fix(cosign): ref-pin the signature identity to release.yml",
"is_bot": false,
"headline": "Merge pull request #70 from OpusPopuli/fix/cosign-identity-pin-34",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T03:58:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "385f93e236ca392d8150861ce72d09a622ab9f91",
"body": "Issue #34 (point 3): DEFAULT_IDENTITY_REGEXP was\n`.../\\.github/workflows/.*$`, which accepts ANY workflow in the opuspopuli\nrepo that ever obtained a Fulcio cert — over-broad. Pin it to the actual\npublishing workflow so verify only trusts images signed by it.\n\n- Pin the workflow FILE: `.../release\\.\n[…]\ncts a different workflow\n(ci.yml), a spoofed owner/repo, and a tag ref.\n\nAdvisory-only for now (verify); no bootstrap behavior change. Refs #34\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cosign): ref-pin the signature identity to release.yml",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T03:52:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "52fa99184f84fd45a58a4e4bf80833ce99c149a9",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.16",
"is_bot": false,
"headline": "Merge pull request #69 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T03:20:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6e36b8e536d959d76b58eaff694b39b8d4d0232e",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.16",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T03:18:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a1d8efe9e348f30b4d3874c6e99945faaef17b1",
"body": "fix(init): seed repo secrets via Octokit + libsodium under the PAT",
"is_bot": false,
"headline": "Merge pull request #68 from OpusPopuli/fix/seed-secrets-via-octokit-32",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T03:18:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec084b945d4c9010b16170eee5d8043402602c07",
"body": "Issue #32: repo-secret seeding shelled out to `gh secret set` (ambient gh\nCLI auth), while every sibling init call used the explicit --gh-token PAT\nvia Octokit. A PAT identity that differed from the gh login seeded to the\nwrong account, and the \"PAT-only, may not have gh\" escape hatch the doc\nclaime\n[…]\necryptable (and plaintext-free), public-key-fetch failure,\nmid-batch PUT failure with correct seeded/pending split, malformed slug.\n\nCloses #32\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(init): seed repo secrets via Octokit + libsodium under the PAT",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T03:16:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "40d0d20b0d98da4211c0019629a2b3396c1d6a20",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.15",
"is_bot": false,
"headline": "Merge pull request #67 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:52:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63cbac754e1e77e1809b540ce7613c9a975eeb17",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.15",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:51:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "291ad49d5175078e3a0889e0d19f802df650c186",
"body": "…ep-35\n\nfix(polling): check workspace before sleeping in the discovery loop",
"is_bot": false,
"headline": "Merge pull request #66 from OpusPopuli/fix/discovery-check-before-sle…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:51:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d0da6456bb96fbf78875c4e19e91a2c3aa2e6c1",
"body": "waitForApply's discovery loop slept a full poll interval before its first\nfindWorkspace call, so a run that already existed was found one interval\nlate, and with pollMs >= discoveryMs the budget could be spent before a\nuseful check. Move the sleep to the end of the loop body (check, then\nsleep): fin\n[…]\n t=0 without\nsleeping) and the pollMs >= discoveryMs edge case. All existing discovery /\ntimeout / resilience tests pass unchanged.\n\nCloses #35\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(polling): check workspace before sleeping in the discovery loop",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T02:49:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "932aa74ab008ffca67217374c09b121035eb0e2f",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.14",
"is_bot": false,
"headline": "Merge pull request #65 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:42:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4fd8b3855e648ec59982188a489fc8f1cbb9ad95",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.14",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:40:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52e8fb1b7a6fa6212d3c7d0d4d89e7e5ac86ff87",
"body": "fix(ollama): add request timeouts to health + warm probes",
"is_bot": false,
"headline": "Merge pull request #64 from OpusPopuli/fix/network-timeouts-ollama-31",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:40:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8d1ff58e5fa2ab7f91ce2310416b340f9b597aac",
"body": "Final slice of #31 (Ollama). Both checkOllamaHealth and warmModel already\nhad try/catch (Ollama never crashed), but their fetch calls had no\ntimeout, so a hung daemon (accepts the connection, never responds) would\nstall bootstrap forever.\n\n- checkOllamaHealth: AbortController + 5s timeout — a metada\n[…]\nboth timeouts via fake timers + an abort-aware fetch stub, plus a\nnon-timeout warm failure case so both catch branches are covered.\n\nCloses #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ollama): add request timeouts to health + warm probes",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T02:39:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a0094db32a45ba9dd2cae7d03383beaa06c46851",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.13",
"is_bot": false,
"headline": "Merge pull request #63 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:30:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba48de76b3fa61f91be292fbb9d7be5c7c90b9d3",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.13",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:29:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4aa09632481f61a77572205eed2fecdd20fa210",
"body": "…e-31\n\nfix(cloudflare): add request timeout + degrade network failures gracefully",
"is_bot": false,
"headline": "Merge pull request #62 from OpusPopuli/fix/network-timeouts-cloudflar…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T02:29:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3075c6a67a6ac485819af31d6eb00ee250a7e17a",
"body": "…fully\n\nSecond slice of #31 (Cloudflare), mirroring the TFC fix. The Cloudflare\n`get` helper had no timeout and only wrapped `.json()` in try/catch, so a\nstalled connection could hang `init` (probeCloudflareToken makes 6\nsequential calls) and a transient fetch throw could reject out of the\nwizard.\n\n\n[…]\net to a\nnetwork-error message) + added probeCloudflareToken network-error and\ntimeout-abort (fake timers) cases.\n\nOllama is Subtask 3. Refs #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cloudflare): add request timeout + degrade network failures grace…",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T02:26:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7c3840742961a87a4281a93c87bb6bc311c9bd37",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.12",
"is_bot": false,
"headline": "Merge pull request #61 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T01:19:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "123314fa53c96fb08261d9c388da48ef11f0c6c3",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.12",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T00:53:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7159518eaf98aea1f67b460ff7a472a4ac9f40c2",
"body": "fix(tfc): add request timeouts + degrade network failures gracefully",
"is_bot": false,
"headline": "Merge pull request #60 from OpusPopuli/fix/network-timeouts-31",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T00:53:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b9a0aa0cfa043ddc5fece473412905e090cc4634",
"body": "First slice of #31 (TFC). Native `fetch` has no default timeout and the\nTFC helpers had no try/catch around the fetch itself, so a stalled\nconnection could hang `init` indefinitely and a transient network throw\ncould reject out of the ~10-minute apply-wait and crash the wizard.\n\n- constants.ts: add \n[…]\n tracks the pre-existing output-missing misdiagnosis on a\ntransient final-output-fetch failure. Cloudflare + Ollama are Subtasks 2/3.\n\nRefs #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tfc): add request timeouts + degrade network failures gracefully",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-08T00:51:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8ee67ee7914d75d74f118f4dc770377fac74026b",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.11",
"is_bot": false,
"headline": "Merge pull request #58 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T00:03:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "419a478f2e474223b8a3471d4d898738e3fa8a4c",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.11",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T00:01:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5d5913cdbd76c05779b9ef916745c44a73871186",
"body": "fix(bootstrap): align llm-model docs + picker hints with actual defaults",
"is_bot": false,
"headline": "Merge pull request #57 from OpusPopuli/fix/llm-default-consistency-33",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-08T00:01:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1a24998464064eb0a1bf96483c9446fd1b4077c",
"body": "Issue #33 asked to verify the default Ollama tag `qwen3.5:9b`. It is valid\nand pullable (confirmed against the Ollama registry manifest + the official\nQwen3.5 release announcement) — Qwen3.5 shipped after the reviewer's\nknowledge cutoff, and their review environment had the registry blocked,\nwhich i\n[…]\n36–48 GB\" hint (48 GB actually pre-selects\n 32b) to \"< 48 GB\".\n\nNo behavior change; bootstrap.test.ts doesn't assert on hint text.\n\nCloses #33\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(bootstrap): align llm-model docs + picker hints with actual defaults",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-07T23:28:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9f6bf9282926335cb98c6379daae33dad19a3640",
"body": "ci(lint): enforce the sonar pass in CI and prepublishOnly",
"is_bot": false,
"headline": "Merge pull request #56 from OpusPopuli/ci/enforce-sonar-gate-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-07T04:00:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb02cec37dd0964cad2102d0935cbb54d71e5fd4",
"body": "Final step of the #37 burndown. All cognitive-complexity findings are\ncleared (58 -> 0), so the second ESLint pass is now turned on as a\nblocking gate:\n\n- ci.yml: add a `Lint (sonar)` step after `Lint (eslint)`\n- package.json: restore `pnpm lint:sonar` to the prepublishOnly chain\n- eslint.sonar.conf\n[…]\nI\" deferral note\n\nThe two-pass ESLint setup (base + sonarjs cognitive-complexity <= 15) now\nmirrors @opuspopuli/regions end to end.\n\nCloses #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(lint): enforce the sonar pass in CI and prepublishOnly",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-07T03:58:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "23f978ec07257a1b55682d42d6e50a707e424849",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.10",
"is_bot": false,
"headline": "Merge pull request #55 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-07T03:55:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aabf289e0b6251b091d02c1a03d33a20428a5db7",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.10",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-07T03:55:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b8b5337d8269729cfb173d18c9bd8c12f9596f0",
"body": "refactor(lib): extract helpers to clear remaining complexity findings",
"is_bot": false,
"headline": "Merge pull request #54 from OpusPopuli/refactor/sonar-lib-cc-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-07T03:54:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b5e61671dd4779afe6733f920b7aefb3a3c14a06",
"body": "Eighth slice of the #37 burndown — clears the last 7 cognitive-complexity\nfindings across the lib + region command. No behavior change.\n\n- lib/region.ts validateRegionConfig (22): split into 4 sub-validators;\n issue-message order preserved via spread\n- lib/docker.ts waitForHealthy (16) + assessHeal\n[…]\ns, guarding the extractions.\n\nWith this, `pnpm lint:sonar` is green (0 findings) — the CI gate flip is\nthe only remaining step (#37).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(lib): extract helpers to clear remaining complexity findings",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-07T03:53:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "71f818f11dbc8566d2582b4bb6e20d32dc62c9e7",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.9",
"is_bot": false,
"headline": "Merge pull request #53 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-07T00:00:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a7547e55666d8817803b867ea34926d0481a59a",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.9",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T22:52:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "202b7f926de09f76c6725e36dd55461504328670",
"body": "refactor(verify): extract phase helpers to cut handler complexity",
"is_bot": false,
"headline": "Merge pull request #52 from OpusPopuli/refactor/sonar-verify-cc-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T22:52:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea4db7d1b5c825f2321729e16622af430076e67a",
"body": "Seventh slice of the #37 burndown — verify had two cognitive-complexity\nfindings: runVerify (28) and the `.action` handler (28). Extract each into\n<=15-CC helpers. No behavior change.\n\nrunVerify -> verifyTlsPhase / verifyHealthPhase / verifyGraphqlPhase /\nverifyCloudflarePhase / verifyCosignPhase. E\n[…]\nhe 17\nrunVerify cases; the action helpers all mix resolution with\np.cancel/process.exit, so there is no fully-pure seam to unit-test.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(verify): extract phase helpers to cut handler complexity",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-06T20:01:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bb08a88b0d70a998e38476abf900d9d73ee19d17",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.8",
"is_bot": false,
"headline": "Merge pull request #51 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T15:39:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b14f4f60e3f824adc27519f0401504c4667dd96",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.8",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T15:35:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dadb350bd5bc4cdbd6f03840e07ab58b58331015",
"body": "refactor(reset): extract phase helpers to cut handler complexity",
"is_bot": false,
"headline": "Merge pull request #50 from OpusPopuli/refactor/sonar-reset-cc-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T15:35:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42804295f4bdd0b9c3e509ad759b3afcbf5628d8",
"body": "Sixth slice of the #37 burndown — reset had two cognitive-complexity\nfindings: runReset (36) and the `.action` handler (50). Extract each into\n<=15-CC helpers. No behavior change.\n\nrunReset -> resetStopStackPhase / resetLaunchAgentPhase /\nresetDockerLogoutPhase, each returning a ResetPhase; runReset\n[…]\n default) — mirrors the buildComposeEnv\nprecedent. Full suite 388 green, incl. the 21 existing runReset cases\n(onPhase order intact).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(reset): extract phase helpers to cut handler complexity",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-06T14:55:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f61ce1912e082908843633d5c73fe9c2c38f2bca",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.7",
"is_bot": false,
"headline": "Merge pull request #49 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T00:24:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0d1c11fa1475db080d411de1d9575dd03047242",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.7",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T00:23:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc86886ee7e3df0ee67aacf6287e784a1daba1b9",
"body": "refactor(init): extract phase helpers to cut handler complexity",
"is_bot": false,
"headline": "Merge pull request #48 from OpusPopuli/refactor/sonar-init-cc-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-06T00:23:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20b3dba367df1fad265e182dba8417d5b8cee619",
"body": "Fifth slice of the #37 burndown — the init `.action` handler was\ncognitive-complexity 71. Extract each phase into its own <=15-CC helper so\nthe handler becomes a ~45-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim, restructured \n[…]\n interactive I/O; the existing\nsuite already covers the pure seams (summarizePhases,\nlistIgnoredLocalOnlyFlags), which are untouched.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(init): extract phase helpers to cut handler complexity",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-06T00:16:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0d85c1fc0e2e5770a4380dbdefb6b6ae4a4e468b",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.6",
"is_bot": false,
"headline": "Merge pull request #47 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:52:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64738945053ff60d69af19680a56d03bcc15698e",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.6",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:51:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d5799dfba567ffa36536f111921e083835407845",
"body": "refactor(bootstrap): extract phase helpers to cut handler complexity",
"is_bot": false,
"headline": "Merge pull request #46 from OpusPopuli/refactor/sonar-bootstrap-cc-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:51:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "407caf434a7778ccefa9bb75d625d6f289579274",
"body": "Fourth slice of the #37 burndown — the bootstrap `.action` handler was\ncognitive-complexity 85. Extract each phase into its own <=15-CC helper so\nthe handler becomes a ~17-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim; a Colle\n[…]\nET fallback). The\ninteractive orchestration has no unit tests (it never did) — verified via\ntypecheck, build, and `bootstrap --help`.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(bootstrap): extract phase helpers to cut handler complexity",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-05T23:48:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3aba80827900f83899d9a7eb918704164cc6f626",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.5",
"is_bot": false,
"headline": "Merge pull request #45 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:18:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4abdd65a1921f674836a17ba8ee11a0496070957",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.5",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:18:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9b5789ca38ad9bb28afd0ac4e0e13d3944326557",
"body": "fix(lint): rewrite super-linear regexes in src",
"is_bot": false,
"headline": "Merge pull request #44 from OpusPopuli/fix/sonar-regex-backtracking-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:17:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "54ab5be40c42cfadd58e07c2824f9737bc81d6c0",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' into fix/sonar-regex-backtracking-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:17:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff66176ac4b5e8252380d3afd97c808bb3e7172c",
"body": "…--components--create-op-node\n\nchore(main): release 0.10.4",
"is_bot": false,
"headline": "Merge pull request #43 from OpusPopuli/release-please--branches--main…",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:16:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84e957343b8afc0a374604a008f6387b4a2e1a14",
"body": "Third slice of the #37 burndown — clears the 4 super-linear-regex\nfindings in `src/`, leaving only the 13 cognitive-complexity refactors.\nEach rewrite is backtracking-free and behavior-preserving for real\ninputs, with characterization tests locking the equivalence.\n\n- bootstrap.ts estimatedPullTime:\n[…]\n05b\nsizes) and the slugify edge trim; the existing generatePostgresPassword\n\"no + / =\" assertion already covers the base64url change.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(lint): rewrite super-linear regexes in src",
"author_name": "Rodney Gagnon",
"author_login": null,
"committed_at": "2026-07-05T23:15:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4e0e0fada6cd3fb476d74c40477b47e7cd54ea7b",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.10.4",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:04:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "68e892131c6260d7626292ed1f1cdefb45573047",
"body": "refactor(lint): clear cheap sonar findings in src",
"is_bot": false,
"headline": "Merge pull request #42 from OpusPopuli/refactor/sonar-cheap-src-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:03:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "845f7fee4ecf763fdbbb5c561245dd788c009932",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' into refactor/sonar-cheap-src-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:03:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e9cd70224a103a688a2f0e9e4c44232de2b4c926",
"body": "test(lint): clear sonar findings in the test suite",
"is_bot": false,
"headline": "Merge pull request #40 from OpusPopuli/test/sonar-test-findings-37",
"author_name": "Rodney Gagnon",
"author_login": "rodneygagnon",
"committed_at": "2026-07-05T23:03:02Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 35,
"commits_last_year": 187,
"latest_release_at": "2026-07-19T16:13:33Z",
"latest_release_tag": "v0.16.0",
"releases_from_tags": false,
"days_since_last_push": 5,
"active_weeks_last_year": 5,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "create-op-node",
"exists": true,
"license": "AGPL-3.0-or-later",
"keywords": [
"opuspopuli",
"civic-tech",
"federation",
"cli",
"bootstrap",
"mac-studio",
"cloudflare-tunnel"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/create-op-node",
"is_deprecated": false,
"latest_version": "0.16.0",
"repository_url": "https://github.com/OpusPopuli/create-op-node",
"versions_count": 44,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 5028,
"first_published_at": "2026-06-18T01:59:12.555000Z",
"latest_published_at": "2026-07-19T16:14:23.712000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 1,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-07-11",
"count": 1
}
],
"complete": true,
"collected": 1,
"total_forks": 1
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 78214,
"source_files_sampled": 58,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 88,
"malicious_count": 0,
"assessed_package": "npm:create-op-node@0.16.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@cfworker/json-schema",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.1.1"
},
{
"name": "@clack/prompts",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.9.0"
},
{
"name": "@octokit/rest",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^22.0.0"
},
{
"name": "cloudflare",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.0"
},
{
"name": "commander",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.0"
},
{
"name": "execa",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^9.5.2"
},
{
"name": "libsodium-wrappers",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.8.4"
},
{
"name": "picocolors",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "zod",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.24.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 90,
"open_issues": 1,
"closed_ratio": 0.955,
"closed_issues": 21,
"closed_unmerged_prs": 2
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "rodneygagnon",
"commits": 120,
"avatar_url": "https://avatars.githubusercontent.com/u/43381472?v=4"
},
{
"type": "User",
"login": "claude",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.984
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"publish.yml",
"release-please.yml"
],
"has_docs_dir": false,
"linter_configs": [
"eslint.config.mjs"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/25 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 7,
"reason": "dependency not pinned by hash detected -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 5,
"reason": "5 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "0edf6c903b9ada6a3973490465ce0de02856fc09",
"ran_at": "2026-07-25T14:28:41Z",
"aggregate_score": 3.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-19T16:14:28Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-19T16:13:23Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 114,
"created_at": "2026-07-19T16:26:12Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/OpusPopuli/create-op-node",
"host": "github.com",
"name": "create-op-node",
"owner": "OpusPopuli"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"security": 51,
"vitality": 75,
"community": 33,
"governance": 54,
"engineering": 70
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 75,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"commits_last_year": 187,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 5
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "5/52 weeks with commits",
"points": 3.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 5
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "187 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 187
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 35,
"latest_release_tag": "v0.16.0",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "35 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 35
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 33,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 1,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "1 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 1
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (AGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "AGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"packages": [
"create-op-node"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 5028
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "5,028 downloads/month across npm",
"points": 49.4,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 5028,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 12,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.984
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 98% of commits",
"points": 0.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 98
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"merged_prs": 90,
"open_issues": 1,
"closed_issues": 21,
"issue_closed_ratio": 0.955,
"closed_unmerged_prs": 2
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "96% of issues closed",
"points": 44.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 96
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "90/92 decided PRs merged",
"points": 37.4,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 90,
"decided": 92
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 38,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "OpusPopuli",
"public_repos": 7,
"account_age_days": 216
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of OpusPopuli",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "OpusPopuli"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "7 public repos, account ~0 yr old",
"points": 7.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 7
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"create-op-node"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "44 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 44
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 70,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.mjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 51,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 39,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 3.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "5 existing vulnerabilities detected",
"points": 3.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-op-node@0.16.0 runtime dependency closure — what installing the published package pulls in — 88 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:create-op-node@0.16.0",
"assessed": 88
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 88,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 88,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 65,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.98,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 98,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0.29,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.mjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "29 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 29,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 7,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 78214,
"source_files_sampled": 58,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/58 source files over 60KB",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 58,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T14:28:58.849025Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpusPopuli/create-op-node.svg",
"full_name": "OpusPopuli/create-op-node",
"license_state": "standard",
"license_spdx": "AGPL-3.0"
}