公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 15:52 UTC

Ramenm / MCPace

Rust · JavaScript自定义许可证★ 0 星标⑂ 0 复刻始于 2026年4月在 GitHub 上查看 ↗

Ramenm/MCPace 的健康指数为 100 分中的 54 分,处于「中等」区间。 其得分最高的类别是Vitality(81/100),最低的是Community & Adoption(24/100)。 最近一次更新在 3 天前。 近期的大部分工作由 1 位贡献者完成。

54
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

54
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Ramenm个人账户
0 关注者4 个公开仓库始于 2018年10月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

81良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 3 天前
11.8/36提交节奏 — 52 周中有 17 周有提交
18/18提交量 — 最近一年 116 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year116
human_commit_share1
days_since_last_push3
active_weeks_last_year17

发布纪律

88优秀
评分方式
16.2/27有发布版本 — 4 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 8 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count4
latest_release_tagv0.8.2
releases_from_tags
days_since_latest_release5
mean_days_between_releases8
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

24危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

51中等
评分方式
22.5/22.5README
16.9/22.5许可证 — 存在许可证文件,但不是可识别的许可证
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

27危急 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
20.9/38.3PR 接受 — 已裁定的 PR 中 6/11 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/19 approved changesets -- score normalized to 0
所用输入
merged_prs6
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs5
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
0/25所有者影响力 — Ramenm 有 0 位关注者
17.1/25既往记录 — 4 个公开仓库,账户约 7 年
所用输入
followers0
owner_typeUser
is_verified
owner_loginRamenm
public_repos4
account_age_days2,848
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。

工程质量

基础的工程与文档实践是否到位?

66中等 · 占总体的 20%

工程实践

74良好
评分方式
24/24CI 工作流 — 9 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
6.4/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

55中等
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

75良好 · 占总体的 16%

安全态势

69中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/19 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.9
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages146
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 146 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

64中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 84 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.84
agent_instruction_files
agent_instruction_max_bytes
评分方式
12.6/18一条命令的引导启动 — Cargo.toml(工具链约定,无任务运行器)
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Rust(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilesCargo.lock, package-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsCargo.toml
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Rust(静态类型)
53.3/55可控的文件大小 — 采样的 353 个源文件中有 11 个超过 60KB
所用输入
primary_languageRust
largest_source_bytes429,592
source_files_sampled353
oversized_source_files11
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
1贡献者
116最近 12 个月提交数
3距最近推送天数
4发布版本数
1巴士系数(bus factor)
0开放议题
crates.io, npm软件包生态系统数

数据采集警告

  • Could not fetch crates package 'mcpace' from its registry

更多细节

OpenSSF Scorecard 6.9 / 10
6.9综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 15:52 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/19 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
4Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
直接依赖 7
注册表软件包版本约束清单文件
crates.ioauto-launch0.6Cargo.toml
crates.iogetrandom0.3Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.iowhich8Cargo.toml
crates.ioclap4Cargo.toml
crates.ioureq3.3.0Cargo.toml
全部依赖 146

来自 GitHub 依赖图的完整解析依赖集合:8 个直接依赖与 138 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
crates.ioauto-launch0.6.0直接
crates.ioclap4.6.1直接
crates.iogetrandom0.2.17直接
crates.iogetrandom0.3.4直接
crates.ioserde1.0.228直接
crates.ioserde_json1.0.150直接
crates.ioureq3.3.0直接
crates.iowhich8.0.4直接
crates.ioandroid_system_properties0.1.5间接
crates.ioanstream1.0.0间接
crates.ioanstyle1.0.14间接
crates.ioanstyle-parse1.0.0间接
crates.ioanstyle-query1.1.5间接
crates.ioanstyle-wincon3.0.11间接
crates.iobase640.22.1间接
crates.iobitflags2.13.0间接
crates.ioblock20.6.2间接
crates.iobytes1.12.1间接
crates.iocc1.2.66间接
crates.iocesu81.1.0间接
crates.iocfg-if1.0.4间接
crates.iocfg_aliases0.2.1间接
crates.ioclap_builder4.6.0间接
crates.ioclap_derive4.6.1间接
crates.ioclap_lex1.1.0间接
crates.iocolorchoice1.0.5间接
crates.iocombine4.6.7间接
crates.iocore-foundation0.10.1间接
crates.iocore-foundation-sys0.8.7间接
crates.iodirs6.0.0间接
crates.iodirs-sys0.5.0间接
crates.iodispatch20.3.1间接
crates.iofind-msvc-tools0.1.9间接
crates.ioheck0.5.0间接
crates.iohttp1.4.2间接
crates.iohttparse1.10.1间接
crates.iois_terminal_polyfill1.70.2间接
crates.ioitoa1.0.18间接
crates.iojni0.21.1间接
crates.iojni-sys0.3.1间接
crates.iojni-sys0.4.1间接
crates.iojni-sys-macros0.4.1间接
crates.iolibc0.2.186间接
crates.iolibredox0.1.18间接
crates.iolog0.4.33间接
crates.iomemchr2.8.2间接
crates.ionix0.31.3间接
crates.ioobjc20.6.4间接
crates.ioobjc2-cloud-kit0.3.2间接
crates.ioobjc2-core-data0.3.2间接
crates.ioobjc2-core-foundation0.3.2间接
crates.ioobjc2-core-graphics0.3.2间接
crates.ioobjc2-core-image0.3.2间接
crates.ioobjc2-core-location0.3.2间接
crates.ioobjc2-core-text0.3.2间接
crates.ioobjc2-encode4.1.0间接
crates.ioobjc2-foundation0.3.2间接
crates.ioobjc2-io-surface0.3.2间接
crates.ioobjc2-quartz-core0.3.2间接
crates.ioobjc2-security0.3.2间接
crates.ioobjc2-service-management0.3.2间接
crates.ioobjc2-ui-kit0.3.2间接
crates.ioobjc2-user-notifications0.3.2间接
crates.ioonce_cell1.21.4间接
crates.ioonce_cell_polyfill1.70.2间接
crates.ioopenssl-probe0.2.1间接
crates.iooption-ext0.2.0间接
crates.ioos_info3.15.0间接
crates.iopercent-encoding2.3.2间接
crates.ioproc-macro21.0.106间接
crates.ioquote1.0.46间接
crates.ior-efi5.3.0间接
crates.ioredox_users0.5.2间接
crates.ioring0.17.14间接
crates.iorustls0.23.41间接
crates.iorustls-native-certs0.8.4间接
crates.iorustls-pki-types1.15.0间接
crates.iorustls-platform-verifier0.6.2间接
crates.iorustls-platform-verifier-android0.1.1间接
crates.iorustls-webpki0.103.13间接
crates.iosame-file1.0.6间接
crates.ioschannel0.1.29间接
crates.iosecurity-framework3.7.0间接
crates.iosecurity-framework-sys2.17.0间接
crates.ioserde_core1.0.228间接
crates.ioserde_derive1.0.228间接
crates.ioshlex2.0.1间接
crates.iosmappservice-rs0.1.3间接
crates.iostrsim0.11.1间接
crates.iosubtle2.6.1间接
crates.iosyn2.0.118间接
crates.iothiserror1.0.69间接
crates.iothiserror2.0.18间接
crates.iothiserror-impl1.0.69间接
crates.iothiserror-impl2.0.18间接
crates.iounicode-ident1.0.24间接
crates.iountrusted0.9.0间接
crates.ioureq-proto0.6.0间接
crates.ioutf8-zero0.8.1间接
crates.ioutf8parse0.2.2间接
crates.iowalkdir2.5.0间接
crates.iowasi0.11.1+wasi-snapshot-preview1间接
crates.iowasip21.0.4+wasi-0.2.12间接
crates.iowebpki-root-certs1.0.8间接
crates.iowebpki-roots1.0.8间接
crates.iowinapi-util0.1.11间接
crates.iowindows-link0.2.1间接
crates.iowindows-registry0.6.1间接
crates.iowindows-result0.4.1间接
crates.iowindows-strings0.5.1间接
crates.iowindows-sys0.45.0间接
crates.iowindows-sys0.52.0间接
crates.iowindows-sys0.61.2间接
crates.iowindows-targets0.42.2间接
crates.iowindows-targets0.52.6间接
crates.iowindows_aarch64_gnullvm0.42.2间接
crates.iowindows_aarch64_gnullvm0.52.6间接
crates.iowindows_aarch64_msvc0.42.2间接
crates.iowindows_aarch64_msvc0.52.6间接
crates.iowindows_i686_gnu0.42.2间接
crates.iowindows_i686_gnu0.52.6间接
crates.iowindows_i686_gnullvm0.52.6间接
crates.iowindows_i686_msvc0.42.2间接
crates.iowindows_i686_msvc0.52.6间接
crates.iowindows_x86_64_gnu0.42.2间接
crates.iowindows_x86_64_gnu0.52.6间接
crates.iowindows_x86_64_gnullvm0.42.2间接
crates.iowindows_x86_64_gnullvm0.52.6间接
crates.iowindows_x86_64_msvc0.42.2间接
crates.iowindows_x86_64_msvc0.52.6间接
crates.iowit-bindgen0.57.1间接
crates.iozeroize1.9.0间接
crates.iozmij1.0.21间接
npm@mcpace/cli0.8.2间接
npm@mcpace/cli-darwin-arm640.8.2间接
npm@mcpace/cli-darwin-x640.8.2间接
npm@mcpace/cli-linux-arm64-gnu0.8.2间接
npm@mcpace/cli-linux-x64-gnu0.8.2间接
npm@mcpace/cli-win32-arm64-msvc0.8.2间接
npm@mcpace/cli-win32-x64-msvc0.8.2间接
npm@publint/pack0.1.4间接
npmmri1.2.0间接
npmpackage-manager-detector1.6.0间接
npmpicocolors1.1.1间接
npmpublint0.3.21间接
npmsade1.8.1间接
依赖安全公告 0

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 146 个包,其中也包含从不交付的开发与测试版本固定:0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 6673,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "CSS": 377163,
        "HTML": 48520,
        "Rust": 2787894,
        "Shell": 2180,
        "Python": 40870,
        "JavaScript": 1798662
      },
      "pushed_at": "2026-07-21T16:05:49Z",
      "created_at": "2026-04-12T06:33:57Z",
      "owner_type": "User",
      "updated_at": "2026-07-19T17:00:22Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "Ramenm",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/43914741?v=4",
      "created_at": "2018-10-06T18:22:27Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 2848
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-07-19T17:00:05Z"
        },
        {
          "tag": "v0.7.7",
          "kind": "patch",
          "published_at": "2026-06-25T18:44:19Z"
        },
        {
          "tag": "v0.7.6",
          "kind": "patch",
          "published_at": "2026-06-25T18:25:28Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-06-25T17:55:52Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f7dafcc2909deb8398e3365df948c9800abd17a4",
          "body": "Release MCPace 0.8.2",
          "is_bot": false,
          "headline": "Merge pull request #15 from Ramenm/release/0.8.2",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-19T17:00:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bb4069887c66437c48a13daa77d5857f52c7d14",
          "body": null,
          "is_bot": false,
          "headline": "Fix release URL assertion",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T10:28:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e34b0766fc0e6d4aa2e933bdb051d55d9c46628",
          "body": null,
          "is_bot": false,
          "headline": "Fix non-Windows HTTP probe lint",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T10:01:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43b3afb9723e8047f0d261db793d548f05d564c1",
          "body": null,
          "is_bot": false,
          "headline": "Fix native installer placement and TCP test flakes",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T09:47:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "824a054daea9e081655d56e8a13469a9fb9d1d6d",
          "body": null,
          "is_bot": false,
          "headline": "Fix Windows release verification",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T06:32:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06364acd818ff7e73b975f2e3b4ab2871aa4b983",
          "body": null,
          "is_bot": false,
          "headline": "Fix cross-platform release artifact proofs",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T06:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a74b9228e32eb4b8405ea934788e0d87a519bc7",
          "body": null,
          "is_bot": false,
          "headline": "Retry transient Windows lease lock contention",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T04:43:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d127c8cf9969334bd2baf1c0f6bb70add2d815d",
          "body": null,
          "is_bot": false,
          "headline": "Harden Windows timeout proof diagnostics",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T04:00:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c28e390571a35c645eb30886616c37a026398dcb",
          "body": null,
          "is_bot": false,
          "headline": "Fix release platform smoke and Rust timeout flake",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T03:30:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "000c633d5ade629500a0a7714b3bbda44a63a7a9",
          "body": null,
          "is_bot": false,
          "headline": "Make assurance proof validation checkout independent",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T02:23:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6032a0abae0e2f730c2fc4880c33667e5d625478",
          "body": null,
          "is_bot": false,
          "headline": "Fix cross-platform release CI proofs",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-18T01:02:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4b98043384ae98721669f54369400c95d4e1a8a",
          "body": "Simplify the public command surface while preserving generated compatibility entrypoints, add ownership-safe status/uninstall and supervisor recovery proofs, and harden installer, report freshness, source archive, and publication gates.\\n\\nVerified locally with npm test/check, Rust fmt/clippy/302+4 \n[…]\nllel Rust runs, installed-binary/native-npm smoke, live MCP and source-bound release proofs, Gitleaks, Trivy, and npm audit. Unsigned OS installers remain draft-only; npm is the supported public lane.",
          "is_bot": false,
          "headline": "Release MCPace 0.8.2 CLI and lifecycle hardening",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-17T23:52:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "577f01ffd4075ea0f837eccc0953b103de16ec88",
          "body": null,
          "is_bot": false,
          "headline": "Fix direct Linux stop without user bus",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-17T12:07:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba69ad89b937d04c7548c8ed8a960e567d76a046",
          "body": null,
          "is_bot": false,
          "headline": "Harden supervised runtime lifecycle ownership",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-17T09:58:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d344f472bdad8dab0781bd99ac58a0cb70a38919",
          "body": null,
          "is_bot": false,
          "headline": "fix: avoid Darwin probe timeout errors",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T20:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f8a15d8a0430145101b541ba2e406fb5c4bb6bf",
          "body": null,
          "is_bot": false,
          "headline": "fix: preserve serve startup failure details",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T19:34:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5cc0edb460627fd5e4b7d450483ddd1c89920ab",
          "body": null,
          "is_bot": false,
          "headline": "fix: start packaged runtime on macOS",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T18:08:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5311669dd22b1535cc38958fbde4c66e66a9b585",
          "body": null,
          "is_bot": false,
          "headline": "fix: unblock native release matrix",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T16:35:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00081b65f598c6b0d6a01e6a6dcdca2fa3424dda",
          "body": null,
          "is_bot": false,
          "headline": "test: make assurance portable to clean CI",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T15:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cc55bcb1c6d81b19411cc64ca2a0605b5d92d20",
          "body": null,
          "is_bot": false,
          "headline": "fix: make user autostart supervision reliable",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-16T15:13:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24458e75641b4eb54ecf3e7e7375f02c23719898",
          "body": null,
          "is_bot": false,
          "headline": "release: prepare MCPace 0.8.0",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-15T07:18:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d164c4eae8864a43a11a3173c10fa20e233d288",
          "body": "The Windows autostart fix reached GitHub at 0.7.8, but npm cannot republish an existing latest version. Bump the workspace, Cargo crate, npm launcher, native optional dependency pins, lockfiles, and project config to 0.7.9 so the main publish workflow can produce a real latest package containing the\n[…]\n autostart verify --json --root .\nTested: MCP initialize POST returned HTTP 200 and serverInfo.version 0.7.9\nNot-tested: npm latest publication before push; requires GitHub trusted publishing workflow",
          "is_bot": false,
          "headline": "Release the autostart repair as a new npm latest version",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-06T05:39:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "845ca44672fe59cec26895c5c2c3deebaee5281c",
          "body": "Windows Run entries could be configured correctly while the current MCP endpoint was still down, and launching the foreground agent path from login could leave a console-hosted process model. The autostart target now uses an agent start path on Windows, which delegates to the existing hidden serve s\n[…]\nTested: MCP initialize POST to http://127.0.0.1:39022/mcp returned HTTP 200\nNot-tested: Actual Windows logoff/login cycle; current-user Run entry was verified in registry and by current-session repair",
          "is_bot": false,
          "headline": "Keep Windows MCPace autostart hidden and live",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-06T05:25:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb79f06baea22aa79786479b4080cf111850bf4c",
          "body": "The release hygiene tests exercised a local cleanzip helper that was excluded from Git, so clean GitHub checkouts failed while the local workspace passed. Track the helper and narrow persistent environment helpers to Windows so Linux clippy sees no dead platform-only code.\n\nConstraint: CI runs from \n[…]\nsts/node/source-archive-hygiene.test.mjs tests/node/source-archive-policy.test.mjs\n\nTested: npm run check:rust\n\nTested: npm run check:ci\n\nNot-tested: GitHub Actions rerun before this commit is pushed.",
          "is_bot": false,
          "headline": "Keep CI release hygiene self-contained",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-05T17:59:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b1034c59ec23a59d32dff8559fe83182adc3ca4",
          "body": "The project had moved to the new direct MCPace Agent login model, but the local\nWindows startup state still had the old wscript/VBS entry and the release gates\nwere catching stale generated/compat artifacts. This hardens autostart install\nand verify around the real login item, removes obsolete compa\n[…]\nrun check:ci\nTested: npm run check:rust\nTested: npm run build\nTested: target/release/mcpace.exe autostart verify --json --root .\nNot-tested: Full OS reboot/login cycle after the Run entry was enabled.",
          "is_bot": false,
          "headline": "Make login startup dependable across release checks",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-05T17:49:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8048339a04902771e782dbb7213a963ebce67eda",
          "body": "After the stable native packages became visible in the npm registry, npm ci started validating omitted optional workspace lockfile entries more strictly. The lockfile stubs now carry the release version while still avoiding hoisted native packages in source installs, and the source-bundle test mirro\n[…]\npm@11.16.0 -- npm ci --ignore-scripts --no-audit --no-fund --omit=optional\n\nTested: npm run check:rust\n\nTested: node --test tests/node/supply-chain-policy.test.mjs tests/node/docs-and-package.test.mjs",
          "is_bot": false,
          "headline": "Keep post-publish source installs valid",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T09:59:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97bcabe490d56e27fe394ff07053997637013a1f",
          "body": "The 0.7.8 source bump made workspace optional native package ranges point at a version that has to be built by the publish workflow before it exists in npm. Source CI should install only locked dev tooling, while the publish job builds and contract-checks native tarballs separately.\n\nConstraint: Nat\n[…]\nTested: npm run check:security-policy\nTested: npm run check:package\nNot-tested: Local check:publish-contract pass without GitHub-built native tarballs; local run correctly blocked on missing tarballs.",
          "is_bot": false,
          "headline": "Keep release installs independent of unpublished native packages",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T09:31:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78f5a1f8bae99b51a85dda5a770d5b8492996901",
          "body": "The dev lane proved the release workflow, trusted publishing, npm install, version reporting, diagnostics, and Windows autostart against the npm binary. Bumping source metadata lets the main branch publish the same code as stable latest automatically instead of skipping the already-published 0.7.7 v\n[…]\nted: npm run check; npm run check:package; npm run pack:npm:dry-run; npm run check:rust; npm view @mcpace/cli@0.7.8 returned E404 before bump.\nNot-tested: main-branch stable publish before merge/push.",
          "is_bot": false,
          "headline": "Prepare a stable 0.7.8 npm release",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T09:18:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffb88bc7da3ed97375590bbaf4bd6c5d2dcb7595",
          "body": "Node 24 warns when a child process uses shell:true together with an argument array. MCPace terminal diagnostics only need fixed npm probes, so Windows now routes them through cmd.exe explicitly without enabling Node's shell option.\n\nConstraint: Windows npm is exposed as npm.cmd, but diagnostics must\n[…]\ne.js --mcpace-npm-diagnostics --json; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust\nNot-tested: Fresh npm registry install of this exact commit before push.",
          "is_bot": false,
          "headline": "Keep npm diagnostics warning-free on current Node",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T09:06:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3917cf3603e2cb65ce7fd96180445cc989e41e7d",
          "body": "Windows autostart can resolve a local MCPace root even when a user invokes the npm-installed binary from elsewhere. Using mcpace.config.json for --version therefore made a freshly published dev binary look stale. The version command now reports the compiled package version while doctor remains the p\n[…]\nrun check:publish-trust; target/release/mcpace.exe --version with MCPACE_ROOT pointing at config version 999.999.999\nNot-tested: CI rebuild/publish of the new dev package before this commit is pushed.",
          "is_bot": false,
          "headline": "Make npm-installed MCPace report its actual binary version",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T08:58:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "610cf36b708efaafdf4846873d3e1d356d2800d6",
          "body": "The npm registry requires package-side trust relationships for every published package, including native optional packages. Add a bulk helper around npm trust github so a maintainer can authenticate once and configure all MCPace packages without repeated UI clicks.\n\nConstraint: npm trust requires np\n[…]\nm run check; npm run check:workflow-policy; npm run check:security-policy\nNot-tested: npm run npm:trust:configure against npm because this session is not logged in to npm and cannot satisfy owner 2FA.",
          "is_bot": false,
          "headline": "Automate npm trusted publisher bootstrap",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T08:41:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70f1d8dde567ede720eb019773c7d01eaf55c0c9",
          "body": "OpenSSF Scorecard only supports the default branch outside pull requests, so manual proof runs from dev must not turn that third-party limitation into a repository failure. CodeQL still runs on dev dispatches while Scorecard remains active for pull requests and the default branch.\n\nConstraint: ossf/\n[…]\ncheck:security-policy; npm run check:publish-trust; node scripts/run-node-tests.mjs --quiet tests/node/project-hygiene.test.mjs\nNot-tested: GitHub security workflow rerun after this commit before push",
          "is_bot": false,
          "headline": "Keep dev security dispatch from false failing",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T07:41:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f5d4767ab462c4727a285833b9c5feee0510834",
          "body": "The publish workflow previously exported NODE_AUTH_TOKEN from a missing repository secret, which left an empty token in the publish environment. npm then attempted token auth and failed before OIDC trusted publishing could authenticate the GitHub-hosted workflow. Remove the token fallback and tighte\n[…]\neck:publish-trust; npm run check:workflow-policy; npm run check:security-policy; node scripts/run-node-tests.mjs --quiet; npm run check:ci\n\nNot-tested: Real npm OIDC publish after this workflow change",
          "is_bot": false,
          "headline": "Let npm trusted publishing own release authentication",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T07:24:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97837d2d9b2dcfbae2f509a0dfe0ea5e13cb51c3",
          "body": "The npm publish workflow now runs full Rust checks inside the Ubuntu glibc baseline image before native tarballs are published. That image previously lacked node, so dashboard upstream tests failed for an environmental reason rather than a product regression. Install the distro nodejs package in tha\n[…]\nn check:rust; MCPACE_GLIBC_BASELINE_CHECKS=full bash scripts/build-linux-glibc-baseline.sh for x86_64-unknown-linux-gnu\n\nNot-tested: GitHub-hosted linux-arm64 baseline rerun before pushing this commit",
          "is_bot": false,
          "headline": "Keep Linux release baseline tests faithful",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T07:14:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdf9375991b154c8034c90eafed86ff205cdd593",
          "body": "The published npm package did not update after main merged because publish-npm only supported manual dry-runs and tag-shaped gates, while the 0.7.7 registry package predated the Windows autostart fix. Add an explicit publish planner so dev branch pushes produce unique prerelease versions on the dev \n[…]\nll run blocks.\nTested: npm run check:ci; npm run check:rust; npm run build; npm run platform:binary-smoke\nNot-tested: Live npm publish from GitHub Actions will be verified after merging this workflow.",
          "is_bot": false,
          "headline": "Automate npm release channels without stale package reuse",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T07:03:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72c0425829aa69217b5a5d2977cd2d224c7d04e9",
          "body": "Windows Startup folder shortcuts show up as command scripts, which made MCPace look like an accidental .cmd autostart entry. Store the launch command in the per-user Run registry key instead and clean up the legacy Startup-folder file on enable/disable.\n\nConstraint: Windows users should see a named \n[…]\nat/auto-launch/Cargo.toml\n\nTested: cargo test --manifest-path crates/compat/auto-launch/Cargo.toml --locked\n\nTested: cargo check --locked\n\nNot-tested: rebuilt release binary and reboot autostart smoke",
          "is_bot": false,
          "headline": "Make Windows autostart register as MCPace",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-07-03T06:18:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13722af758bd149f26afa489e56458f01e700ed0",
          "body": "GitHub-hosted Windows jobs check out the repository on D: while temporary directories can live on C:. The release completion tests were joining report paths against the repo root unconditionally, which corrupted absolute paths emitted from cross-drive temporary output directories.\n\nConstraint: Relea\n[…]\nreport paths as absolute when they are absolute; only join repoRoot for relative report paths.\nTested: node --test tests/node/release-completion.test.mjs\nTested: npm run check\nTested: git diff --check",
          "is_bot": false,
          "headline": "Keep release tests portable across Windows runner drives",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-26T08:56:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "204b7486f4ff3390b48ecf292c37ee2ddbef580c",
          "body": "The release flow needed to stop treating archives as the main user-download artifact while still avoiding a risky custom self-updater. This makes npm the recommended install/update path, builds installable GitHub assets for every enabled native target, lowers the Linux glibc floor with an Ubuntu 22.\n[…]\n packed native npm tarball proof\nNot-tested: Live GitHub-hosted Windows MSI signing, macOS notarization, and non-dry-run npm/GitHub publication require external credentials and protected environments.",
          "is_bot": false,
          "headline": "Make installable releases the safe public path",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-26T08:47:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3870ac5e90d92078ab1aa1ab919b6c35e57ba26",
          "body": "After the native packages were published, npm could fully resolve optional platform packages during npm ci. The lockfile now records those real package entries, and negative resolver tests explicitly ignore installed optional packages so they keep testing missing-binary behavior instead of depending\n[…]\n explicitly rather than relying on absent node_modules entries\nTested: npm ci --ignore-scripts --no-audit --no-fund; npm run check; npm run check:package; npm run check:install-smoke; git diff --check",
          "is_bot": false,
          "headline": "Keep CI installs compatible with published native packages",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T19:10:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92636fa1f2130352479a220b917ecd78c05212b7",
          "body": "The regression builds native package tarballs into the OS temp directory. GitHub Windows runners can place that temp directory on a different drive than the checkout, so path.relative returns a drive-qualified path that must not be joined back under the repository root.\n\nConstraint: Windows CI temp \n[…]\nry | would increase cleanup risk and couple the test to workspace write state\nConfidence: high\nScope-risk: narrow\nTested: node tests/node/npm-publish-contract.test.mjs; npm run check; git diff --check",
          "is_bot": false,
          "headline": "Keep native tarball regression portable across Windows runners",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T19:03:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd4cae09b8ed7bc6057f3efd4d3029f430b3a978",
          "body": "The first published native packages also claimed a mcpace bin entry, which caused npm to skip creating the launcher shim during a normal install. Native packages now only provide platform binaries while @mcpace/cli remains the sole user-facing command owner, and the release is bumped because 0.7.6 i\n[…]\nun check:publish-trust; npm run check:workflow-policy; npm run check:security-policy; cargo check --locked; focused native tarball regression\nNot-tested: Fresh registry install of 0.7.7 before publish",
          "is_bot": false,
          "headline": "Ensure npm installs create the mcpace command",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T18:44:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8c6d0809d1fd97a6fa8b98b29974b9333ebe025",
          "body": "The first npm publication showed that the launcher package metadata was correct but the packed bin shim lacked executable mode, so fresh installs on Windows did not create the mcpace command until npm rebuild. Keep the bin shim executable in git, add a regression check for that release property, and\n[…]\nrust; npm run check:workflow-policy; npm run check:security-policy; npm run check; cargo check --locked; git diff --check\n\nNot-tested: Fresh install of 0.7.6 from npm until tag-gated publish completes",
          "is_bot": false,
          "headline": "Restore npm launcher command creation",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T18:25:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a60e7f9e30b5bb6e6c544dc49b9fbde74de9f818",
          "body": "The first scoped npm publish cannot rely only on trusted publishing because npm package settings exist only after package creation. Add repository/provenance metadata to the launcher and generated native packages, then permit a narrowly scoped protected-environment token fallback for this bootstrap \n[…]\n; npm run check:publish-trust; npm run check:workflow-policy; npm run check:security-policy; npm run check; git diff --check\n\nNot-tested: Real npm publish until the tag-gated GitHub workflow completes",
          "is_bot": false,
          "headline": "Prepare npm packages for first trusted-release bootstrap",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T17:55:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f990262fd792886d566a7cf72a540270149aa2ca",
          "body": "The manual npm dry-run proved that the publish job downloaded generated\nnative tarballs before running the clean source test suite. That polluted the\nworkspace state expected by the publish-contract regression test and would\nbreak the release lane before the actual contract enforcement step.\n\nConstr\n[…]\nr artifact download\nTested: npm run check; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust; git diff --check\nNot-tested: GitHub publish-npm dry-run after push",
          "is_bot": false,
          "headline": "Keep publish validation independent of staged native tarballs",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T17:31:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a13303226639a89c20eef869bbd83f770e41bb7",
          "body": "The publish workflow previously skipped every job when manually dispatched\nfrom main, which made the safest pre-release package proof impossible without\nfirst creating a release tag. Keep real publication tag-gated, but allow the\nmanual dry-run path to build native packages and exercise npm publish\n\n[…]\nted: npm run check; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust; npm run check:package; git diff --check\nNot-tested: GitHub publish-npm dry-run after push",
          "is_bot": false,
          "headline": "Allow npm publish dry-runs before cutting release tags",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T17:24:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52fe15cfab7ccea4a5279de7978fc1a8145e8d84",
          "body": "The manual platform proof workflow now pins macOS to explicit release runner images and adds an Intel macOS Rust smoke lane, matching the release target split more closely than a single moving macos-latest label.\n\nConstraint: GitHub warned that macos-latest is migrating to macOS 26, which can silent\n[…]\ncheck; manual platform-proof run 28186596161 passed before this pinning change on Linux/macOS/Windows.\nNot-tested: New macos-15-intel lane after this commit until GitHub Actions reruns platform-proof.",
          "is_bot": false,
          "headline": "Stabilize macOS platform proof coverage",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T17:00:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d4c9a3e6cea557fc7c2d66ee0b0809050d40588",
          "body": "The release path now treats MCPace as one generic local Streamable HTTP broker for Codex, Cursor, Claude-family, and other supported local MCP clients while hardening the surrounding install, restart, package, dashboard, and proof surfaces.\n\nThis keeps compatibility generic instead of pinning behavi\n[…]\nrowser; isolated temp HOME client install for 10 local targets; git diff --cached --check.\nNot-tested: Native macOS LaunchAgent execution; real cloud public relay; GitHub branch protection after push.",
          "is_bot": false,
          "headline": "Make MCPace reliable across local client installs and managed restarts",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-25T16:43:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "283a9e8e94ed7d925b432789d0f16f240f6415f1",
          "body": "The Rust adapter tests use tiny Node-based stdio MCP mocks for upstream tools/list coverage. Hosted Windows rust jobs did not install Node, so those mocks produced an empty catalog and made the main CI fail even though product code and local checks passed. The rust matrix now installs the repo Node \n[…]\nl assumptions explicit in both CI setup and test guards\n\nTested: cargo fmt --check; cargo test -- --test-threads=1; npm run check; git diff --check\n\nNot-tested: GitHub hosted Windows rerun before push",
          "is_bot": false,
          "headline": "Keep Windows Rust CI running upstream mock tests",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-14T14:30:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b2d5f4dd58c816e6016dcc940eb7fbda2c76237",
          "body": "Windows autostart can launch from WScript or Explorer without the current shell environment, which left MCPACE_MCP_SETTINGS invisible after login and made rootless serve commands fail outside the repo. The change teaches the autostart launcher to hydrate persistent MCPace env vars from the registry \n[…]\nuser-specific paths or settings defaults\n\nTested: cargo fmt --check; cargo test; git diff --check; rootless serve status from home with source-built binary\n\nNot-tested: Full Windows reboot/login cycle",
          "is_bot": false,
          "headline": "Make Windows MCPace restart survive user environment drift",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-14T14:13:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab31356be8750560e6b0aa06a5d9710978eb74ac",
          "body": "The Windows hosted Rust runner exposed that the parallel projection test\nassumed the auto upstream worker count would be at least two. On constrained\nrunners available_parallelism can be one, so the peer-gated fake upstreams\nrun sequentially and both return no tools.\n\nThe test now scopes MCPACE_UPST\n[…]\nts that require upstream fan-out must force their worker budget instead of relying on available_parallelism.\nTested: npm run check:rust\nNot-tested: GitHub-hosted Windows Rust after this follow-up push",
          "is_bot": false,
          "headline": "Make parallel-probe Rust test independent of runner CPU count",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T20:34:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4e8be991b578bc36d1be6d5046a5bd9d29b69e3",
          "body": "The hosted Rust job uncovered that several Rust tests exercise local HTTP listeners and short-lived stdio upstream processes. Running the lib suite with the default parallel harness can race those live probes on constrained runners, producing unrelated catalog misses even when the implementation is \n[…]\nect-hygiene.test.mjs tests/node/platform-proof.test.mjs\nTested: npm run check\nTested: npm run check:package\nTested: npm run pack:npm:dry-run\nNot-tested: GitHub-hosted Rust CI after this follow-up push",
          "is_bot": false,
          "headline": "Stabilize Rust CI around live runtime tests",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T20:27:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "016ff28f98ccdfa0cddd6471882305981724fa88",
          "body": "The Windows node matrix was checking out Cargo.lock with CRLF because the repository only pinned common source extensions to LF. The docs/package metadata test intentionally compares Cargo.lock content with LF-sensitive Rust metadata, so lockfiles need to be covered by the same repository text polic\n[…]\ne/docs-and-package.test.mjs tests/node/project-hygiene.test.mjs\nTested: npm run check\nTested: npm run check:package\nTested: npm run pack:npm:dry-run\nNot-tested: GitHub-hosted Windows runner after push",
          "is_bot": false,
          "headline": "Make hosted Windows CI honor lockfile LF policy",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T20:14:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2eb60e83766ca7a61bc8e68e0b71eeb02069e48c",
          "body": "After adding LF rules for .mjs and HTML, switching branches on Windows still materialized .gitattributes itself with CRLF because the named control files were only covered by text=auto. The hygiene gate checks those names directly, so they need explicit LF attributes as well.\n\nConstraint: core.autoc\n[…]\nfile type/name to the LF hygiene gate, add a matching .gitattributes rule in the same change.\n\nTested: node --test tests/node/project-hygiene.test.mjs\n\nNot-tested: Fresh clone on another Windows host.",
          "is_bot": false,
          "headline": "Keep repository control text files LF on Windows",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T20:05:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9cac4effd250b3cf89a05179ebcfbd4b6a7f1194",
          "body": "Fast-forwarding main on a Windows checkout exposed that .mjs scripts and the dashboard HTML were not covered by the repository LF attributes. With core.autocrlf enabled, Git can materialize those files with CRLF and make the project hygiene gate fail before push.\n\nConstraint: The repository enforces\n[…]\nt-hygiene's line-ending gate covered by .gitattributes.\n\nTested: node --test tests/node/project-hygiene.test.mjs\n\nNot-tested: Hosted GitHub runners; this is a local Windows checkout normalization fix.",
          "is_bot": false,
          "headline": "Keep generated JavaScript and dashboard sources LF on Windows",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T20:03:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e4a811687f665e2830527de8cb63994e4255492",
          "body": "Node 24 on Windows can reject direct spawnSync of npm.cmd with EINVAL, which made the full release proof fail even though the underlying npm commands worked from the shell. Route npm script invocations through the current npm CLI entrypoint when available, and keep a cmd.exe fallback only for Window\n[…]\n: npm run proof:local -- --full\n\nTested: npm run check:rust\n\nTested: npm run check:ci\n\nTested: npm run build:release-artifacts\n\nNot-tested: npm publish blocked pending platform binary package tarballs",
          "is_bot": false,
          "headline": "Keep Windows local proof from spawning npm shims directly",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-06T19:59:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ef0e56c57e25f2df7104c308ef34226a8ab7478",
          "body": "Windows verification exposed a release-build borrow issue, Rust 1.95\nclippy/rustfmt drift, and stale guardrail expectations. The runtime smoke\nalso showed that upstream server definitions such as browser and playwright\nmust remain in user MCP settings while the repository config stays focused on\nMCP\n[…]\nindows MCP runtime smoke with sequential-thinking upstream_search/upstream_call and tools/list cache hit checks\nNot-tested: External/browser-desktop upstream tool execution and publish/release dry-run",
          "is_bot": false,
          "headline": "Keep MCPace Windows runtime usable without bundling personal upstreams",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-06-05T13:29:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5ca29ee3214b853da44ae25c4e324a6c797be2f",
          "body": "…ntation and scripts.",
          "is_bot": false,
          "headline": "Remove stale report files and update release manifest with new docume…",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-29T19:44:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee5d07d5e3222a0c211f14b0a03b9503f0cec1fe",
          "body": "The server cards now expose the useful per-server actions without making\nusers reason through worker internals, and the dashboard backend now handles\nthose actions through the existing dynamic mcpace server commands instead of\nstatic or per-server shortcuts.\n\nConstraint: UI actions must work for arb\n[…]\n cargo check --package mcpace\nTested: node scripts/cargo-task.mjs fmt --check; git diff --check\nTested: live 39022 healthz refresh ok, server-autotune empty POST 200, ABP process count 0 after restart",
          "is_bot": false,
          "headline": "Make dashboard server controls act on real MCPace state",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-26T21:09:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1953265271c4bbbc3768304f5e74c69d97a7c47",
          "body": "The dashboard was guessing server purpose and the upstream pool only cleaned idle child processes lazily. This change makes server rows derive capability text from backend/source/tools-list evidence and exposes generic pool eviction in runtime status so process cleanup applies across pooled stdio MC\n[…]\ns test\n\nTested: node scripts/cargo-task.mjs test dashboard\n\nTested: node scripts/cargo-task.mjs fmt --check\n\nTested: live 39022 health shows upstreamSessionPool evictedIdleCount and zero ABP processes",
          "is_bot": false,
          "headline": "Make MCP server controls evidence-driven",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-26T20:26:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d95b86b8eb206ee4721cf7872f471376e22e718f",
          "body": "This pass turns the local hub toward the scheduler niche: discover likely MCP\nservers, infer conservative runtime/effect classes, expose policy/instance\nsurfaces, and ship a lab corpus that keeps auto mode auditable. It also fixes\nrelease-only Windows load stability found during final validation by \n[…]\npm run pack:npm:dry-run; npm publish --workspace @mcpace/cli --dry-run --json; npm run build:release-artifacts; npm run check\nNot-tested: Real npm publish, because npm authentication is not configured",
          "is_bot": false,
          "headline": "Make MCPace prove safe automatic runtime scheduling",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-26T12:45:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f44b73610097cc739602795b70360a4f05ab5f4",
          "body": null,
          "is_bot": false,
          "headline": "Remove manager.settings.json and centralize helper functions",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-25T17:12:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ad5ee0d551b433e3d2ab0d110571763b5d71d1f",
          "body": "…tracking",
          "is_bot": false,
          "headline": "Add strict MCP JSON-RPC validation, lifecycle gating, and request ID …",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-23T13:19:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1a3bfbee254ec499a8ce477f331d357dc30d49a",
          "body": "The source tree is trimmed to the public MCPace runtime and npm launcher surface while preserving the local Windows restart path through a stable cargo-installed native binary. The bundled checks now validate manifest-declared source paths instead of treating a normal git checkout as a release archi\n[…]\ntion; /healthz readiness probe.\n\nNot-tested: Full Windows logout/login reboot cycle; GitHub-hosted CI because repository intentionally avoids paid hosted CI.\n\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Ship a lean verified source surface",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-20T06:26:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f3533342a831267a363d9f73e6a26ac05d46d5f",
          "body": "Promotes the final automation quiet-state cleanup into main through PR flow.\n\nConstraint: User wants no stale PRs, no automatic paid GitHub Actions, and no hanging repository state.\nRejected: Leave security/codeql schedules active | they still create skipped check noise on a private repo without ena\n[…]\nling or a self-hosted runner is intentionally configured.\nTested: npm run ci:local:quick\nNot-tested: Manual GitHub workflow dispatch after future runner setup\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Promote quiet automation cleanup to main",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-19T14:36:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1fc5a72c9e4c45742589336c4c3637c31e8c91ad",
          "body": "Makes the remaining hosted workflows manual-only and pauses Dependabot version PR creation. This removes automatic skipped/failing check noise while preserving explicit workflow dispatch for later GitHub Actions setup.\n\nConstraint: User wants no hanging GitHub noise and does not want paid hosted Act\n[…]\nor a trusted self-hosted runner.\nTested: npm run ci:local:quick\nTested: git diff --check\nNot-tested: Manual GitHub workflow dispatch after future runner setup\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Keep GitHub automation quiet until runners are intentional",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-19T14:35:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45768872e7bc41deaa450c0ebf633c48bad1729f",
          "body": "Brings the locally verified dev branch into main through the normal pull-request path while preserving the dev branch for continued work.\n\nConstraint: User asked to avoid paid GitHub-hosted Actions and run CI locally instead.\nConstraint: Branch protection/status-check enforcement is not available on\n[…]\npromotion into main after local CI passes.\nTested: npm run ci:local\nNot-tested: GitHub-hosted Actions, intentionally manual-only to avoid paid runner minutes.\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Promote locally verified dev to main",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-19T14:29:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7670d14b5ec738f7b73f898401fc1a27f44e5d4",
          "body": "Moves the default repository quality gate to local commands and keeps GitHub-hosted Actions as explicit manual proof lanes. This prevents private-repo pushes and pull requests from starting paid GitHub runners while preserving a cloud validation path when billing is intentionally enabled.\n\nThe local\n[…]\ns.\nTested: npm run hooks:install\nTested: npm run ci:local\nTested: git diff --cached --check\nNot-tested: Manual GitHub workflow dispatch after billing recovery\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Avoid paid hosted CI for normal repository sync",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-19T14:20:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71096d349e1a5b753862e22dd0549bfb0ba4b1d0",
          "body": "Reworks the public source snapshot around evidence-backed MCP install, overhead, and runtime-validation lanes. The change removes stale preset-era artifacts, refreshes reports and docs, adds targeted MCP overhead and race coverage, and keeps local/public publication decisions separated.\n\nThe adapter\n[…]\nce upstream_search and browser dashboard smoke against localhost:39022\nNot-tested: npm/native package publication and optional cargo audit/deny advisory lanes\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
          "is_bot": false,
          "headline": "Prepare MCPace for evidence-first public source sync",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-19T14:04:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb1c2b678a6b6a72268afcca65b9c0ddf7d2b7d8",
          "body": "…dynamic source policies\n\nThis commit refactors upstream tool validation to work with session pools by moving validation after lease acquisition and passing the pool to validation functions. It introduces dynamic source policy inference based on server characteristics (name, command, URL) to replace\n[…]\nd script updates in package.json\n\nThe core refactor enables safer, more flexible upstream server handling by decoupling tool validation from lease acquisition and making source policies context-aware.",
          "is_bot": false,
          "headline": "refactor: implement session pooling for upstream tool validation and …",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-17T19:04:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d9c229b66e65b6769548aefae0d08a05ea4881",
          "body": null,
          "is_bot": false,
          "headline": "Add Playwright E2E test script for dashboard",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-16T19:48:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e3d0fc45e15411ea8f919981d8a68ba24207f4f",
          "body": "…exposure guards, message-integrity hardening, and upstream resilience improvements",
          "is_bot": false,
          "headline": "chore: bump version to 0.6.0 and implement lifecycle hardening, tool …",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-15T18:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ebc6ec80e91470d3dbf52d19a71cc1f092ccb3",
          "body": "The adapter now keeps the default auto tools/list path cache-only and\nfalls back to broker tools when the upstream catalog is cold or stale,\nwhile serve warms a persistent tools/list cache in the background.  The\nraw catalog path still supports native/hybrid/refresh modes, but probes\ncallable upstre\n[…]\n; cargo check; cargo clippy --all-targets -- -D warnings; cargo test; live mcpace serve MCP smoke with tools/list in 60ms\nNot-tested: Long-running multi-day cache aging beyond schema/fingerprint tests",
          "is_bot": false,
          "headline": "Prevent DA clients from timing out on large upstream MCP catalogs",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-14T10:16:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c162d52c632d47e6c397ba44fd7a0ec6e9a1414",
          "body": "MCPace was treating every upstream as a short-lived direct child, which left Windows launcher descendants alive for npx-based servers and made Docker/Bun launchers sensitive to absolute shim paths. This keeps upstream registration config-driven while hardening stdio process-tree cleanup, adding a se\n[…]\n docker mcp gateway server test (8 tools); serve restart/status warnings empty; leak check 0.\n\nNot-tested: Direct HTTPS upstream without stdio/TLS adapter; heavyweight docker image-specific run smoke.",
          "is_bot": false,
          "headline": "Stabilize dynamic MCP upstream launch paths",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-13T17:00:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94085d7b488ff4546ed09941637985d1b8b5c212",
          "body": "Defaulting top-level tool exposure to broker keeps initial tools/list small and avoids probing every configured upstream MCP server during client startup. Native projected tools remain available through explicit MCPACE_TOOL_EXPOSURE=auto|hybrid|native for clients that need them.\n\nThe doctor now trea\n[…]\ne-syntax.mjs --json; node scripts/mcpace-full-doctor.mjs --json\nNot-tested: Non-Codex clients that deliberately rely on implicit top-level projected upstream tools without setting MCPACE_TOOL_EXPOSURE",
          "is_bot": false,
          "headline": "Prevent MCPace startup fan-out from stalling clients",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-11T13:31:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "941040cd246dec0682247dd5b1a86ac6e5ac3244",
          "body": "Merged with local verification because GitHub-hosted checks did not start due to the account billing/spending-limit blocker.\n\nLocal evidence for head 23673f5002653cb28accc9cf7d662500bbe37f84:\n- npm run test:repo: pass (39/39)\n- npm run test:rust:ci: pass\n- npm run doctor:full: exit 0 with warnings o\n[…]\nargo check -p mcpace: pass\n- code/security review blockers resolved\n\nHosted CI blocker annotation: jobs were not started because recent account payments failed or spending limit needs to be increased.",
          "is_bot": false,
          "headline": "Merge verified MCPace dev proof lane",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-11T12:26:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23673f5002653cb28accc9cf7d662500bbe37f84",
          "body": "The local tree had accumulated machine-state artifacts and Linux verification work that needed to be made safe before updating the dev branch. This commit keeps private client/runtime state out of the source snapshot, adds a Linux auto-check/doctor surface with durable evidence, and preserves Window\n[…]\n run verify:secrets; npm run verify:npm-pack; npm test; cargo check -p mcpace; targeted linux-auto contract test\nNot-tested: Linux Docker full auto-check on a real Linux host from this Windows session",
          "is_bot": false,
          "headline": "Harden local readiness before syncing the public proof lane",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-11T12:16:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f90d27b2e7d6d1221f849c597e1a974690e1e58e",
          "body": "The local readiness sweep found two integration-contract drifts: adapter_profile advertised token reducers that strict pluginPolicy could not accept, and disabled source-only MCP servers made health/readiness look failed even though they were intentionally disabled.\n\nThis checkpoint keeps the fix, r\n[…]\nlive smoke; healthz readyForRuntimeOps true; git diff --check\n\nNot-tested: npm/native public publication and GitHub release were not run; optional third-party supply-chain scanners are still warnings.",
          "is_bot": false,
          "headline": "Stabilize MCPace plugin and readiness gates",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-04T13:25:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb1b705b984cdf2ad73b649ac11b579326de7461",
          "body": "The repo was technically ready for a source-preview opening, but one client-surface test used a literal private-key marker as fake redaction input. That could create confusing GitHub secret-scanning noise after making the repository public. Replace it with a non-secret test redaction block while kee\n[…]\nracked-file secret pattern scan returned 0 provider/private-key matches\\nTested: git diff --check\\nNot-tested: full npm test, full Cargo suite, GitHub secret scanning UI after public visibility change",
          "is_bot": false,
          "headline": "Reduce public-readiness friction before opening the repo",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T18:16:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e62afaf33643bc82568adda2271ec7062354ec1",
          "body": "The product-practice gate had a compiled binary and tiny upstream fixture available, but runtime-trace still stopped at a manual checklist. The harness now runs a bounded local proof by spawning a temporary MCPace serve process, calling initialize and tools/list over HTTP MCP, then calling upstream_\n[…]\ntract.test.js tests/node/product-truth-contract.test.js\\nTested: git diff --check\\nNot-tested: full npm test, full Cargo test/build, multi-host runtime proof, real external client compatibility traces",
          "is_bot": false,
          "headline": "Prove the local MCP broker loop before adding more surface",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T17:32:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d22a7e3321b38dfbc471b34605b644e6e65dc3d6",
          "body": "The second full_ci run proved Docker cleanup was fixed, but left two\ncorrectness gaps: Windows archive listings still needed platform-neutral\nentry handling, and the full Docker proof was asserting a stdio-owned plan\neven though the default distribution intentionally has no upstream servers.\nThe pro\n[…]\ncontract.test.js tests/node/archive-contract.test.js\nTested: npm test\nTested: node scripts/verify-ubuntu-docker-full.mjs --json\nNot-tested: Re-dispatched full GitHub CI after this proof alignment fix.",
          "is_bot": false,
          "headline": "Make full CI proofs match portable default artifacts",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T16:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7139c645535a543f3a2e95399d487cc4d6ff8415",
          "body": "The real full_ci GitHub run proved the cheap path was not enough: Windows\nhosted source tests found zip entries created with platform separators, and\nUbuntu Docker lanes passed their checks but left root-owned bind-mount files\nthat the host runner could not remove. The Docker proof scripts now resto\n[…]\nive-contract.test.js\nTested: node scripts/verify-ubuntu-docker-fast.mjs --json\nTested: node scripts/verify-ubuntu-docker-e2e.mjs --json\nNot-tested: Re-dispatched full GitHub CI after this cleanup fix.",
          "is_bot": false,
          "headline": "Make full GitHub CI lanes clean up after themselves",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T16:03:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a383f251c585cc8d8e7ac2264962030463044ae",
          "body": "The GitHub run reached Linux rust-tests and exposed a Windows-specific\nplaceholder assertion. A Rust-only Docker proof also showed that the\ndashboard upstream smoke should not fail before test intent when node is not\ninstalled. This keeps the CI path platform-neutral while preserving the real\nupstre\n[…]\n -- -D warnings\nTested: npm test\nTested: docker run --rm -v ${PWD}:/work -w /work rust:1.95-bookworm bash -c 'cargo test --locked --lib'\nNot-tested: Re-dispatched GitHub CI after this portability fix.",
          "is_bot": false,
          "headline": "Keep Rust tests portable in CI and Rust-only containers",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T15:37:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "113dce32ab1a83b9d4c1f53f82ac7f3185a515f3",
          "body": "The GitHub run reached the real Rust quality gate after the setup-node cache fix\nand then exposed two Linux-only clippy failures: the Unix-only upstream test did\nnot import the stdio spawn helper, and the POSIX detach closure nested an\nunnecessary unsafe block. Windows local clippy could not see the\n[…]\nm test\nTested: docker run --rm -v ${PWD}:/work -w /work rust:1.95-bookworm bash -c 'cargo clippy --all-targets --locked -- -D warnings'\nNot-tested: Re-dispatched GitHub CI after this Linux clippy fix.",
          "is_bot": false,
          "headline": "Make Linux clippy prove the pushed CI branch",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T15:07:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07097aa6dcd852a37fecf42aed87c924365e5b4c",
          "body": "The first dispatched CI run proved the budget split worked because all expensive\nfull-ci lanes were skipped, but setup-node failed immediately on jobs that had no\nnpm lockfile to cache. MCPace currently has no package-lock.json, so automatic\npackage-manager caching must stay disabled anywhere setup-\n[…]\nts/node/stack-contract.test.js tests/node/rust-test-runner-contract.test.js\nTested: git diff --check\nNot-tested: Re-dispatched GitHub CI after this fix; previous run failed at setup-node before tests.",
          "is_bot": false,
          "headline": "Prevent GitHub setup-node from failing before tests",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T14:56:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf3af5f0492cac8a0ce5033ee8e56fcdd0a546ba",
          "body": "The default workflow was proving too much on every pull request: full Windows,\nmacOS, Rust, Docker, and release dry-run lanes all competed for hosted minutes\nbefore a change was release-shaped. This keeps fast confidence on normal pushes\nand pull requests while preserving explicit full-proof paths f\n[…]\nff --check\nTested: git ls-remote confirmed actions/checkout@v6 and actions/setup-node@v6 tags exist upstream\nNot-tested: Actual GitHub-hosted workflow execution; requires pushing the branch to GitHub.",
          "is_bot": false,
          "headline": "Keep GitHub CI useful without burning hosted minutes",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T14:50:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b79f8c272867c34795fefcf279d31b3e5713f291",
          "body": "This change completes the client-first runtime lane: MCPace can install one\nlocalhost Streamable HTTP entry into supported local clients, onboard useful\nBYO MCP servers through preset/starter fragments, expose live upstream tools\nthrough broker and projected MCP tools, and keep source/release eviden\n[…]\ne-final-20260502T141338Z.json\nNot-tested: Actual macOS host execution; verified macOS contracts/matrix only.\nNot-tested: Published native npm install from registry; package mode remains thin-launcher.",
          "is_bot": false,
          "headline": "Make MCPace client-first runtime usable across local clients",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-02T14:37:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04e5d7814684c184eca697cc76041e567942fb8b",
          "body": "A live CLI sweep found that `mcpace --version` failed even though the binary\nsupports `mcpace version`. The npm launcher forwards user flags directly, so\ncommon package-manager and smoke-test probes should not trip over this alias.\n\nConstraint: Keep the Rust command surface minimal while supporting \n[…]\noot version_flag_aliases_version_command -- --exact\nTested: cargo run --quiet -- --version\nTested: cargo run --quiet -- -V\nTested: npm run verify:rust-quality\nTested: npm test\nTested: git diff --check",
          "is_bot": false,
          "headline": "Support standard version flags for CLI smoke checks",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-01T13:42:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a4c2f7beb4bc73034cd44a0b813757f15ec7892",
          "body": "MCPace now commits to one local adapter endpoint with generic upstream\nbrokering, source-only MCP server discovery from user mcp_settings.json,\nand no bundled upstream server recommendations by default.\n\nThis also tightens the proof boundary around runtime hardening: explicit\nenvironment allowlistin\n[…]\ndiff --check\nNot-tested: Published npm provenance proof.\nNot-tested: GitHub Release publication.\nNot-tested: macOS/Linux real-host runtime from this Windows host.\nNot-tested: HTTP upstream forwarding.",
          "is_bot": false,
          "headline": "Make MCPace a verifiable BYO local MCP runtime",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-05-01T13:33:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72d64b061d746c1f379c75b2dd1996beb139a3be",
          "body": "MCPace now keeps the Codex-visible tool surface small without hiding what is\nactually proxied. The runtime exposes explicit upstream discovery, policy audit,\npolicy suggestions, guarded upstream calls, batch/session routing, and a\nsurface manifest that distinguishes native MCPace tools from configur\n[…]\nanifest, upstream_policy_audit, upstream_policy_suggest, browser guard/batch smoke, windows-mcp guarded PowerShell smoke\nNot-tested: Linux/macOS real-host runtime lanes and public/cloud relay surfaces",
          "is_bot": false,
          "headline": "Make MCPace honest and safe as the local MCP gateway",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-28T21:52:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d0a1faebf5a874db00bb975f433e599a90db255",
          "body": "This change closes the practical local gaps around client install,\nrestore, runtime lease forwarding, and proof truth. It adds previewable\ninstalls and rollback backups, gates upstream wrapper calls with\nscheduler leases, heartbeat-renews short-TTL calls, refuses stale\nresponses after lease loss, co\n[…]\nm run prove:local; npm run prove:report; git diff --check\nNot-tested: real-host runtime proof across Windows/macOS/Linux; GitHub/npm publish provenance proof; durable pooled-session takeover semantics",
          "is_bot": false,
          "headline": "Make MCPace safer to run without manual recovery",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-28T09:42:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c3654215254cee5a6bd75e24a02d50972e310b6",
          "body": "Snapshot the verified local MCPace working tree onto a GitHub-backed branch.\nThis keeps client startup behind stable MCPace management tools while adding\nruntime/client hardening, npm release lanes, evidence reports, and the latest\nupstream bridge improvements: explicit upstream catalog/call/batch t\n[…]\n npm run test:repo; npm run lint:npm; cargo +stable build --release; live HTTP MCP upstream_catalog and upstream_probe cache smoke at http://127.0.0.1:39022/mcp\nNot-tested: GitHub-hosted CI after push",
          "is_bot": false,
          "headline": "Make MCPace native runtime and upstream bridge releasable",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-27T18:49:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "756a6259debc41d47eac34ff4534c7ef0304c209",
          "body": "The GitHub repository had an unrelated older history, so this merge keeps that\nhistory reachable while making the current Rust-first one-server MCPace tree the\npublished mainline. Conflicting legacy files were resolved in favor of the\ncurrent local implementation so the remote ends up with the verif\n[…]\nble cargo test -q\nTested: npm test\nTested: rustup run stable cargo build --release\nNot-tested: Manual inspection of every historical remote-only file beyond the ones excluded by current repo contracts",
          "is_bot": false,
          "headline": "Preserve GitHub history while publishing the new one-server MCPace",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-21T20:36:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cdbee04e7efde0fcf6ef7fc932968ec4a554c070",
          "body": "This change finishes the local one-server direction: MCPace now centers on a\nsingle localhost MCP URL, a managed serve lifecycle, and HTTP-first client\ninstall/export/plan flows instead of per-client launcher drift. The client\nsurfaces, docs, dashboard/help text, and verification now line up around \n[…]\nclient plan --json --root . --client-id hermes-agent\nNot-tested: Fresh interactive session validation in every supported client UI\nNot-tested: Cloud/public relay surfaces and blocked connector classes",
          "is_bot": false,
          "headline": "Make MCPace the one local HTTP server for supported clients",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-21T20:29:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87d1d585a2143ded0557d1f49c97b185972ebb88",
          "body": "The workspace arrived without git metadata, so this commit snapshots the\ncurrent Rust-only repo locally and removes ambiguity about the exact\nchecked state. While verifying the snapshot, Windows hub launch tests\nexposed a background-start path that left `hub up` hanging under\ncaptured stdio; the lau\n[…]\n\nNot-tested: bare `cargo test` under this machine's `rust-toolchain.toml` override, because the local 1.95.0 rustup override is misconfigured even though `+stable` resolves to Rust 1.95.0 successfully",
          "is_bot": false,
          "headline": "Capture a verified local baseline for mcpace",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-21T13:24:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49269071e74873ba3fd86064d4b19517cc691da4",
          "body": "The top-level verification entrypoints were already present, but the reusable\nscenario catalog should live in its own module so both the scripts and the\nreporting surface can share one definition of what the repo claims to verify.\n\nConstraint: Verification scripts and reports should derive their sce\n[…]\nd of copying them into scripts or docs\nTested: Module restored into the reconstructed tree before final verification rerun\nNot-tested: Scenario-by-scenario behavioral review beyond the full test suite",
          "is_bot": false,
          "headline": "Extract reusable verification scenarios once the CI lane is in place",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-12T20:54:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b31568d563ae8f621f6e85e1fe5a9c0afa1bbc4",
          "body": "Finish the timeline with the public-facing README, contributor guidance, and summary reports once the runtime, verification, and audit surfaces have settled into the shape that should be presented to other people.\n\nConstraint: Public-facing repo narrative should trail the implementation and verifica\n[…]\nas a distilled view of the verified repository surface\nTested: Final narrative files reviewed against the current repository contents\nNot-tested: External contributor onboarding against the final docs",
          "is_bot": false,
          "headline": "Refresh the public MCPace narrative after the baseline stabilizes",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-12T14:27:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c31e649c3d7d5b2ef460d62b9150d893c8e482f",
          "body": "Integrate the separate report stream without flattening it so the main line shows that the baseline, artifacts, and explanatory reports arrived as a parallel documentation effort.\n\nConstraint: Audit work should read as a distinct lane rather than generic follow-up edits\nRejected: Re-commit reports l\n[…]\nnce: medium\nScope-risk: narrow\nDirective: Keep evidence-oriented reporting distinguishable from stable product documentation\nTested: Merge completed cleanly\nNot-tested: Re-rendered reports after merge",
          "is_bot": false,
          "headline": "Merge the audit lane after the reporting baseline is coherent",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-11T20:41:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63c200c859f52b484f3bb8ec5e8fb0204ca918d2",
          "body": "Extend the reporting lane with the latest generated verification artifacts so the repository keeps an evidence snapshot of what the launcher actually produced at this stage.\n\nConstraint: Verification artifacts are evidence snapshots and should travel with the audit narrative that produced them\nRejec\n[…]\nerated audit artifacts as time-bound evidence, not evergreen documentation\nTested: Artifacts reviewed for consistency with the recorded baseline\nNot-tested: Fresh regeneration after later code changes",
          "is_bot": false,
          "headline": "Publish verification artifacts alongside the verified baseline",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-11T12:18:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a06d8345744aaa5b6439c3c8eff629569209f04d",
          "body": "…able\n\nStart a separate reporting lane for the reproducible baseline so the narrative of audit work remains visible instead of being flattened into general documentation updates.\n\nConstraint: Audit-style reports should preserve their own cadence and context\nRejected: Fold audit results into generic \n[…]\nports dated and evidence-oriented instead of rewriting them into timeless docs\nTested: Reports reviewed against the current launcher and verification behavior\nNot-tested: Independent third-party audit",
          "is_bot": false,
          "headline": "Record the security and stability baseline once behavior looks repeat…",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-10T18:49:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3290d5004ffbcf90c1d37f5693ba292415cc820",
          "body": "Add CODEOWNERS once the collaboration and verification surfaces are present so future changes route to a clear owner instead of relying on implicit knowledge.\n\nConstraint: Ownership metadata is useful only after the repo has enough surface to review meaningfully\nRejected: Add ownership in the first \n[…]\nw\nDirective: Keep ownership mappings aligned with the reviewable surface of the repository\nTested: Ownership file reviewed for repo scope coverage\nNot-tested: Live code-owner review requests on GitHub",
          "is_bot": false,
          "headline": "Make repository ownership explicit before wider sharing begins",
          "author_name": "Ramenm",
          "author_login": "Ramenm",
          "committed_at": "2026-04-10T11:27:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 4,
      "commits_last_year": 116,
      "latest_release_at": "2026-07-19T17:00:05Z",
      "latest_release_tag": "v0.8.2",
      "releases_from_tags": true,
      "days_since_last_push": 3,
      "active_weeks_last_year": 17,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 10
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml"
      ],
      "largest_source_bytes": 429592,
      "source_files_sampled": 353,
      "oversized_source_files": 11,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 146,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "auto-launch",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.6"
        },
        {
          "name": "getrandom",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "which",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8"
        },
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "ureq",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3.3.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "auto-launch",
            "direct": true,
            "version": "0.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "clap",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": true,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": true,
            "version": "0.3.4",
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": true,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": true,
            "version": "1.0.150",
            "ecosystem": "crates"
          },
          {
            "name": "ureq",
            "direct": true,
            "version": "3.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "which",
            "direct": true,
            "version": "8.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "android_system_properties",
            "direct": false,
            "version": "0.1.5",
            "ecosystem": "crates"
          },
          {
            "name": "anstream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle",
            "direct": false,
            "version": "1.0.14",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-parse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-query",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-wincon",
            "direct": false,
            "version": "3.0.11",
            "ecosystem": "crates"
          },
          {
            "name": "base64",
            "direct": false,
            "version": "0.22.1",
            "ecosystem": "crates"
          },
          {
            "name": "bitflags",
            "direct": false,
            "version": "2.13.0",
            "ecosystem": "crates"
          },
          {
            "name": "block2",
            "direct": false,
            "version": "0.6.2",
            "ecosystem": "crates"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "1.12.1",
            "ecosystem": "crates"
          },
          {
            "name": "cc",
            "direct": false,
            "version": "1.2.66",
            "ecosystem": "crates"
          },
          {
            "name": "cesu8",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "cfg-if",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "cfg_aliases",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "clap_builder",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "clap_derive",
            "direct": false,
            "version": "4.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "clap_lex",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "colorchoice",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "crates"
          },
          {
            "name": "combine",
            "direct": false,
            "version": "4.6.7",
            "ecosystem": "crates"
          },
          {
            "name": "core-foundation",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "core-foundation-sys",
            "direct": false,
            "version": "0.8.7",
            "ecosystem": "crates"
          },
          {
            "name": "dirs",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "dirs-sys",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "dispatch2",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "find-msvc-tools",
            "direct": false,
            "version": "0.1.9",
            "ecosystem": "crates"
          },
          {
            "name": "heck",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "http",
            "direct": false,
            "version": "1.4.2",
            "ecosystem": "crates"
          },
          {
            "name": "httparse",
            "direct": false,
            "version": "1.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "is_terminal_polyfill",
            "direct": false,
            "version": "1.70.2",
            "ecosystem": "crates"
          },
          {
            "name": "itoa",
            "direct": false,
            "version": "1.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "jni",
            "direct": false,
            "version": "0.21.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys-macros",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "libc",
            "direct": false,
            "version": "0.2.186",
            "ecosystem": "crates"
          },
          {
            "name": "libredox",
            "direct": false,
            "version": "0.1.18",
            "ecosystem": "crates"
          },
          {
            "name": "log",
            "direct": false,
            "version": "0.4.33",
            "ecosystem": "crates"
          },
          {
            "name": "memchr",
            "direct": false,
            "version": "2.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "nix",
            "direct": false,
            "version": "0.31.3",
            "ecosystem": "crates"
          },
          {
            "name": "objc2",
            "direct": false,
            "version": "0.6.4",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-cloud-kit",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-data",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-foundation",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-graphics",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-image",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-location",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-text",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-encode",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-foundation",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-io-surface",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-quartz-core",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-security",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-service-management",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-ui-kit",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-user-notifications",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "once_cell",
            "direct": false,
            "version": "1.21.4",
            "ecosystem": "crates"
          },
          {
            "name": "once_cell_polyfill",
            "direct": false,
            "version": "1.70.2",
            "ecosystem": "crates"
          },
          {
            "name": "openssl-probe",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "option-ext",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "os_info",
            "direct": false,
            "version": "3.15.0",
            "ecosystem": "crates"
          },
          {
            "name": "percent-encoding",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro2",
            "direct": false,
            "version": "1.0.106",
            "ecosystem": "crates"
          },
          {
            "name": "quote",
            "direct": false,
            "version": "1.0.46",
            "ecosystem": "crates"
          },
          {
            "name": "r-efi",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "redox_users",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "crates"
          },
          {
            "name": "ring",
            "direct": false,
            "version": "0.17.14",
            "ecosystem": "crates"
          },
          {
            "name": "rustls",
            "direct": false,
            "version": "0.23.41",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-native-certs",
            "direct": false,
            "version": "0.8.4",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-pki-types",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-platform-verifier",
            "direct": false,
            "version": "0.6.2",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-platform-verifier-android",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-webpki",
            "direct": false,
            "version": "0.103.13",
            "ecosystem": "crates"
          },
          {
            "name": "same-file",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "crates"
          },
          {
            "name": "schannel",
            "direct": false,
            "version": "0.1.29",
            "ecosystem": "crates"
          },
          {
            "name": "security-framework",
            "direct": false,
            "version": "3.7.0",
            "ecosystem": "crates"
          },
          {
            "name": "security-framework-sys",
            "direct": false,
            "version": "2.17.0",
            "ecosystem": "crates"
          },
          {
            "name": "serde_core",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_derive",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "shlex",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "smappservice-rs",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "strsim",
            "direct": false,
            "version": "0.11.1",
            "ecosystem": "crates"
          },
          {
            "name": "subtle",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": false,
            "version": "2.0.118",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": false,
            "version": "1.0.69",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": false,
            "version": "2.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror-impl",
            "direct": false,
            "version": "1.0.69",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror-impl",
            "direct": false,
            "version": "2.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "unicode-ident",
            "direct": false,
            "version": "1.0.24",
            "ecosystem": "crates"
          },
          {
            "name": "untrusted",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "ureq-proto",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "utf8-zero",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "crates"
          },
          {
            "name": "utf8parse",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "walkdir",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "wasi",
            "direct": false,
            "version": "0.11.1+wasi-snapshot-preview1",
            "ecosystem": "crates"
          },
          {
            "name": "wasip2",
            "direct": false,
            "version": "1.0.4+wasi-0.2.12",
            "ecosystem": "crates"
          },
          {
            "name": "webpki-root-certs",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "crates"
          },
          {
            "name": "webpki-roots",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "crates"
          },
          {
            "name": "winapi-util",
            "direct": false,
            "version": "0.1.11",
            "ecosystem": "crates"
          },
          {
            "name": "windows-link",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-registry",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-result",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-strings",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.45.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.52.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.61.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-targets",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-targets",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_gnullvm",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_msvc",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnu",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_msvc",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnu",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnullvm",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_msvc",
            "direct": false,
            "version": "0.42.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen",
            "direct": false,
            "version": "0.57.1",
            "ecosystem": "crates"
          },
          {
            "name": "zeroize",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "zmij",
            "direct": false,
            "version": "1.0.21",
            "ecosystem": "crates"
          },
          {
            "name": "@mcpace/cli",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-darwin-arm64",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-darwin-x64",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-linux-arm64-gnu",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-linux-x64-gnu",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-win32-arm64-msvc",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mcpace/cli-win32-x64-msvc",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "@publint/pack",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "mri",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "package-manager-detector",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "publint",
            "direct": false,
            "version": "0.3.21",
            "ecosystem": "npm"
          },
          {
            "name": "sade",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 146,
        "direct_count": 8,
        "indirect_count": 138
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 6,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Ramenm",
          "commits": 116,
          "avatar_url": "https://avatars.githubusercontent.com/u/43914741?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "linux-auto.yml",
        "performance.yml",
        "platform-proof.yml",
        "publish-npm.yml",
        "release-dry-run.yml",
        "release.yml",
        "security.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/19 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f7dafcc2909deb8398e3365df948c9800abd17a4",
        "ran_at": "2026-07-25T15:52:03Z",
        "aggregate_score": 6.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T16:05:08Z",
      "oldest_open_prs": [
        {
          "number": 10,
          "created_at": "2026-07-16T15:17:05Z",
          "last_comment_at": "2026-07-16T15:17:06Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 11,
          "created_at": "2026-07-16T15:17:05Z",
          "last_comment_at": "2026-07-16T15:17:06Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 12,
          "created_at": "2026-07-16T15:17:09Z",
          "last_comment_at": "2026-07-16T15:17:10Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 13,
          "created_at": "2026-07-16T15:17:10Z",
          "last_comment_at": "2026-07-16T15:17:11Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 16,
          "created_at": "2026-07-21T16:05:02Z",
          "last_comment_at": "2026-07-21T16:05:03Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 17,
          "created_at": "2026-07-21T16:05:06Z",
          "last_comment_at": "2026-07-21T16:05:07Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 18,
          "created_at": "2026-07-21T16:05:13Z",
          "last_comment_at": "2026-07-21T16:05:14Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 19,
          "created_at": "2026-07-21T16:05:14Z",
          "last_comment_at": "2026-07-21T16:05:14Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 20,
          "created_at": "2026-07-21T16:05:21Z",
          "last_comment_at": "2026-07-21T16:05:22Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 21,
          "created_at": "2026-07-21T16:05:44Z",
          "last_comment_at": "2026-07-21T16:05:45Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-07-19T17:00:06Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Ramenm/MCPace",
    "host": "github.com",
    "name": "MCPace",
    "owner": "Ramenm"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 75,
        "vitality": 81,
        "community": 24,
        "governance": 27,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 116,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 17
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "17/52 weeks with commits",
                "points": 11.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 17
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "116 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 116
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 4,
              "latest_release_tag": "v0.8.2",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "4 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "critical",
        "name": "Sustainability & Governance",
        "value": 27,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "merged_prs": 6,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "6/11 decided PRs merged",
                "points": 20.9,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 6,
                      "decided": 11
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/19 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Ramenm",
              "public_repos": 4,
              "account_age_days": 2848
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of Ramenm",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "Ramenm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~7 yr old",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 75,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 69,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/19 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 146 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 146
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 146,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 146,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 64,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.84,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "84 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 84,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 429592,
              "source_files_sampled": 353,
              "oversized_source_files": 11
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "11/353 source files over 60KB",
                "points": 53.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 353,
                      "oversized": 11
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch crates package 'mcpace' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T15:52:10.569432Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/Ramenm/MCPace.svg",
  "full_name": "Ramenm/MCPace",
  "license_state": "custom",
  "license_spdx": null
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计.