公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 08:02 UTC

Sahith59 / BoLD

Python · TypeScript未检测到许可证★ 0 星标⑂ 0 复刻始于 2026年6月在 GitHub 上查看 ↗

Sahith59/BoLD 的健康指数为 100 分中的 40 分,处于「存在风险」区间。 其得分最高的类别是Engineering Quality(72/100),最低的是Community & Adoption(22/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

40
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

40
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Sahith59个人账户
1 关注者52 个公开仓库始于 2022年1月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

36存在风险 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
4.8/36提交节奏 — 52 周中有 7 周有提交
18/18提交量 — 最近一年 403 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year403
human_commit_share1
days_since_last_push0
active_weeks_last_year7
评分方式
0/27有发布版本 — 未发布任何发布版本
0/36发布时效 — 没有发布版本
0/27发布节奏 — 没有发布版本
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count0
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

22危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

45存在风险
评分方式
22.5/22.5README
0/22.5许可证 — 未检测到许可证文件
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

40存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0.1/22.5提交分布 — 头号贡献者编写了 100% 的提交
2.7/13.5贡献者广度 — 2 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled2
top_contributor_share0.995
评分方式
0/46.8议题解决 — 没有议题或无数据
38.2/38.3PR 接受 — 已裁定的 PR 中 2/2 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/28 approved changesets -- score normalized to 0
所用输入
merged_prs2
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
2.2/25所有者影响力 — Sahith59 有 1 位关注者
21.7/25既往记录 — 52 个公开仓库,账户约 4 年
所用输入
followers1
owner_typeUser
is_verified
owner_loginSahith59
public_repos52
account_age_days1,661
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。

工程质量

基础的工程与文档实践是否到位?

72良好 · 占总体的 20%

工程实践

84良好
评分方式
24/24CI 工作流 — 2 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.mjs
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

55中等
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — https://bold-lemon.vercel.app
0/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepagehttps://bold-lemon.vercel.app
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

23危急 · 占总体的 16%

安全态势

23危急
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5许可证 — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 49 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate2.3
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

70良好 · 占总体的 0%
评分方式
45/45代理指令 — web/frontend/AGENTS.md, web/frontend/CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 99 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.99
agent_instruction_filesweb/frontend/AGENTS.md, web/frontend/CLAUDE.md
agent_instruction_max_bytes327
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.mjs
11/11静态类型检查 — src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 97 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
2/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
所用输入
has_nix
has_tests
lockfilespackage-lock.json, uv.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configssrc/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json
agent_commit_share0.97
toolchain_manifests
dependency_bot_commit_share0
评分方式
27/45可类型检查的代码 — Python,已配置类型检查(src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json)
54.1/55可控的文件大小 — 采样的 611 个源文件中有 10 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes245,593
source_files_sampled611
oversized_source_files10

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
2贡献者
403最近 12 个月提交数
0距最近推送天数
0发布版本数
1巴士系数(bus factor)
0开放议题
PyPI软件包生态系统数

数据采集警告

  • Could not fetch pypi package 'ideax' from its registry
  • Could not fetch pypi package 'bold-backend' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 2.3 / 10
2.3综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 08:02 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities49 existing vulnerabilities detected
直接依赖 39
注册表软件包版本约束清单文件
PyPIhttpx>=0.27pyproject.toml
PyPIpyyaml>=6.0pyproject.toml
PyPIideaxweb/backend/pyproject.toml
PyPIfastapi>=0.115web/backend/pyproject.toml
PyPIuvicorn>=0.32web/backend/pyproject.toml
PyPIpydantic>=2.9web/backend/pyproject.toml
PyPIpydantic-settings>=2.6web/backend/pyproject.toml
PyPIsqlalchemy>=2.0web/backend/pyproject.toml
PyPIalembic>=1.14web/backend/pyproject.toml
PyPIasyncpg>=0.30web/backend/pyproject.toml
PyPIaiosqlite>=0.20web/backend/pyproject.toml
PyPIpython-multipart>=0.0.12web/backend/pyproject.toml
PyPIargon2-cffi>=23.1web/backend/pyproject.toml
PyPIauthlib>=1.3web/backend/pyproject.toml
PyPIemail-validator>=2.2web/backend/pyproject.toml
PyPIitsdangerous>=2.2web/backend/pyproject.toml
PyPIanthropic>=0.40web/backend/pyproject.toml
PyPIreportlab>=4.2web/backend/pyproject.toml
PyPIpython-docx>=1.1web/backend/pyproject.toml
npm@hookform/resolvers^5.4.0web/frontend/package.json
npm@radix-ui/react-avatar^1.1.12web/frontend/package.json
npm@radix-ui/react-dialog^1.1.16web/frontend/package.json
npm@radix-ui/react-dropdown-menu^2.1.17web/frontend/package.json
npm@radix-ui/react-label^2.1.9web/frontend/package.json
npm@radix-ui/react-separator^1.1.9web/frontend/package.json
npm@radix-ui/react-slot^1.2.5web/frontend/package.json
npmclass-variance-authority^0.7.1web/frontend/package.json
npmclsx^2.1.1web/frontend/package.json
npmcmdk^1.1.1web/frontend/package.json
npmframer-motion^12.40.0web/frontend/package.json
npmlucide-react^1.18.0web/frontend/package.json
npmnext16.2.9web/frontend/package.json
npmposthog-js^1.395.0web/frontend/package.json
npmreact19.2.4web/frontend/package.json
npmreact-dom19.2.4web/frontend/package.json
npmreact-hook-form^7.79.0web/frontend/package.json
npmsonner^2.0.7web/frontend/package.json
npmtailwind-merge^3.6.0web/frontend/package.json
npmzod^4.4.3web/frontend/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3678,
      "has_wiki": true,
      "homepage": "https://bold-lemon.vercel.app",
      "languages": {
        "CSS": 29434,
        "HTML": 30733,
        "Mako": 704,
        "Shell": 4375,
        "Python": 3548357,
        "Dockerfile": 3424,
        "JavaScript": 121294,
        "TypeScript": 2072614
      },
      "pushed_at": "2026-07-22T16:16:08Z",
      "created_at": "2026-06-08T01:30:42Z",
      "owner_type": "User",
      "updated_at": "2026-07-22T15:04:02Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "Sahith59",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/97082825?v=4",
      "created_at": "2022-01-04T06:26:35Z",
      "is_verified": null,
      "public_repos": 52,
      "account_age_days": 1661
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "06065e27b947b60ea3ca4e378a9f0d9c50ee7b4c",
          "body": "docs: record the UAT + manual-promotion deploy pipeline is live",
          "is_bot": false,
          "headline": "Merge pull request #2 from Sahith59/docs/deploy-pipeline-state",
          "author_name": "Sahith59",
          "author_login": "Sahith59",
          "committed_at": "2026-07-22T15:00:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fff8ce36fc098c0f48d4dea322cefbac2cf6165",
          "body": "Pranav's PR #1 rewired deploys so merging to main ships to UAT only and\nproduction is a manual, un-bypassable promotion. Log it in the running state\nalongside the open findings (public prod /docs, start.sh boot re-sync, ungated\nfrontend) and the Vercel git-author-authorization gap, so the pipeline change\nand its trade-offs are recorded where the build state is tracked rather than\nleft only in PIPELINE.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: record the UAT + manual-promotion deploy pipeline is live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-22T14:47:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5b161f4a58b5c5dfaed861d972a3409d21faad41",
          "body": "Gate production behind UAT and a manual promotion",
          "is_bot": false,
          "headline": "Merge pull request #1 from Sahith59/pipeline/uat-and-manual-promotion",
          "author_name": "PranavNagothu",
          "author_login": "PranavNagothu",
          "committed_at": "2026-07-22T14:10:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d29508209eccbda673500f3f7695a538143f865e",
          "body": null,
          "is_bot": false,
          "headline": "Gate production behind UAT and a manual promotion",
          "author_name": "Pranav Nagothu",
          "author_login": "PranavNagothu",
          "committed_at": "2026-07-22T01:22:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "660fec50c4deec07bde8e2b651b5ce56ed152edb",
          "body": "Backend deployed first (main 83e4e80, Fly success, healthy) then @boldsec/core\n0.1.1 published (native-wins + provenance) — order satisfied, no false-clean\nwindow. Fresh-install functional verification confirmed the published package\ncarries the 1.6c behavior. @boldsec/mcp 0.13.0 published (1.5c review tools).\nNotes the @boldsec/next git/npm version skew as a tracked hygiene item.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: close P16C-DEPLOY-ORDER — Phase 1.5+1.6 shipped end to end",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T22:34:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "83e4e80dc241cd74941474bb73e727498d355c28",
          "body": "main at 43ae27d, CI green, Fly backend deploy succeeded (api.boldsec.io healthy);\nthe backend now accepts owner_field/declared_owner_provisional (deploy-order\nprecondition met). Records the two latent CI test issues the first push caught +\nthe remaining founder publish step.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: record Phase 1.5+1.6 pushed + backend deployed live on prod",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T19:09:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43ae27d49f2f85bcd7b1ed7966035682f164f794",
          "body": "The 1.5+1.6 stack had never been on main, so the real-Postgres CI + the adapter\nnpm-test fixtures had never run on it. The first main push caught two TEST issues\n(the deploy gate held -- deploy-backend SKIPPED -- so nothing shipped to prod).\nNeither is a product bug; the tri-gated mechanism is uncha\n[…]\nnot the CI gate. Run each adapter's npm test (exact fixture)\nAND the PG-gated tests against a real Postgres before claiming green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix two latent CI-only test failures the first main push exposed",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T18:59:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "313d83b838f18a91b0651e15ca8b54fe15579b33",
          "body": "…locklist\n\nThe Phase 1.6 tri-gate (Critics + Security + BOSS-2) all independently found the\nsame defect: _unsafe_owner_field tokenizes camelCase/snake atomically (sessionId\n-> session + id), so the CONCATENATED blocklist entries (sessionid, apikey,\ncreditcard) were unreachable -- sessionId, apiKey, \n[…]\nase 1.6 (authoritative-but-provisional owner) is\ncode-complete + tri-gated. Backend 1091/0, root engine exit 0, ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6 gate fix (L1): close the camelCase/snake gap in the owner-field b…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T16:00:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c533d64b0ef9d9f6aaf2aa5e942bedcb9aba792",
          "body": "The crown-jewel-ADJACENT core of Phase 1.6. It consumes declared_owner_provisional\nin the ownership model to close the false-CONFIRMED / false-clean the 1.6a design\ngate found. classify() is UNTOUCHED -- only what the ownership model REPORTS changes.\n\nThe hole: the engine trusted ANY declared_owner \n[…]\npy\nclean; classify() untouched. Remaining for 1.6 sign-off: the full BOSS-2 + Security\n+ Critics re-gate on the verdict-path code.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6c-3/d: corroboration gate for a provisional owner (verdict-path core)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T15:41:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8d531309f0221d3eafa0645e4c7279de421a757e",
          "body": "The wire + carry for the authoritative-owner mechanism. Changes NO verdict\nyet -- the corroboration gate that consumes it is 1.6c-3. classify() untouched.\nTwo steps ship together because of a hard extra=\"forbid\" coupling (below).\n\nNative-field-wins (S2 false-clean): @boldsec/core ownerFieldAndValue \n[…]\n ruff + mypy clean. New backend accept-test is fail-on-old\n(neuter the IngestEvent fields -> the post 422s -> RED). Next = 1.6c-3.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6c-1/2: owner-field provenance + native-field-wins (plumbing, inert)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T15:21:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e47a5bf18fe77c0dce51478da6047e774ef539e",
          "body": "Phase 1.6 (PATH 2) storage floor. The review screen already lets a human\nconfirm which field owns a route; until now that confirmation was coverage-only\nand never reached detection. 1.6b persists it so a later sub-phase can steer SDK\nextraction toward the right field -- but stores it safely and chan\n[…]\n3e4f5a6b7c8. The verdict-path corroboration gate\n(1.6c-3) and the full BOSS-2 + Security + Critics re-gate come at the end of 1.6.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6b: store the human-confirmed owner field name, guarded, as metadata",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T14:47:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db6893a4e764c45369413a3905d72603d21b0366",
          "body": "…done)\n\nThe review page told the user what BoLD would watch, but not what they\nwould actually hear from it, or whether BoLD was even receiving their\ntraffic yet. This closes Phase 1.5 by answering both on the screen where\nthe trust decision is made: proof-of-life, plus a faithful preview of\nthe one \n[…]\n field as an authoritative-but-provisional detection\ninput) is next and gets its own design and gate before any verdict-path\ncode.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5f: proof-of-life + the one-alarm expectation (Phase 1.5 …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T14:03:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c3bfd1dc4b68da78ab6b9f48b06afaa799598ba",
          "body": "The review page could only be reached from the exact link a coding\nagent handed the user. A developer who wired an app through the manual\npath, or who closed that link, had no way back to confirm what BoLD\nwatches. And when an agent re-drafted after a confirm, the UI said\nnothing about the fact that\n[…]\nkend 1083/0, root engine clean; frontend 394/394, next build clean;\nthe new tests fail-on-old (KeyError on the pre-1.5e response).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5e: make the review surface reachable + honest on re-draft",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T13:40:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a287f14f3cce1c1d8c446306daf69cba64113300",
          "body": "The manual (non-MCP) path had no review surface. A developer who wired\nan app and let traffic flow had nothing to confirm — the review page\nonly understood a coding agent's draft. This evolves the Review UI so it\nconsumes BOTH draft sources honestly (an agent's code claim, or a draft\nBoLD built from\n[…]\ncurity PASS-with-conditions; frontend Critics SHIP + Security PASS.\nFrontend: tsc + eslint clean, next build clean, 390/390 tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5d frontend: the resumable, source-aware Review UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T12:29:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a85bb088a10309871d67dceca0947bf0a93f5dbb",
          "body": "The Review manifest could only be authored by the MCP path. A user who\nwired an app and let real requests flow had nothing to review — the\ndraft stayed empty until an agent declared routes. This lands the\nobserved-source builder so a monitor's own traffic fills its draft,\nwith the consent gate untou\n[…]\nd3e4f5a6b7). New POST /observe is owner-scoped, rate-limited,\ncounts-only. Contract mirror added to the frontend types (additive).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5d backend: build a reviewable draft from live traffic",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T11:49:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e73e5e1731b82c8af33960203941d95d41be57b9",
          "body": "0.12.0 is already published and predates 1.5c, so the two new review tools\n(bold_prepare_review, bold_review_status) are not in the published package and\nnpm cannot overwrite a released version. Bump to 0.13.0 so the package is\npublish-ready once the backend deploys. Publish itself stays a founder-run,\none-way step (deploy the backend first so the tools call a live endpoint).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump @boldsec/mcp to 0.13.0 for the review-manifest tools",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T03:46:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "450f068d9167a9ba55e8b678c52e12cca2a2778e",
          "body": "…(N2)\n\nThe Security gate on 1.5c noted that /confirm — the one manifest endpoint\nthat seeds DeclaredRoute, i.e. the human agreeing to what BoLD watches — used\nthe PAT-permissive auth pair, so a Bearer token (the credential the MCP holds)\ncould authenticate and skip CSRF and confirm without a browser\n[…]\nEN: Critics = SHIP, Security = PASS. web/backend 1067 passed/0\nfailed; root engine green; ruff + mypy clean. classify() untouched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the review consent gate: /confirm is browser-only server-side …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T03:22:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "635f530c4c6c02a5eff0bc0fde04a3173209c9a3",
          "body": "Until now the review-manifest could only be reached by a human in the\nbrowser; a coding agent had no way to turn what it found in the repo into\na review the human confirms. 1.5c wires that path so setup stays \"connect\nonce, let the agent do the heavy lifting\" instead of hand-authoring a draft.\n\nTwo \n[…]\nCONDITIONS (0 blockers).\nweb/backend 1065 passed/0 failed; root engine green; MCP 148 pass + typecheck\n+ build; ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5c: the MCP path's review-manifest driver",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T02:52:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ed23748b5875d0c6d7d80fe2dfe0650b0d6cd6a",
          "body": "LiveEndpoint tracked only verdict-outcome counters (owner_ok/cross_user/\nunresolved), never \"was an owner field READ on this route.\" An observed-draft\nthat inferred owner-detected from those counters would risk a false green AND a\nfalse needs-input (Critics B4). This adds the explicit signal the hon\n[…]\neview contract is method+path, and DeclaredRoute is\npath-only, so reconciling the granularities is a UI decision for the consumer.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5b Part 1: the durable owner-SEEN signal (Critics B4 fix)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T00:55:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ed048e34c22af3221e320184cd8053be4f8e9858",
          "body": "The review-manifest (where a developer confirms what BoLD watches and the owner\nfield per route) was built but orphaned. 1.5a lays the backend foundation so the\nsurface can be honest and resumable, per web/PHASE_1_5_REVIEW_MANIFEST_PLAN.md.\n\n- The load path returns per-route resolution + resolvedVal\n[…]\nlassify() untouched. 14 new tests (the rejection tests proven to fail on old\nbehavior); double-gated Security PASS + Critics SHIP.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5a: honest, resumable, dedup-safe review-manifest backend",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T00:10:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04e3403cc5d01fbf86ee35a5efaaf0d7b9bb3e21",
          "body": "… prep)\n\nSo the first (permanent) npm publish of the public SDK is clean:\n- READMEs for @boldsec/core + express/fastify/koa/hono/nestjs (had none -> blank npm\n  pages). Each: install + one-place wire + the resolveCallerId namespace note + the\n  honest omit-it-get-a-loud-needs-review rule + metadata-\n[…]\n next 85, 5 adapters, conformance x2, 5\n  adapter conformance, Nest smoke, typecheck); READMEs confirmed in every dry-run tarball.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add READMEs for the 6 SDK packages + pin the core dependency (publish…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T16:22:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "241800b97684cb624cbc61c35fa85b8cf810581f",
          "body": "Phase 0+1 fast-forwarded to main (262ec35) and deployed live: @boldsec/core + 5\nframework adapters, the framework-aware MCP guide + /connect picker, and the P1.2\nreview-manifest flow (manifest_drafts/manifest_routes via alembic f7a8b9c0d1e2).\nVerified: health 200, /api/manifest-draft 401 (deployed), landing + app /connect 200.\nnpm publish of the 8 packages remains as the one-way founder-run step.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the Universal SDK Phase 0+1 prod deploy in the state docs",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T16:12:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "262ec35332f9288c1e273173daba937ceabc5d8b",
          "body": "…t flake\n\nWith ruff fixed, pytest ran on CI Postgres for the first time on this branch: the\nmanifest suite passed (the real Alembic migration + unique/CASCADE constraints proven;\nthe PG-log duplicate-key line is that test's asserted pytest.raises(IntegrityError),\nbenign). The only failure was test_d\n[…]\nls at 30s, so nothing real is masked. This also\nde-risks the main deploy run, which is gated on this same backend job being green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the app_client lifespan fixture against a CI-contention timeou…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:53:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b5b568ea25f8bcc7228c127791ced2654ed84be",
          "body": "The on-branch CI run (branch-first, so main never goes red) caught two gaps a\nwarm local had masked:\n\n- app/db.py: CI's uv-pinned ruff flagged UP037 on two new Mapped[...] relationship\n  annotations whose quotes are redundant under `from __future__ import annotations`\n  and deviate from the file's u\n[…]\nd.\n\nBoth proven fail->pass; full backend suite (1038 passed) + the whole sdk-conformance\njob re-run locally in CI order are green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix two clean-checkout CI gaps blocking the Phase-1 deploy",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3cdb22b9ef116553477ae04dc44d88304646395f",
          "body": "The Nest conformance drives the interceptor through a mock ExecutionContext\nbecause a plain-.mjs harness cannot bootstrap NestFactory. This smoke closes\nthe one gap that leaves open: whether Nest's real Express platform hands the\ninterceptor the request shape it reads.\n\nIt bootstraps a genuine NestF\n[…]\nirst cut (numeric ids converge with the regex floor and\nprove nothing) and cleared the slug fix: @boldsec/nestjs is publish-ready.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prove the NestJS adapter over real Nest HTTP, closing the publish gate",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:24:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02dd1c70733a5f15d041e2b4daec999c10e2ec1c",
          "body": "The four new adapters exist, but the guidance still only knew Next.js. Now the\nMCP wiring guide and the connect page wire any of the six frameworks.\n\nwiringGuide(stack) gains a framework registry: a recognized stack gets a\nfocused install + the one-place wire snippet for its adapter; an unknown or\nh\n[…]\n-bearing conformance,\nthe review-manifest product, the Express live-finding proof, and the\nframework-aware guide and connect page.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the wiring guide and connect page framework-aware (P1.4)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T13:45:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6afbff81b2121bd69157ecfcb3bff0b76e1b6f0c",
          "body": "Express proved the one-deep vertical; these four replicate it to the rest of\nthe JS ecosystem. Each is a thin translator that fills the one neutral\nObservedRequest and hands it to @boldsec/core — zero extraction logic in the\nadapter, so the deterministic engine is never forked and every tap reaches \n[…]\not bootstrap NestFactory;\na real-Nest HTTP smoke test is tracked as a gate before that package is\npublished (SDKX-NEST-REAL-HTTP).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the Fastify, Koa, Hono, and NestJS adapters (P1.3b)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T13:33:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56839a57bac7ae6ffb83e08d44c9691e4d1c037b",
          "body": "The 59 golden vectors proved extraction parity on path- and body-derived\nsignals, but set no resolvers — so identity, caller_in_scope,\ncaller_non_privileged, caller_tenant, object_tenant, and the route flags were\nbound only by each adapter's own unit tests, never by the shared cross-adapter\ngate. \"5\n[…]\n7, Express\n67/67; the base-59 consumers are unchanged. Critics SHIP (golden values\nhand-reasoned against the engine, not the run).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bind the resolver-fed fields in the conformance gate (P1.3a)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:55:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f81c3a180a5b2a4d3b95648d701d395b983a3499",
          "body": "The Express adapter, the review manifest, and a live catch are each tested,\nbut never as one chain. This proves the whole vertical: a real Express app +\n@boldsec/express emits the exact events, and the real ingest pipeline +\nclassify() turn a cross-user read into a live CONFIRMED finding.\n\nThe two h\n[…]\n pipeline).\n\nThis completes the one-deep vertical; the contract is now safe to replicate\nto the four remaining framework adapters.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prove the Express vertical end to end with a live finding (P1.1c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:44:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e66337d1aa390a18f463a1a2ba555960c40a0bf2",
          "body": "The review page was read-only: it showed the drafted manifest but the\nAccept/Edit/Confirm controls did nothing. This makes them real.\n\n- Resolving a route or a caller field now PATCHes it, optimistically: the row\n  reflects the choice immediately, and on a write failure it ROLLS BACK and\n  shows a l\n[…]\ncount). 7 render tests cover accept-persists, rollback on\nfailure, the deduped confirm count, failed confirm, and the empty state.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wire the review-manifest to confirm and connect (P1.2c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:31:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "76e0d9afee1a7aaef13645f2d5b52f049ba20640",
          "body": "The coding agent (via the BoLD MCP) drafts what an app exposes; the user\nconfirms it in the browser before BoLD watches anything. This is the backend\nbehind /connect/review: four endpoints (submit / load / resolve / confirm) over\ntwo new metadata-only tables (manifest_drafts, manifest_routes), plus \n[…]\n\n\nThe interactive Accept/Edit/Confirm write-back is the next sub-phase (P1.2c);\nthe page loads and renders real server state here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the P1.2 review-manifest backend (draft submit/load/resolve/confirm)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:11:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "92f8d8e5a41fd1755ca991064ed73a0f13c1df17",
          "body": "The authed page where a user confirms what BoLD will watch after their coding\nagent drafts it — the agent-assist flow the universal-SDK plan locks in: the\nagent drafts, a human confirms an editable manifest, and a drafted owner stays\nprovisional until observed. Nothing connects until the user confir\n[…]\necondary primary action (distinct from the single\nbrand-amber CTA). Also records the P1.1 gate outcome + fixes in the ledger/plan.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the P1.2 review-manifest UI (frontend, on-brand)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T11:09:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a4079ab39ae57f601d66e70d5f490b2322200e04",
          "body": "Ran an independent Critics + Security gate on the framework-neutral core +\nExpress adapter BEFORE replicating the contract to four more adapters, so a\nflaw is caught once, not five times. Security passed; Critics caught two:\n\nF1 (silent false-clean): observeNeutral read the response body with a bare\n[…]\nreplication.\n\nRe-proven green: core 35/35, next 85/85, express 9/9, conformance 59/59 x3\n(pure, e2e-over-HTTP, Express-over-HTTP).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the P1.1 SDK contract per the early Critics/Security gate",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T11:09:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7ae73d5fa093229859c93106f9deaa49820c7e1",
          "body": "… and the Express adapter\n\nPhase 0 + Phase 1.1 of the universal SDK plan (web/UNIVERSAL_SDK_PLAN.md). The goal is to let BoLD\nconnect from any framework with the SAME deterministic alarm and the same honest coverage ceiling,\nwithout ever letting a false CONFIRMED or a false-clean differ between the \n[…]\n the two phases share the finished core/next files\nand a single lockfile; splitting would risk a non-building intermediate commit.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the universal SDK conformance foundation + framework-neutral core…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T23:07:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b9a3fb16882cb927aeab6c797859b0cbef016d6",
          "body": "Add the concrete deploy details (a9e1c75, CI 29387439898, prod verified)\nnow that it shipped, and drop the prose em dashes I introduced.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record P2.6 as deployed + live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:58:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9e1c7562ef805134313dfaa214175e08fd43f1c",
          "body": "Two things the founder hit on the deployed dashboard.\n\nThe live-tail flagged-route marker painted an alarm-red left border on\nevery row whose route has an open finding, regardless of that request's\nown verdict. So a legitimate \"own object\" or \"public access\" request on\na flagged route read like a vi\n[…]\nCritics-gated (the tail change is anthem-in-pixels); +2 fail-on-old\ntests. Frontend suite 374 pass, tsc, eslint, next build clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the live tail honest per-row and the dashboard update live (P2.6)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:48:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5cfd0624d1df6b619ccd679ce8439172acd3b9db",
          "body": "The running log and ledger still read \"not pushed yet\"; the fix\nshipped in 6797f43 (CI 29386121196 green incl. Fly deploy, prod\nverified). Update the record and note the two extra founder preview\nrounds that were folded in before push.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record P2.5 dashboard fix as deployed + live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:25:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6797f43d635821aedae9ffa662d6cd0b20b0ff33",
          "body": "The deployed dashboard read as unprofessional and the info (i)\ndisclosures did not open at all: an `absolute` panel inside a\n`.glass` card was clipped away by the card's `overflow:hidden`.\nFix the whole class of issues at the root rather than papering over\nsymptoms.\n\n- Info popover now renders throu\n[…]\n Frontend suite +5\n(popover open/close, monotone no-overshoot, viewport-clamp\nplacement sweep); tsc, eslint, and next build clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix the live dashboard on founder real-data feedback (P2.5)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:16:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0ba7f267534f3c8bfbb34e29e9a1e5c47ad1550",
          "body": "… events (P2.4)\n\nThe founder used the deployed dashboard on a real monitor and found real issues.\nDiagnosed each against the code; this fixes them and the reliability gap behind one.\n\n- Charts render on real/sparse data. The verdict-mix chart was BLANK because both\n  charts positioned points by arra\n[…]\nt deploys does not retroactively clear (an all-time\ncounter). Clearing it is a separate careful reconciliation, ledgered as P24-RESIDUAL-STALE.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix the live dashboard on real-data feedback + stop the worker losing…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T01:30:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63b8976e492f0fb68bae2e0d1ea8d2b5388c2580",
          "body": "The founder's original concern was that the live view was \"only a small link under\neach project.\" P2.1b gave it a dedicated page but left the link buried at the bottom\nof the receiving section among the coverage/leads/tail toggles. This promotes it to a\nprominent primary button at the top of the row\n[…]\n live-traffic dashboard (storage -> API -> page -> destination),\nall gated, no engine touch. Frontend gate green (lint, 346 tests, next build).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the live dashboard the primary destination on each app row (P2.2)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T16:25:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8158229b52ccfca2cc68dfc1f1e39334efbec792",
          "body": "The founder-locked v4 dashboard, ported into the real app at /live/[monitorId] and\nwired to the P2.1a owner-scoped API. This is the trust surface the whole live alarm\nis judged on, so it is COUNTS-ONLY (the frontend computes every share) and holds the\nanthem in pixels: no unearned green, a real viol\n[…]\nt clean, npm test 346 passed (48 files), next build OK. The nav entry\n(P2.2) and the \"not stored\" story are the only pieces left in this phase.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the live-traffic dashboard page (P2.1b)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T16:21:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2523811a9ce1a87651d91ed62f7fe3c75ce89a89",
          "body": "The founder-locked v4 dashboard needs graphs and headline numbers OVER TIME; P2.0\nbuilt the durable metadata-only buckets, this serves them. It is the crown-jewel\nDOGFOOD: our OWN dashboard must never be BOLA-vulnerable, so every read here goes\nthrough the same `_owned_monitor` owner check the rest \n[…]\n;\nbackend 991 passed + root engine 716; ruff + mypy clean.\n\nThe page + the pixel-honesty gate (Critics condition B) come in P2.1b; nav in P2.2.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the owner-scoped live-traffic dashboard READ API (P2.1a)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T15:30:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38ec19e34e033a586c6691124e404a79aa62c11d",
          "body": "…2.0)\n\nPhase 2 of the live-traffic dashboard needs graphs OVER TIME; the all-time\ncounters on live_endpoints cannot show a trend. This adds the storage the\nfounder approved: time-bucketed aggregate COUNTS per (monitor, endpoint,\nverdict) per 15 minutes, rolled up to daily after 30 days.\n\nMETADATA ON\n[…]\nmodels are storage + query only; the owner-scoped HTTP surface + the\npage come in P2.1 (owner-scoping is a ledgered binding requirement there).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add durable time-bucketed aggregate storage for the live dashboard (P…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T14:31:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65a2a13ca258742ecb44a37bb5bfa0ebb5b24701",
          "body": "The expandFirstApp test helper waited only for the honesty boundary note,\nwhich renders immediately and independent of the async getCoverage() fetch,\nthen SYNCHRONOUSLY queried for the app-card button that only exists after\nthat fetch resolves. On an idle machine the microtask wins the race; under\nC\n[…]\nverage test files already await findByTestId and are unaffected.\n\nFrontend gate green locally: eslint clean, 46 files / 317 tests, build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix a pre-existing async race in the Coverage test helper (CI flake)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T00:31:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2897d2683badf5bdd303b3c33d37124790508d59",
          "body": "The founder said the Info banner \"looks like an odd one out; the design is\nnot uniform.\" This is the final Phase-1 trust fix: a pure visual / token /\ncopy-voice pass, no logic change.\n\n- The Info banner and the fail-loud banner now share the system vsurface-*\n  grammar (slate vsurface-neutral for in\n[…]\nolor math), BOSS-2 SHIP (\"Phase 1 is\ngenuinely done\"). 317 frontend + build clean; backend untouched.\n\nPhase 1 (P1.1 through P1.5) is complete.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Unify the live-traffic surfaces into one visual language (P1.5)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T20:18:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02768280cdda770b6d40b07a8bcffdb8e0a5f10c",
          "body": "The founder could not parse the live labels (\"owner-access / cross-user /\nneeds review / still classifying / traffic makeup\"). Rewritten by hand\n(founder chose \"Own / allowed\"):\n\n- Coverage makeup segments (traffic-composition.ts): Own / allowed, Needs\n  review, Cross-user access, Not inspected, Bei\n[…]\nSHIP,\nBOSS-2 SHIP. A label-lock regression test guards the copy (mutation-proven).\n949 backend + 317 frontend green; ruff + mypy + build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Rewrite the live-surface labels into plain English (P1.4)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T20:00:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce04bbd341067367fb837aab64bfb1c2a38d5289",
          "body": "…route (P1.3)\n\nA live-tail row shows a per-request BOLA verdict, but a route can carry an OPEN\nfinding of ANOTHER family (tenant/BFLA/BOPLA/missing-auth), or an open BOLA\nCONFIRMED, while a given request looks calm (owner-access / public access). The\ntail had no cross-reference at all, and the Cover\n[…]\nCLEARED via the summary-strip redesign. Backend 949, frontend 316, root engine\ngreen; ruff + mypy + build clean; 4 fail-on-old mutation proofs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cross-reference open findings so no live row reads calm on a flagged …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T19:30:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b43784876c095444ece2ed4c94a83e1462f3354d",
          "body": "A NOT_VULNERABLE verdict is reached for reasons other than \"the caller owns\nthe object\": the object is public (read by many), the caller is a broad-access\nadmin, the caller is a proven tenant/group member, or the object is team-shared.\nThe live tail collapsed all of them into one \"owner-access\" chip\n[…]\nn),\nSecurity PASS (no findings), BOSS-2 SHIP. Backend 935, frontend 306, root engine\ngreen; ruff and mypy clean. Ledger LTV-TAIL-REASON closed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Surface the verdict reason on every live-tail row (P1.2, image-4 fix)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T18:31:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c462c0644ffabb958275cd2b58e1863c78d5d1e",
          "body": "The Coverage traffic-makeup bar parked requests that were DROPPED under load\nforever under \"Still classifying, usually judged within seconds\". The ingest path\ncounts every request in `hits` on arrival, but when the queue is full `submit()`\nsheds the event and it is never judged, so the seen-minus-ju\n[…]\ngreen.\n\nTriple-gated unanimous (Critics SHIP + Security PASS + BOSS-2 SHIP); both\nregression tests mutation-proven to fail on the old behavior.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Split dropped-under-load traffic out of \"still classifying\" (P1.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T17:23:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d565aae650cfb230f6b7adf1d960bdef364f2db",
          "body": "…ard plan\n\nThe live-traffic visibility feature is now live on prod, and after using it on\nreal connected apps the founder surfaced trust + UX concerns. A code investigation\nconfirmed two real honesty bugs (dropped-under-load requests parked forever as\n\"still classifying\"; the tail/makeup hide the ve\n[…]\nadmap and tracked bugs are never\nlost. Storage decision locked: durable aggregates only, never a per-request\nreal-id log (the anthem red line).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record live-traffic visibility deployed-live + store the trust/dashbo…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T17:20:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e24f3410579749befa5f30fcfc122b496a09f18",
          "body": "… re-audit\n\nAll five phases are done and each was gated: composition counters (P1),\nthe Coverage composition UI (P2), the ephemeral zero-persist tail backend\n(P3), and the live-tail console (P4). P5 re-verified the whole feature:\nboth CI suites green (root engine + backend 931), frontend clean, the \n[…]\nent capstone sign-off passed.\n\nRecords the whole-feature state in the plan build log and RUNNING_STAGE3.\nCommitted, not yet pushed or deployed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Mark live-traffic-visibility plan complete after the P5 whole-feature…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T13:20:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bce0ad5507c443ebcf9710ea3d6986db881260a1",
          "body": "The tail backend streams judged events per monitor; this is the console\nthat watches it. On the /live page each monitor row gains a \"Watch live\ntraffic\" toggle that opens a live feed of judged requests: per row a\ntimestamp, the caller reaching an object and that object's owner (the\nmetadata that ans\n[…]\n-proved the no-green\nguard), Design SHIP (5 fixes, including a real Tailwind-v4 border bug and\na truncated-identity-line fix, all re-verified).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add live-tail console to the /live monitor row (#2 UI)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T13:08:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7b4b5dd748d27dad0d03c8da658b1ba61e892b2",
          "body": "…ist (#2 backend)\n\nThe Coverage composition (#1) tells an owner the aggregate makeup of a\nroute's traffic. This adds the live counterpart: an owner can watch judged\nevents stream in real time (endpoint, verdict owner-access/cross-user/\nunresolved, and the caller/object/owner ids BoLD already receive\n[…]\nostgres LISTEN/NOTIFY) is deferred.\n\nTriple-gated: Security PASS (runtime-proved zero-persist + no connection\nheld), Critics SHIP, BOSS-2 SHIP.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add ephemeral live tail: owner-scoped SSE of judged events, zero-pers…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T12:49:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e1306d96e77f06040f3ed5547736fc0690e321c",
          "body": "Coverage could show a route was seen in live traffic, but not WHAT that\ntraffic was. A user could not tell whether requests were owners reaching\ntheir own objects or cross-user violations, and clean same-user access\nwas invisible entirely. This surfaces the makeup: expand a live route to\nsee a stack\n[…]\nated then reconciled: Critics SHIP (mutation-proven), Design\nrevise (applied), BOSS-2 SHIP after its one regression was fixed and\nre-confirmed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add per-endpoint live traffic-makeup drill-down to Coverage (#1 UI)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T12:05:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "430d7408aa20681503e900855a62b103b3d6ddc6",
          "body": "…-only)\n\nCoverage could show that an endpoint was seen in live traffic, but not\nwhat that traffic was: a user could not tell whether requests were owners\nreaching their own objects or cross-user violations, and clean same-user\naccess was invisible entirely. This surfaces that split WITHOUT a\npersist\n[…]\n\n(the live lens has no green branch at all). Fail-isolated: a counter error\nis logged and skipped, never touching the verdict or finding write.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add per-endpoint live-traffic health composition (aggregate, metadata…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T11:30:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3a693ccfd106262fef6aa24cbf013ff1ac6ebc42",
          "body": "A staging backend deploy job gated to a future 'staging' branch (inert on main), its fly.staging.toml targeting a separate Fly app + deploy token so it can never touch production, plus CODEOWNERS and CONTRIBUTING.md.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a staging deploy pipeline and contribution guardrails",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "38809438d4a47ec7e83f3018f3befdd33174ceb0",
          "body": "The gated frontier-expansion research (market numbers verified to primary sources, the OWASP agentic threat map, the competitive + pricing landscape, buyer/pain signal, and the moat-safe AI/ML workstreams), plus the reconciled findings, the pre-research checkpoint, the pitch-clarity brief, the desig\n[…]\nle record behind the permission-violation-alarm-for-the-AI-era positioning. (.docx originals stay local per the repo's standing *.docx ignore.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Scope-Expansion: frontier research, positioning, and GTM docs",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d129b78a47b717e13a909ed2459c2b96f58ef91",
          "body": "POSITIONING.md and PRICING.md were not git-ignored — a real risk of leaking the founder's private positioning and pricing into version control. Ignore them explicitly, and ignore agent working-memory wherever it lands (including under Scope-Expansion/).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Protect private strategy files from ever being committed",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d0adc31af7a08c364f0978cd393388a7836a2ed7",
          "body": "…rod)\n\nThe Authorization nav's \"Missing Auth\" entry, the command palette, and the\nconnect guide all link to /noauth, but no /noauth landing page existed --\nR5.5c built only /noauth/run/[pending_id] (the consent page reached from a\nprepared check). Every other authz family has a landing page; missing\n[…]\n\nsurface for other orphan/broken-link gaps -- none) + Security PASS. 279\nfrontend tests green; lint + build clean; /noauth is now a real route.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(noauth): add the missing /noauth landing page (dead nav link on p…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T15:18:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7ca467b72d3c6a24d7f51791ad56e4140e69316b",
          "body": "…y + orthogonality\n\nThe final R5 hardening phase. Three guards, then the family is code-complete.\n\nCOPY-HONESTY INVARIANT (BOSS-2's binding trust guard). R5-active is the softest\nCONFIRMED in the authorization family — its whole true-vs-false-positive\ndistance rests on the declaration-relative copy \n[…]\n the whole-family deploy sign-off). Folds the\nold R5.6. 912 backend + 273 frontend green; mypy + ruff + lint clean; crown\njewel byte-untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5f: close the missing-auth family — copy-honesty invariant + parit…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T14:36:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "845f09020424af027ffa117129e2e7e3ed27f296",
          "body": "Coverage: a missing-auth route earns GREEN only from an ACTIVE NOT_VULNERABLE\n(the seeded no-credential check refused on a declared route) -- \"noauth\" joins\n_ACTIVE_SOURCES. The passive \"noauth-live\" lens joins _LIVE_SOURCES so a missed\nlead is visible, but it can NEVER be green: the live lens's _li\n[…]\nCONCLUSIVE companion stays green, the\ndistinguishing catch). 883 backend + 270 frontend + mypy + ruff + lint clean;\nengine + testapp untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5e: missing-auth coverage-green + connect-guide ceilings",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:53:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80653657f2c966fecbe56e84c5a8749aae4cd37b",
          "body": "…mcp 0.11.0)\n\nbold_noauth_guide + bold_prepare_noauth_check + bold_noauth_status, mirroring\nthe shipped bopla/tenant MCP tools. The MCP is a thin client that drives the\nflow but is structurally incapable of crossing any anthem line:\n\n  - It NEVER handles a credential -- no session/credential field i\n[…]\nP tests +\ntsc clean. Docs cover R5.5c + R5.5d. NOT published -- 0.11.0 publish is\nfounder-gated behind the R5 backend deploy (R5-DEPLOY-ORDER).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5d: MCP orchestration for the missing-auth active check (@boldsec/…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:23:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6a241abf46a8a0cb1744814b0a4f3e306c88c376",
          "body": "The browser page (/noauth/run/[pending_id]) where the operator confirms the\nplan, supplies ONE authenticated seed session, affirms the route is meant to\nrequire auth (the D3 checkbox), and runs the active check. Mirrors the shipped\nbopla/tenant consent pages.\n\nThe anthem, in pixels: green is EARNED,\n[…]\ny me; Critics\nmutation-proved every rendering branch (null->green and CONFIRMED->neutral both\ngo red). 263 frontend tests + lint + build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5c: the missing-auth active-check consent + run UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:23:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "66f2828eb69b29380265a81151d32f4c1d305ad3",
          "body": "… path)\n\nR5-active is the only authorization sibling whose CONFIRMED carries no second\ncredential -- the whole true-vs-false-positive distance collapses onto the\noperator's one authRequired declaration, so a mis-declared public+seedable\nroute could manufacture a false CONFIRMED. The engine hardcodes\n[…]\nted by me, danger gate mutation-proven on every axis. Crown jewel\nuntouched. 876 backend + root-engine + 247 frontend green; mypy + ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5b: the active missing-auth check + THE DANGER GATE (the CONFIRMED…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T12:48:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fef31cb5fa7173a72525fa59fae0755406c7fe81",
          "body": "The R5.3 noauth-live passive lead persisted as a Finding but every product\nsurface still spoke BOLA for it: the explain card, the source badge, the\nfamily filter, and the finding-detail blurb all fell through to object-\nownership copy. That is a false-family-in-pixels failure -- the anthem bans a\nfi\n[…]\ntypes.\nTracked as R5-OPENAPI-DRIFT for a dedicated resync pass.\n\nCrown jewel untouched. 849 backend + 246 frontend green; mypy/ruff/lint clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5a: render the missing-auth passive lead truthfully on every surface",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T05:03:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e019eb743c0c9c2ac246a74abb37e5f7d2a625de",
          "body": "…spine)\n\nThe R5.3 noauth-live lead misfiled into the BOLA family bucket and rendered BOLA\ncopy. This threads is_noauth across every backend surface that branches on family,\nso a missing-auth finding is bucketed, badged, explained, fixed, reported, and\nnotified as missing-auth -- never BOLA. First R5\n[…]\n re-confirmed with a fail-on-old test) + Security PASS +\nBOSS-2 SHIP. Crown jewel decision.py untouched. 840 backend tests + ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5.0: give missing-auth its own finding-family identity (the model …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T04:20:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d083d3c4ced902eaf283431d109ff819d398eb0",
          "body": "…= protocol\n\nR5.2 widened RequestSender.unauthenticated_request with a keyword-only headers=\nargument (the R5 cache-prevent) but did not update two implementers, leaving them\nnon-conforming. The 3 mypy errors were latent on main since R5.2 because the mypy\nchecks in R5.2/R5.3 were scoped to app/live/ and the engine, never full app/. Add\nthe keyword-only headers param + pass it through on both. Full `mypy app/` clean again.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: conform OriginLockedSession/_Sender to the RequestSender headers…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T04:19:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3e821fd12974f792618fee0bd227232e8fb6103b",
          "body": "The last R5 phase, planned end-to-end and double-gated (Critics SHIP + BOSS-2\nSHIP) before any code. 7 sub-phases (R5.5.0 model spine -> a passive UI -> b\nactive backend + danger gate -> c consent UI -> d MCP -> e coverage/ceilings ->\nf hardening/discovery/claims), each grounded in the shipped BFLA/\n[…]\niscovery-surface parity (the R4.7 lesson), the family-branch\nsurfaces, and the connect-guide honesty (resolveCallerId ceiling + the N2 clause).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5: the end-to-end missing-auth product-surface plan (gated)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T03:34:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d5006f2549ff1555c7c7a4fd633737465fc7b90",
          "body": "The operator-facing half of R5. A per-route `authRequired?: boolean` on the SDK's\nBoldConfig, mirroring the shipped `privileged` (BFLA) flag exactly: when set, the\nSDK adds `route_auth_required: true` to the metadata event, which the R5.3 backend\nturns into a needs-review lead when a no-credential r\n[…]\nion 0.10.0 -> 0.11.0, BUILT NOT PUBLISHED: the R5.3 backend\nmust deploy first (IngestEvent is extra=\"forbid\", so an unshipped field would 422).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.4: add the @boldsec/next authRequired declaration for missing-auth",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T01:57:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0ddbf8a9e801880065031f7f671d04de9e5b91c",
          "body": "The live twin of R5.1's classifier and R5.2's active check. A real anonymous\nrequest (no credential) that succeeds on a route the operator DECLARED requires\nauth is now surfaced as a loud needs-review lead -- never a CONFIRMED, because\npassive traffic has no authenticated baseline to fingerprint aga\n[…]\nver forked).\nTriple-gated (Critics SHIP + Security PASS + BOSS-2 SHIP, all re-audited). Engine 716\n+ backend 819 tests green on fresh bytecode.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.3: add the passive/live missing-authorization lead",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T01:33:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f6ca4098cfe94419cfe34f9167f5ae29ea1bd5f8",
          "body": "R5 is the first BoLD check ever issued with NO credential, which opens a\nfalse-CONFIRMED hazard unique to it: an auth-keyless CDN could serve a cached\nauthenticated body back to the no-cred probe. The defense is structural, not a\ndetector. The no-credential probe is issued FIRST, on a fresh\nnever-be\n[…]\ns byte-untouched (classify_noauth unforked). Triple-gated\n(Critics SHIP + Security PASS + BOSS-2 SHIP, all re-audited). 690 engine tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.2: add the active missing-authorization check (no-credential probe)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T23:27:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "05197fcf0fc7c80f6b01af4afbf828dcdb33eba7",
          "body": "R5 catches missing authorization: a request that succeeded with no credential on a route the operator declared must require auth. It is the positive-detection twin of the engine's existing no-auth guard (G3) -- the same 'reachable with no credentials' signal that clears an object as public now incri\n[…]\nache-prevent are R5.2. Double-gated (Critics SHIP + Security PASS); 24 unit tests incl. a 300-case combinatorial grid; full engine suite green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add classify_noauth, the fifth authorization-family classifier (R5.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T22:10:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1faeddfeab551318fc63c18e3772ebf668556a4c",
          "body": "R4.8 hardened the tenant active check against a path-traversal hole where an operator-supplied id or path is interpolated into a request path. The same class was pre-existing in BOLA, BFLA, and BOPLA, and reached through the object_path_template / collection_path literals as well as the ids. Close i\n[…]\ntics double-gate (which between them found five stored-read sites neither found alone). Engine and backend suites green; decision.py unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Close the operator path-traversal class across all authz families (R4.9)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T12:59:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d37849bbb656b9a802848957903d1d7fa649c9da",
          "body": "The backend CI lint runs ruff over app/ AND tests/; a 102-char f-string in the new traversal test tripped E501 and failed the Backend job (so R4.8 did not deploy). Shorten the message under 100. No behavior change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reflow an over-long assertion message in the R4.8 backend test",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T05:05:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "abfc2bcc28eae5047d8f5d76dbed12157f8877f1",
          "body": "A path-based multi-tenant app (tenant in the URL, e.g. /api/tenants/{tenantId}/reports/{id}) crashed the tenant active check: object_path_template.format(id=...) supplied only `id`, so any other placeholder raised KeyError, escaped the EngineError guard, and became an unhandled 500 (\"try again\"). Re\n[…]\nnow shows the resolved path.\n\nCaught by the Security + Critics double-gate before ship. Engine and backend suites green; decision.py unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix tenant active-check crash on path-based multi-tenant apps (R4.8)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T04:58:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a347f3b275553eb591b04d379a90d7fb8d40819",
          "body": "R4 shipped tenant detection end to end but only into the surfaces where a finding is VIEWED (findings inbox, badge, detail, coverage). The surfaces where a user DISCOVERS and launches a check -- the Authorization nav dropdown, the Cmd-K palette, and the connect-guide -- still listed only BOLA/BFLA/B\n[…]\n in the nav tests so a future family cannot silently skip a discovery surface.\n\nFrontend-only; the engine, backend, and SDK are byte-unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wire tenant isolation into every discovery surface (R4.7)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T02:54:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8fde11eec19bd9fb2b77fe8201ca0ed665877f5",
          "body": "Both packages are now live on npm at 0.10.0 with tenant-isolation support in their SDK/MCP surfaces. Bump the versions and add \"tenant isolation\" to the package descriptions so the repo matches the registry.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record @boldsec/next + @boldsec/mcp 0.10.0 publish",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T02:54:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3194c2dcce2ffb2dfc2ca8ad17a15370c6d34ce",
          "body": "The closer for R4. tests/test_r46_orthogonality.py proves the two \"wrong\nstones\" the R4 gate named, at the engine (crown-jewel) layer the R4.3\npipeline suite did not reach:\n\n  #1 the false-CLEAN trap -- tenant-match is not \"safe\". A same-tenant\n  access to a DIFFERENT user's private object clears th\n[…]\nily is green\ntogether: engine + backend + frontend + @boldsec/next + @boldsec/mcp.\nDouble-gated: Critics SHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.6: the tenant orthogonality regression suite + closing hardening",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T01:55:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6bd9acc8803643bfc4fab7bd2e8483b1f7b84c51",
          "body": "Completes R4.5. bold_prepare_tenant_check + bold_tenant_status +\nbold_tenant_guide in @boldsec/mcp, mirroring the shipped BOPLA MCP.\nThe MCP is a thin client: it never reaches a verdict (classify_tenant\ndoes), and the two tenant sessions are never a tool argument -- the\nhuman pastes them into the br\n[…]\nre re-verify link and never\nsources an object.\n\nBackend and engine byte-unchanged. Double-gated: Critics SHIP +\nSecurity PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.5: the MCP tenant-isolation tools",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T01:23:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cccf16ee680666eb753e6dea55446b5fcf5822c3",
          "body": "Coverage tells the user, per route, what BoLD can honestly say. Its one\nrule: GREEN (\"verified safe on what BoLD can see\") is earned only by an\nactive check returning NOT_VULNERABLE, in the active lens; passive\nsilence has no path to green.\n\nThis wires tenant in without weakening that rule. The enti\n[…]\nge renders on state, never source, with\na neutral default). Engine byte-unchanged. Double-gated: Critics SHIP +\nSecurity PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.4: wire tenant isolation into Coverage",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T00:53:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0b4d0b110f492284d2333c73724921094eac5f27",
          "body": "R4.5.2 earns a CONFIRMED tenant finding; R4.5.3 is the surface a user\ndrives it from. Mirroring the shipped /bopla UI: a /tenant teaching +\nlaunch page, a consent + credential-handoff run page that collects the\nTWO throwaway-tenant sessions (owner + cross-tenant caller) and fresh\nattestation, a Tena\n[…]\nno\nconfirmed finding.\n\nFrontend-only; no backend or engine change. Triple-gated: Design\nAPPROVE + Critics SHIP + Security PASS, all re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.3: the active tenant-isolation check UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T00:27:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3f170e6cf478fc1cba82f7ba66d1cbf67c9073c3",
          "body": "R4.5.1 rendered tenant findings; R4.5.2 is where a CONFIRMED tenant\nfinding is earned. tenant_checks_api.py mirrors the shipped BOPLA active\ncheck: a 4-endpoint pending flow (prepare -> plan -> run -> status) that\nwires the R4.2 TenantOrchestrator to seed a throwaway object under one\ntest tenant, at\n[…]\nectly blocked\", a false-clean.\n\nclassify_tenant and the engine are byte-unchanged. Double-gated: Critics\nSHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.2: the active tenant-isolation check backend",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T23:50:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f994f0c9c761fdffc76327c3d80cc28d66643231",
          "body": "R4.3/R4.4 made the passive tenant lead fire and persist findings with\nsource=\"tenant-live\", but they rendered with BOLA \"another user's\nobject\" copy -- a wrong-family, honest-pixels violation. R4.5.1 makes\nTENANT a first-class finding family everywhere is_bopla/is_bfla are\nhandled: the badge (Tenant\n[…]\nr the BOLA tell) plus two mutation proofs confirm the tests bite.\n\nTriple-gated: Critics SHIP + Security PASS + Design APPROVE, all\nre-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.1: render tenant findings as a first-class family",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T23:01:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "74c8c56de31c713a5ad46713e0ad91c217de21aa",
          "body": "R4.3 gave the engine + backend a live tenant judge, but it was inert:\nnothing supplied caller_tenant/object_tenant on real traffic. R4.4 is\nthe SDK side — the wrapper now resolves and emits both, so the passive\ncross-tenant LEAD fires on a connected app.\n\nThree opt-in options mirror the owner/scope/\n[…]\nnly ever a needs-review LEAD, never a CONFIRMED.\n\nEngine + backend byte-unchanged. Double-gated: Critics SHIP + Security\nPASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.4: the @boldsec/next SDK tenant declaration/emission",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T21:58:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6dac1ee69ab7b26a0ce6739f5a154e1eef62d06a",
          "body": "The R4.2 active check only fires on our own seeded tenants. Real\ncustomer traffic needs a passive path that raises a needs-review LEAD\nwhen a caller in one tenant is seen reaching another tenant's object —\nbut the anthem forbids a passive CONFIRMED, so the lead must be\nstructurally incapable of ever\n[…]\nd (R4-CARRY-5 avoided).\nclassify_tenant is byte-unchanged — reused, never forked.\n\nDouble-gated: Critics SHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.3: the live/passive tenant-isolation lead",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T20:32:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c06166a08b440501c6c5183111d2e3d645e5bdd9",
          "body": "The tenant-isolation CONFIRMED path -- the fourth active check, a sibling of the BOLA/BFLA/BOPLA orchestrators. TenantReplaySession seeds a throwaway object as a tenant-A test account and attempts cross-tenant access as a tenant-B account; TenantOrchestrator runs it behind the same rails (permission\n[…]\nnt_a_id != tenant_b_id is enforced at construction. Double-gated (Critics SHIP + Security PASS). 20 machinery tests over a real mock transport.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.2: the active tenant-isolation check (engine)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T19:24:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2927a89e8a9dc285a79de7ab97ac3e8563e8588",
          "body": "classify_tenant's TG4 (public-endpoint guard) cleared a cross-tenant access as NOT_VULNERABLE on ANY unauthenticated 2xx-with-body response. Unlike BOLA's G3, it did not require the anonymous read to actually return the object (a fingerprint match with the owner's baseline). So an app answering unau\n[…]\nd no-false-CLEAN (0/0); reverting the fix reintroduces 1,260 grid false-cleans (fail-on-old). The three sibling classifiers are byte-unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix a soft-200 false-clean in classify_tenant (TG4 + new TG4c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T19:24:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04afaa1b6d0fc6fe3ca881b80739c17adeb50acc",
          "body": "Tenant/boundary isolation ('did a caller in tenant B reach tenant A's object?') needs its own verdict logic, but the crown jewel must never fork: classify_tenant is a pure SIBLING of classify/classify_privilege/classify_property, sharing the Verdict/Decision/Action spine and adding zero lines to the\n[…]\n SHIP + Security PASS); three independent stress grids (~4.6M cases) each found 0 false CONFIRMED; fail-on-old proven by mutating all 8 guards.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add classify_tenant, the 4th deterministic decision sibling (R4.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T16:52:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a69c05e7547ec088c8b2183c65725a5a1ee120c0",
          "body": "R4.0 (the R4 tenant research + convergence gate) ran: product + tech research, my re-audit, and an independent Critics BLOCK -- the gate working, not rubber-stamping. Captures the converged decisions (tenant CONFIRMED is active-only, sitting with BFLA/BOPLA; object_scope [A5 org-readability] is dist\n[…]\n1 fix + double-gate outcome + the anthem-required noise tradeoff. R4.0's blockers are cleared; the gate awaits founder go to lock + begin R4.1.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the R4.0 tenant-isolation gate + the B1 fix",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T13:51:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1db7bf1d6669769915ed8092319ff75de38ffbcc",
          "body": "On a scoped URL (/orgs/{org}/items/{id}) the SDK and backend auto-derive object_scope from the URL, so a per-user PRIVATE object read by a DIFFERENT same-org member (caller_in_scope=True) was exempted to NOT_VULNERABLE via ExemptReason.SCOPE -- silently clearing an intra-tenant BOLA. object_scope an\n[…]\n that encoded the false-clean are corrected (proven fail-on-old) + a learned-owner regression added. Double-gated: Security PASS, Critics SHIP.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Close a live A5/SCOPE false-clean: hold a per-user-owner conflict",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T13:50:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5904486e89967d937873d493dc6795409d599e53",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: log the ACTION->POST method-hint fix (METHOD-HINT)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:48:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "118bbf6cd7f8669257777b16879fc7af0ee3ab29",
          "body": "The frontend METHOD_BY_ACTION and backend _HTTP_BY_ACTION both re-declared\nthe action->HTTP-method map and both had drifted from the engine: a\nphantom CREATE and no ACTION. So a state-changing \"action\" finding (a\nrefund / share / invite / promote, which is exactly the shape of a\nprivileged BFLA func\n[…]\n sides are proven to\nfail on the old maps (they returned GET for an ACTION finding). Hint-line\nonly: no verdict, auth, or data surface changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: map the ACTION verb to POST in the AI-fix method hint",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:48:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38e138cae964ffcb30e4c6e16e9f3f25f040ae7e",
          "body": "… redesign\n\nRecord the two founder-reported BOPLA-surface fixes plus the BFLA-FIXCOPY\nfollow-up in the running log and the hardening ledger: BOPLA-FIXTHIS,\nBOPLA-CHIPS, BOPLA-REDOS (addressed inline), and BFLA-FIXCOPY (fixed, not\ndeferred). All double-gated.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: log the family-correct Fix this (BOPLA + BFLA) and consent chip…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6bdd4fab4d71a5155ebef7db08ca6d3951be9f1c",
          "body": "… amber\n\nThe declared-field chips painted \"write-protected\" with verdict-review,\nthe amber reserved for the \"needs review\" verdict. But these chips are\nthe subjects of the check, not a verdict, so the reuse was both\nsemantically wrong and read as AI-generated tag soup. Use one calm glass\nchip per fi\n[…]\nmeaning, so it never relies on\ncolor alone. Purely visual: the credential/consent/attestation logic is\nuntouched. Critics SHIP + Security PASS.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "bopla consent: premium glass field chips, gold accent not the verdict…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0694d7e80e561e3fd09b38849c520ddb5b39dbf2",
          "body": "…this\n\nA CONFIRMED BOPLA finding rendered only \"Verify your fix\" with no\nremediation: it presumed the user knew to allow-list the field but never\nshowed how. A CONFIRMED non-live BFLA fell through to the shared BOLA\nblock, showing ownership copy (reproduce/fix/AI prompt all said\n\"BOLA/IDOR ownership\n[…]\nktracking). Regression tests proven to fail on the old behavior.\nDouble-gated: Critics SHIP + Security PASS on both the BOPLA and BFLA\nchanges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "findings: give CONFIRMED BOPLA and BFLA their own family-correct Fix …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7a5dd6b72dd8aab3d97da0d931f5424a813b672",
          "body": "Log the two Findings changes, the Critics SHIP + Security PASS double-gate, and\nledger the now-orphaned /api/findings/suggest surface (DEAD-SUGGEST) as a safe\nbroom-pass follow-up per the founder's call to push now and clean up next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the findings overlay removal + type filter (both gates green)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ddb95496ecfb058032ed05f4cd7b4d1aa6e5d97c",
          "body": "The findings list already filters live as you type, so the floating autocomplete\ndropdown was a second, redundant overlay sitting on top of the real filtered\nlist. Replace it with a plain search input (the instant live filter, the\nshareable ?q= URL, and the no-flicker refetch are all unchanged) and \n[…]\nsing with the status filter and\nsearch via ?family=. An empty family-filtered view stays honest (\"never an\nall-clear\"); it never reads as safe.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Drop the redundant findings search overlay; add type-filter chips",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "997eb2cbe74f1fc01c4a58bcadbbe7add1662054",
          "body": "Add a family view-filter to the findings query, keyed off Finding.source\n(bfla/bfla-live -> BFLA, bopla/bopla-live -> BOPLA, else BOLA -- the same map as\nFinding.is_bfla/is_bopla, asserted to agree in tests so the filter and the\nsource badges can never disagree about a finding's family). It composes\n[…]\nnly: it never touches a verdict, \"All types\" hides nothing, and an\nunknown value falls back to \"all\" so a partial view can never read as clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Filter findings by authorization family (BOLA / BFLA / BOPLA)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1116328e576062bd9a67d54dd5db3c2037356cf8",
          "body": "The Settings > Developer MCP card and the other places that show the connect\ncommand still displayed the bare `npx @boldsec/mcp`, which npx can pin to a\nstale cached build (the drift that lost a client the BOPLA detector). Show\n`@boldsec/mcp@latest` everywhere a user can copy it, and add a \"Staying \n[…]\nupdate. Deliberately do not\nimply `status` verifies the running version (it only checks the connection), so\nnothing reads as a false all-clear.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Teach @latest and the restart-to-update step in the MCP setup UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-06T20:55:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45fc6bfcd3e369e16dd95312c6660b707c977918",
          "body": "Log the findings-search opacity fix and the MCP anti-drift fix, note the\nSecurity/Critics double-gate, and ledger the pin-exact-at-wire-time supply-chain\nhardening as a tracked founder decision. Also record that the live passive BOPLA\n\"needs review\" is correct by design (classify_property PRP4), not a defect.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the three prod fixes (search, MCP drift, BOPLA needs-review)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-06T20:37:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 0,
      "commits_last_year": 403,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 7,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "src/ideax/py.typed",
        "web/frontend/tsconfig.json",
        "web/sdk/bold-core/tsconfig.json",
        "web/sdk/bold-express/tsconfig.json",
        "web/sdk/bold-fastify/tsconfig.json",
        "web/sdk/bold-hono/tsconfig.json",
        "web/sdk/bold-koa/tsconfig.json",
        "web/sdk/bold-mcp/tsconfig.json",
        "web/sdk/bold-nestjs/tsconfig.json",
        "web/sdk/bold-next/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 245593,
      "source_files_sampled": 611,
      "oversized_source_files": 10,
      "agent_instruction_files": [
        "web/frontend/AGENTS.md",
        "web/frontend/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 327
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "ideax",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "fastapi",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.115"
        },
        {
          "name": "uvicorn",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.32"
        },
        {
          "name": "pydantic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.9"
        },
        {
          "name": "pydantic-settings",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "alembic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.14"
        },
        {
          "name": "asyncpg",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.30"
        },
        {
          "name": "aiosqlite",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.20"
        },
        {
          "name": "python-multipart",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.0.12"
        },
        {
          "name": "argon2-cffi",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=23.1"
        },
        {
          "name": "authlib",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.3"
        },
        {
          "name": "email-validator",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.2"
        },
        {
          "name": "itsdangerous",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.2"
        },
        {
          "name": "anthropic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.40"
        },
        {
          "name": "reportlab",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.2"
        },
        {
          "name": "python-docx",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1"
        },
        {
          "name": "@hookform/resolvers",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.0"
        },
        {
          "name": "@radix-ui/react-avatar",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.12"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.16"
        },
        {
          "name": "@radix-ui/react-dropdown-menu",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.17"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.9"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.9"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.5"
        },
        {
          "name": "class-variance-authority",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "cmdk",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "framer-motion",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.40.0"
        },
        {
          "name": "lucide-react",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.18.0"
        },
        {
          "name": "next",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "16.2.9"
        },
        {
          "name": "posthog-js",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.395.0"
        },
        {
          "name": "react",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.4"
        },
        {
          "name": "react-dom",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.4"
        },
        {
          "name": "react-hook-form",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.79.0"
        },
        {
          "name": "sonner",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "zod",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Sahith59",
          "commits": 401,
          "avatar_url": "https://avatars.githubusercontent.com/u/97082825?v=4"
        },
        {
          "type": "User",
          "login": "PranavNagothu",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/274616405?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "promote-to-production.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "49 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "06065e27b947b60ea3ca4e378a9f0d9c50ee7b4c",
        "ran_at": "2026-07-23T08:02:49Z",
        "aggregate_score": 2.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T15:06:37Z",
      "oldest_open_prs": [
        {
          "number": 3,
          "created_at": "2026-07-22T16:16:56Z",
          "last_comment_at": "2026-07-22T16:16:57Z",
          "last_comment_author": "vercel"
        }
      ],
      "last_merged_pr_at": "2026-07-22T15:00:50Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Sahith59/BoLD",
    "host": "github.com",
    "name": "BoLD",
    "owner": "Sahith59"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 40,
      "inputs": {
        "security": 23,
        "vitality": 36,
        "community": 22,
        "governance": 40,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 36,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "commits_last_year": 403,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "403 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 403
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 22,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 40,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Sahith59",
              "public_repos": 52,
              "account_age_days": 1661
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of Sahith59",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "Sahith59"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "52 public repos, account ~4 yr old",
                "points": 21.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 52
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://bold-lemon.vercel.app",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://bold-lemon.vercel.app",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 23,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 2.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "49 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "web/frontend/AGENTS.md",
                "web/frontend/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 327
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "web/frontend/AGENTS.md, web/frontend/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "web/frontend/AGENTS.md, web/frontend/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "src/ideax/py.typed",
                "web/frontend/tsconfig.json",
                "web/sdk/bold-core/tsconfig.json",
                "web/sdk/bold-express/tsconfig.json",
                "web/sdk/bold-fastify/tsconfig.json",
                "web/sdk/bold-hono/tsconfig.json",
                "web/sdk/bold-koa/tsconfig.json",
                "web/sdk/bold-mcp/tsconfig.json",
                "web/sdk/bold-nestjs/tsconfig.json",
                "web/sdk/bold-next/tsconfig.json"
              ],
              "agent_commit_share": 0.97,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "97 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 245593,
              "source_files_sampled": 611,
              "oversized_source_files": 10
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "10/611 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 611,
                      "oversized": 10
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'ideax' from its registry",
    "Could not fetch pypi package 'bold-backend' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T08:02:56.487773Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/Sahith59/BoLD.svg",
  "full_name": "Sahith59/BoLD",
  "license_state": "absent",
  "license_spdx": null
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计.