公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 10:40 UTC

YosefHayim / ebay-mcp

Local MCP server that exposes eBay Sell APIs to AI assistants with OAuth, tool gating, and stdio/HTTP transports.

TypeScriptMIT★ 105 星标⑂ 48 复刻始于 2025年11月在 GitHub 上查看 ↗

YosefHayim/ebay-mcp 的健康指数为 100 分中的 70 分,处于「良好」区间。 其得分最高的类别是Vitality(92/100),最低的是Sustainability & Governance(54/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。

70
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

70
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

YosefHayim个人账户
16 关注者12 个公开仓库始于 2024年8月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npmebay-mcp1.14.12,316345 天前mcpebayebay-apimodel-context-protocolai-toolsaillmdocumentationapiserverbackend

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

92优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
22.2/36提交节奏 — 52 周中有 32 周有提交
18/18提交量 — 最近一年 697 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year697
human_commit_share0.73
days_since_last_push5
active_weeks_last_year32

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 51 个发布版本
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 3.8 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count51
latest_release_tagv1.14.1
releases_from_tags
days_since_latest_release5
mean_days_between_releases3.8
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

65中等 · 占总体的 18%

流行度与采用

47存在风险
评分方式
32.7/60星标 — 105 个星标
13.9/25复刻 — 48 个复刻
0/15关注者 — 2 位关注者
所用输入
forks48
stars105
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
44.9/80月度下载量 — npm 合计每月 2,316 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesebay-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,316
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

54中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
2.4/22.5提交分布 — 头号贡献者编写了 89% 的提交
9.5/13.5贡献者广度 — 7 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled7
top_contributor_share0.892
评分方式
44/46.8议题解决 — 94% 的议题已关闭
26.2/38.3PR 接受 — 已裁定的 PR 中 85/124 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs85
open_issues1
closed_issues16
issue_closed_ratio0.941
closed_unmerged_prs39
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
8.8/25所有者影响力 — YosefHayim 有 16 位关注者
11.9/25既往记录 — 12 个公开仓库,账户约 1 年
所用输入
followers16
owner_typeUser
is_verified
owner_loginYosefHayim
public_repos12
account_age_days701
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 34 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesebay-mcp
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

82良好 · 占总体的 20%

工程实践

70良好
评分方式
24/24CI 工作流 — 11 个工作流
24/24存在测试
16/16Linter 配置 — biome.json
0/9.6Pre-commit 钩子
6.4/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.npmjs.com/package/ebay-mcp
10/10仓库描述
10/10主题标签 — 16 个主题标签
10/10Wiki
所用输入
topicschatgpt, claude, ebay, mcp-server, typescript, api-wrapper, ebay-api, mcp, model-context-protocol, npm, oauth2, ai-agents, cursor, local-first, nodejs, tool-gating
has_wiki
homepagehttps://www.npmjs.com/package/ebay-mcp
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

56中等 · 占总体的 16%

安全态势

48存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 10 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.8
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
13.2/25间接依赖不含已知公告 — 1 个受影响:@hono/node-server 1.19.15 (moderate 5.9)
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages194
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
比对的是 npm:ebay-mcp@1.14.1 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 194 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

76良好 · 占总体的 0%
评分方式
45/45代理指令 — .github/copilot-instructions.md, AGENTS.md, CLAUDE.md
15/15机器可读文档(llms.txt) — 存在 llms.txt
40/40可读的提交历史 — 73 次人类提交中有 72 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.986
agent_instruction_files.github/copilot-instructions.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes12,152
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — biome.json
11/11静态类型检查 — tsconfig.json, ui/tsconfig.json
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 29 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 2 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configstsconfig.json, ui/tsconfig.json
agent_commit_share0.29
toolchain_manifests
dependency_bot_commit_share0.02
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
53.2/55可控的文件大小 — 采样的 245 个源文件中有 8 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes507,840
source_files_sampled245
oversized_source_files8
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_files

关键数据

105GitHub 星标
7贡献者
697最近 12 个月提交数
5距最近推送天数
51发布版本数
1巴士系数(bus factor)
1开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 48 ⇿
0Star
48Fork
51发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

010203040504722025-112026-032026-07
主版本 1次版本 13修订 37
OpenSSF Scorecard 4.8 / 10
4.8综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 10:39 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
0CI-Tests0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities10 existing vulnerabilities detected
直接依赖 17
注册表软件包版本约束清单文件
npm@modelcontextprotocol/ext-apps1.7.4package.json
npm@modelcontextprotocol/sdk1.29.0package.json
npmchalk^5.6.2package.json
npmcors^2.8.6package.json
npmdotenv^17.4.2package.json
npmdotenv-stringify^3.0.1package.json
npmeffect^3.21.4package.json
npmexpress^5.2.1package.json
npmfast-xml-builder1.2.0package.json
npmfast-xml-parser^5.9.0package.json
npmhelmet^8.2.0package.json
npmjose^6.2.3package.json
npmprompts^2.4.2package.json
npmupdate-notifier^7.3.1package.json
npmwinston^3.19.0package.json
npmzod^3.25.76package.json
npmzod-to-json-schema^3.25.2package.json
全部依赖 442

来自 GitHub 依赖图的完整解析依赖集合:17 个直接依赖与 425 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@modelcontextprotocol/ext-apps1.7.4直接
npm@modelcontextprotocol/sdk1.29.0直接
npmchalk5.6.2直接
npmcors2.8.6直接
npmdotenv17.4.2直接
npmdotenv-stringify3.0.1直接
npmeffect3.21.4直接
npmexpress5.2.1直接
npmfast-xml-builder1.2.0直接
npmfast-xml-parser5.9.0直接
npmhelmet8.2.0直接
npmjose6.2.3直接
npmprompts2.4.2直接
npmupdate-notifier7.3.1直接
npmwinston3.19.0直接
npmzod3.25.76直接
npmzod-to-json-schema3.25.2直接
npm@babel/code-frame7.29.7间接
npm@babel/helper-string-parser7.29.7间接
npm@babel/helper-validator-identifier7.29.7间接
npm@babel/parser7.29.7间接
npm@babel/types7.29.7间接
npm@bcoe/v8-coverage1.0.2间接
npm@biomejs/biome2.5.1间接
npm@biomejs/cli-darwin-arm642.5.1间接
npm@biomejs/cli-darwin-x642.5.1间接
npm@biomejs/cli-linux-arm642.5.1间接
npm@biomejs/cli-linux-arm64-musl2.5.1间接
npm@biomejs/cli-linux-x642.5.1间接
npm@biomejs/cli-linux-x64-musl2.5.1间接
npm@biomejs/cli-win32-arm642.5.1间接
npm@biomejs/cli-win32-x642.5.1间接
npm@colors/colors1.6.0间接
npm@dabh/diagnostics2.0.8间接
npm@esbuild/aix-ppc640.28.1间接
npm@esbuild/android-arm0.28.1间接
npm@esbuild/android-arm640.28.1间接
npm@esbuild/android-x640.28.1间接
npm@esbuild/darwin-arm640.28.1间接
npm@esbuild/darwin-x640.28.1间接
npm@esbuild/freebsd-arm640.28.1间接
npm@esbuild/freebsd-x640.28.1间接
npm@esbuild/linux-arm0.28.1间接
npm@esbuild/linux-arm640.28.1间接
npm@esbuild/linux-ia320.28.1间接
npm@esbuild/linux-loong640.28.1间接
npm@esbuild/linux-mips64el0.28.1间接
npm@esbuild/linux-ppc640.28.1间接
npm@esbuild/linux-riscv640.28.1间接
npm@esbuild/linux-s390x0.28.1间接
npm@esbuild/linux-x640.28.1间接
npm@esbuild/netbsd-arm640.28.1间接
npm@esbuild/netbsd-x640.28.1间接
npm@esbuild/openbsd-arm640.28.1间接
npm@esbuild/openbsd-x640.28.1间接
npm@esbuild/openharmony-arm640.28.1间接
npm@esbuild/sunos-x640.28.1间接
npm@esbuild/win32-arm640.28.1间接
npm@esbuild/win32-ia320.28.1间接
npm@esbuild/win32-x640.28.1间接
npm@hono/node-server1.19.14间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@jridgewell/trace-mapping0.3.31间接
npm@mswjs/interceptors0.41.9间接
npm@noble/hashes1.8.0间接
npm@nodable/entities2.2.0间接
npm@nodelib/fs.scandir2.1.5间接
npm@nodelib/fs.stat2.0.5间接
npm@nodelib/fs.walk1.2.8间接
npm@open-draft/deferred-promise2.2.0间接
npm@open-draft/logger0.3.0间接
npm@open-draft/until2.1.0间接
npm@paralleldrive/cuid22.3.1间接
npm@pnpm/config.env-replace1.1.0间接
npm@pnpm/network.ca-file1.0.2间接
npm@pnpm/npm-conf3.0.3间接
npm@polka/url1.0.0-next.29间接
npm@redocly/ajv8.11.2间接
npm@redocly/config0.22.0间接
npm@redocly/openapi-core1.34.15间接
npm@rollup/rollup-android-arm-eabi4.62.0间接
npm@rollup/rollup-android-arm644.62.0间接
npm@rollup/rollup-darwin-arm644.62.0间接
npm@rollup/rollup-darwin-x644.62.0间接
npm@rollup/rollup-freebsd-arm644.62.0间接
npm@rollup/rollup-freebsd-x644.62.0间接
npm@rollup/rollup-linux-arm-gnueabihf4.62.0间接
npm@rollup/rollup-linux-arm-musleabihf4.62.0间接
npm@rollup/rollup-linux-arm64-gnu4.62.0间接
npm@rollup/rollup-linux-arm64-musl4.62.0间接
npm@rollup/rollup-linux-loong64-gnu4.62.0间接
npm@rollup/rollup-linux-loong64-musl4.62.0间接
npm@rollup/rollup-linux-ppc64-gnu4.62.0间接
npm@rollup/rollup-linux-ppc64-musl4.62.0间接
npm@rollup/rollup-linux-riscv64-gnu4.62.0间接
npm@rollup/rollup-linux-riscv64-musl4.62.0间接
npm@rollup/rollup-linux-s390x-gnu4.62.0间接
npm@rollup/rollup-linux-x64-gnu4.62.0间接
npm@rollup/rollup-linux-x64-musl4.62.0间接
npm@rollup/rollup-openbsd-x644.62.0间接
npm@rollup/rollup-openharmony-arm644.62.0间接
npm@rollup/rollup-win32-arm64-msvc4.62.0间接
npm@rollup/rollup-win32-ia32-msvc4.62.0间接
npm@rollup/rollup-win32-x64-gnu4.62.0间接
npm@rollup/rollup-win32-x64-msvc4.62.0间接
npm@so-ric/colorspace1.1.6间接
npm@standard-schema/spec1.1.0间接
npm@types/body-parser1.19.6间接
npm@types/chai5.2.3间接
npm@types/configstore6.0.2间接
npm@types/connect3.4.38间接
npm@types/cookiejar2.1.5间接
npm@types/cors2.8.19间接
npm@types/deep-eql4.0.2间接
npm@types/estree1.0.9间接
npm@types/express5.0.6间接
npm@types/express-serve-static-core5.1.1间接
npm@types/http-errors2.0.5间接
npm@types/methods1.1.4间接
npm@types/node25.9.3间接
npm@types/prompts2.4.9间接
npm@types/qs6.15.1间接
npm@types/range-parser1.2.7间接
npm@types/react19.2.17间接
npm@types/react-dom19.2.3间接
npm@types/send1.2.1间接
npm@types/serve-static2.2.0间接
npm@types/superagent8.1.10间接
npm@types/supertest7.2.0间接
npm@types/triple-beam1.3.5间接
npm@types/update-notifier6.0.8间接
npm@vitest/coverage-v84.1.9间接
npm@vitest/expect4.1.9间接
npm@vitest/mocker4.1.9间接
npm@vitest/pretty-format4.1.9间接
npm@vitest/runner4.1.9间接
npm@vitest/snapshot4.1.9间接
npm@vitest/spy4.1.9间接
npm@vitest/ui4.1.9间接
npm@vitest/utils4.1.9间接
npmaccepts2.0.0间接
npmagent-base7.1.4间接
npmajv8.20.0间接
npmajv-formats3.0.1间接
npmansi-align3.0.1间接
npmansi-colors4.1.3间接
npmansi-regex5.0.1间接
npmansi-regex6.2.2间接
npmansi-styles6.2.3间接
npmanymatch3.1.3间接
npmanynum1.0.0间接
npmargparse2.0.1间接
npmarray-union2.1.0间接
npmasap2.0.6间接
npmassertion-error2.0.1间接
npmast-v8-to-istanbul1.0.4间接
npmasync3.2.6间接
npmasynckit0.4.0间接
npmatomically2.1.1间接
npmbalanced-match1.0.2间接
npmbinary-extensions2.3.0间接
npmbody-parser2.3.0间接
npmboxen7.1.1间接
npmboxen8.0.1间接
npmbrace-expansion2.1.1间接
npmbraces3.0.3间接
npmbytes3.1.2间接
npmcall-bind-apply-helpers1.0.2间接
npmcall-bound1.0.4间接
npmcamelcase7.0.1间接
npmcamelcase8.0.0间接
npmchai6.2.2间接
npmchange-case5.4.4间接
npmchokidar3.6.0间接
npmcli-boxes3.0.0间接
npmcolor5.0.3间接
npmcolor-convert3.1.3间接
npmcolor-name2.1.0间接
npmcolor-string2.1.4间接
npmcolorette1.4.0间接
npmcombined-stream1.0.8间接
npmcommander9.5.0间接
npmcomponent-emitter1.3.1间接
npmconfig-chain1.1.13间接
npmconfigstore7.1.0间接
npmcontent-disposition1.1.0间接
npmcontent-type1.0.5间接
npmcontent-type2.0.0间接
npmconvert-source-map2.0.0间接
npmcookie0.7.2间接
npmcookie-signature1.2.2间接
npmcookiejar2.1.4间接
npmcross-spawn7.0.6间接
npmcsstype3.2.3间接
npmdebug4.4.3间接
npmdeep-extend0.6.0间接
npmdelayed-stream1.0.0间接
npmdepd2.0.0间接
npmdezalgo1.0.4间接
npmdir-glob3.0.1间接
npmdot-prop9.0.0间接
npmdunder-proto1.0.1间接
npmeastasianwidth0.2.0间接
npmee-first1.1.1间接
npmemoji-regex10.6.0间接
npmemoji-regex8.0.0间接
npmemoji-regex9.2.2间接
npmenabled2.0.0间接
npmencodeurl2.0.0间接
npmes-define-property1.0.1间接
npmes-errors1.3.0间接
npmes-module-lexer2.1.0间接
npmes-object-atoms1.1.2间接
npmes-set-tostringtag2.1.0间接
npmesbuild0.28.1间接
npmescape-goat4.0.0间接
npmescape-html1.0.3间接
npmestree-walker3.0.3间接
npmetag1.8.1间接
npmeventsource3.0.7间接
npmeventsource-parser3.1.0间接
npmexpect-type1.3.0间接
npmexpress-rate-limit8.5.2间接
npmfast-check3.23.2间接
npmfast-deep-equal3.1.3间接
npmfast-glob3.3.3间接
npmfast-safe-stringify2.1.1间接
npmfast-uri3.1.2间接
npmfastq1.20.1间接
npmfdir6.5.0间接
npmfecha4.2.3间接
npmfflate0.8.3间接
npmfill-range7.1.1间接
npmfinalhandler2.1.1间接
npmflatted3.4.2间接
npmfn.name1.1.0间接
npmform-data4.0.6间接
npmformidable3.5.4间接
npmforwarded0.2.0间接
npmfresh2.0.0间接
npmfsevents2.3.3间接
npmfunction-bind1.1.2间接
npmget-east-asian-width1.6.0间接
npmget-intrinsic1.3.0间接
npmget-proto1.0.1间接
npmget-tsconfig4.14.0间接
npmglob-parent5.1.2间接
npmglobal-directory4.0.1间接
npmglobby11.1.0间接
npmgopd1.2.0间接
npmgraceful-fs4.2.10间接
npmgraceful-fs4.2.11间接
npmhas-flag4.0.0间接
npmhas-symbols1.1.0间接
npmhas-tostringtag1.0.2间接
npmhasown2.0.4间接
npmhono4.12.25间接
npmhtml-escaper2.0.2间接
npmhttp-errors2.0.1间接
npmhttps-proxy-agent7.0.6间接
npmhusky9.1.7间接
npmiconv-lite0.7.2间接
npmignore5.3.2间接
npmindex-to-position1.2.0间接
npminherits2.0.4间接
npmini1.3.8间接
npmini4.1.1间接
npmip-address10.2.0间接
npmipaddr.js1.9.1间接
npmis-binary-path2.1.0间接
npmis-extglob2.1.1间接
npmis-fullwidth-code-point3.0.0间接
npmis-glob4.0.3间接
npmis-in-ci1.0.0间接
npmis-installed-globally1.0.0间接
npmis-node-process1.2.0间接
npmis-npm6.1.0间接
npmis-number7.0.0间接
npmis-path-inside4.0.0间接
npmis-promise4.0.0间接
npmis-stream2.0.1间接
npmis-unsafe1.0.1间接
npmisexe2.0.0间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-report3.0.1间接
npmistanbul-reports3.2.0间接
npmjs-levenshtein1.1.6间接
npmjs-tokens10.0.0间接
npmjs-tokens4.0.0间接
npmjs-yaml4.2.0间接
npmjson-schema-traverse1.0.0间接
npmjson-schema-typed8.0.2间接
npmjson-stringify-safe5.0.1间接
npmkleur3.0.3间接
npmkuler2.0.0间接
npmky1.14.3间接
npmlatest-version9.0.0间接
npmlogform2.7.0间接
npmmagic-string0.30.21间接
npmmagicast0.5.3间接
npmmake-dir4.0.0间接
npmmath-intrinsics1.1.0间接
npmmedia-typer1.1.0间接
npmmerge-descriptors2.0.0间接
npmmerge21.4.1间接
npmmethods1.1.2间接
npmmicromatch4.0.8间接
npmmime2.6.0间接
npmmime-db1.52.0间接
npmmime-db1.54.0间接
npmmime-types2.1.35间接
npmmime-types3.0.2间接
npmminimatch5.1.9间接
npmminimist1.2.8间接
npmmrmime2.0.1间接
npmms2.1.3间接
npmmylas2.1.14间接
npmnanoid3.3.12间接
npmnegotiator1.0.0间接
npmnock14.0.15间接
npmnormalize-path3.0.0间接
npmobject-assign4.1.1间接
npmobject-inspect1.13.4间接
npmobug2.1.3间接
npmon-finished2.4.1间接
npmonce1.4.0间接
npmone-time1.0.0间接
npmopenapi-typescript7.13.0间接
npmoutvariant1.4.3间接
npmpackage-json10.0.1间接
npmparse-json8.3.0间接
npmparseurl1.3.3间接
npmpath-expression-matcher1.5.0间接
npmpath-key3.1.1间接
npmpath-to-regexp8.4.2间接
npmpath-type4.0.0间接
npmpathe2.0.3间接
npmpicocolors1.1.1间接
npmpicomatch2.3.2间接
npmpicomatch4.0.4间接
npmpkce-challenge5.0.1间接
npmplimit-lit1.6.1间接
npmpluralize8.0.0间接
npmpostcss8.5.15间接
npmpropagate2.0.1间接
npmproto-list1.2.4间接
npmproxy-addr2.0.7间接
npmpupa3.3.0间接
npmpure-rand6.1.0间接
npmqs6.15.2间接
npmqueue-lit1.5.2间接
npmqueue-microtask1.2.3间接
npmrange-parser1.2.1间接
npmraw-body3.0.2间接
npmrc1.2.8间接
npmreact19.2.7间接
npmreact-dom19.2.7间接
npmreadable-stream3.6.2间接
npmreaddirp3.6.0间接
npmregistry-auth-token5.1.1间接
npmregistry-url6.0.1间接
npmrequire-from-string2.0.2间接
npmresolve-pkg-maps1.0.0间接
npmreusify1.1.0间接
npmrollup4.62.0间接
npmrouter2.2.0间接
npmrun-parallel1.2.0间接
npmsafe-buffer5.2.1间接
npmsafe-stable-stringify2.5.0间接
npmsafer-buffer2.1.2间接
npmscheduler0.27.0间接
npmsemver7.8.4间接
npmsend1.2.1间接
npmserve-static2.2.1间接
npmsetprototypeof1.2.0间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmside-channel1.1.1间接
npmside-channel-list1.0.1间接
npmside-channel-map1.0.1间接
npmside-channel-weakmap1.0.2间接
npmsiginfo2.0.0间接
npmsirv3.0.2间接
npmsisteransi1.0.5间接
npmslash3.0.0间接
npmsource-map-js1.2.1间接
npmstack-trace0.0.10间接
npmstackback0.0.2间接
npmstatuses2.0.2间接
npmstd-env4.1.0间接
npmstrict-event-emitter0.5.1间接
npmstring-width4.2.3间接
npmstring-width5.1.2间接
npmstring-width7.2.0间接
npmstring_decoder1.3.0间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.2.0间接
npmstrip-json-comments2.0.1间接
npmstrnum2.4.0间接
npmstubborn-fs2.0.0间接
npmstubborn-utils1.0.2间接
npmsuperagent10.3.0间接
npmsupertest7.2.2间接
npmsupports-color10.2.2间接
npmsupports-color7.2.0间接
npmtext-hex1.0.0间接
npmtinybench2.9.0间接
npmtinyexec1.2.4间接
npmtinyglobby0.2.17间接
npmtinyrainbow3.1.0间接
npmto-regex-range5.0.1间接
npmtoidentifier1.0.1间接
npmtotalist3.0.1间接
npmtriple-beam1.4.1间接
npmtsc-alias1.8.17间接
npmtsx4.22.4间接
npmtype-fest2.19.0间接
npmtype-fest4.41.0间接
npmtype-is2.1.0间接
npmtypescript5.9.3间接
npmundici-types7.24.6间接
npmunpipe1.0.0间接
npmuri-js-replace1.0.1间接
npmutil-deprecate1.0.2间接
npmvary1.1.2间接
npmvite7.3.5间接
npmvite-plugin-singlefile2.3.3间接
npmvitest4.1.9间接
npmwhen-exit2.1.5间接
npmwhich2.0.2间接
npmwhy-is-node-running2.3.0间接
npmwidest-line4.0.1间接
npmwidest-line5.0.0间接
npmwinston-transport4.9.0间接
npmwrap-ansi8.1.0间接
npmwrap-ansi9.0.2间接
npmwrappy1.0.2间接
npmxdg-basedir5.1.0间接
npmxml-naming0.1.0间接
npmyaml-ast-parser0.0.43间接
npmyargs-parser21.1.1间接
依赖安全公告 1

安装 npm:ebay-mcp@1.14.1 会引入 194 个包(直接与传递):其中 1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
@hono/node-server1.19.15间接12.0.5

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "chatgpt",
        "claude",
        "ebay",
        "mcp-server",
        "typescript",
        "api-wrapper",
        "ebay-api",
        "mcp",
        "model-context-protocol",
        "npm",
        "oauth2",
        "ai-agents",
        "cursor",
        "local-first",
        "nodejs",
        "tool-gating"
      ],
      "is_fork": false,
      "size_kb": 13761,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/ebay-mcp",
      "languages": {
        "CSS": 4837,
        "HTML": 1195,
        "Shell": 6826,
        "Dockerfile": 1193,
        "JavaScript": 92316,
        "TypeScript": 4178261
      },
      "pushed_at": "2026-07-19T13:51:13Z",
      "created_at": "2025-11-09T06:05:17Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T13:06:30Z",
      "description": "Local MCP server that exposes eBay Sell APIs to AI assistants with OAuth, tool gating, and stdio/HTTP transports.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://yosefhayimsabag.com",
      "name": null,
      "type": "User",
      "login": "YosefHayim",
      "company": null,
      "location": "Israel, HaMarkeZ, Tel Aviv",
      "followers": 16,
      "avatar_url": "https://avatars.githubusercontent.com/u/179159376?v=4",
      "created_at": "2024-08-22T17:23:42Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 701
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.14.1",
          "kind": "patch",
          "published_at": "2026-07-19T13:07:45Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-07-19T11:57:14Z"
        },
        {
          "tag": "v1.13.3",
          "kind": "patch",
          "published_at": "2026-07-04T01:27:09Z"
        },
        {
          "tag": "v1.13.2",
          "kind": "patch",
          "published_at": "2026-07-01T23:59:57Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2026-06-25T18:25:43Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-06-25T18:13:31Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-06-16T16:56:55Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2026-06-15T18:22:33Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-06-15T16:04:00Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-06-15T15:36:29Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-06-15T15:04:09Z"
        },
        {
          "tag": "v1.8.10",
          "kind": "patch",
          "published_at": "2026-05-23T10:54:34Z"
        },
        {
          "tag": "v1.8.9",
          "kind": "patch",
          "published_at": "2026-05-09T17:52:28Z"
        },
        {
          "tag": "v1.8.8",
          "kind": "patch",
          "published_at": "2026-04-26T10:08:28Z"
        },
        {
          "tag": "v1.8.6",
          "kind": "patch",
          "published_at": "2026-04-23T14:44:23Z"
        },
        {
          "tag": "v1.8.5",
          "kind": "patch",
          "published_at": "2026-03-21T02:43:50Z"
        },
        {
          "tag": "v1.8.4",
          "kind": "patch",
          "published_at": "2026-03-16T15:36:12Z"
        },
        {
          "tag": "v1.8.3",
          "kind": "patch",
          "published_at": "2026-03-16T14:00:02Z"
        },
        {
          "tag": "v1.8.2",
          "kind": "patch",
          "published_at": "2026-03-16T13:45:50Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2026-03-16T13:42:06Z"
        },
        {
          "tag": "v1.7.9",
          "kind": "patch",
          "published_at": "2026-03-16T07:22:13Z"
        },
        {
          "tag": "v1.7.8",
          "kind": "patch",
          "published_at": "2026-03-16T07:19:42Z"
        },
        {
          "tag": "v1.7.7",
          "kind": "patch",
          "published_at": "2026-03-16T06:51:48Z"
        },
        {
          "tag": "v1.7.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:44:42Z"
        },
        {
          "tag": "v1.7.5",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:26Z"
        },
        {
          "tag": "v1.7.4",
          "kind": "patch",
          "published_at": "2026-03-04T23:11:03Z"
        },
        {
          "tag": "v1.7.3",
          "kind": "patch",
          "published_at": "2026-02-28T15:12:09Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:59Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-02-04T22:10:45Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-02-04T22:01:07Z"
        },
        {
          "tag": "v1.6.4",
          "kind": "patch",
          "published_at": "2026-02-04T21:51:30Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2026-02-04T21:41:37Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-01-09T12:09:45Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-01-08T01:52:30Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:25Z"
        },
        {
          "tag": "v1.4.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:24Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:22Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:19Z"
        },
        {
          "tag": "v1.1.8",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:18Z"
        },
        {
          "tag": "v1.1.7",
          "kind": "patch",
          "published_at": "2025-11-12T19:56:16Z"
        },
        {
          "tag": "v1.1.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:17Z"
        },
        {
          "tag": "v1.1.5",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:17Z"
        },
        {
          "tag": "v1.1.4",
          "kind": "patch",
          "published_at": "2025-11-12T14:37:20Z"
        },
        {
          "tag": "v1.1.3",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:53Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:40Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:29Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-11-12T14:36:21Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2025-11-12T14:36:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0a23f966e50695e7bb1087ee4e71ae9a03a85da5",
          "body": "Record marketing/inventory splits, setup re-home, OpenAPI path fix,\nand docs truth-up for the 1.14.1 patch release.",
          "is_bot": false,
          "headline": "docs(changelog): backfill v1.14.1 structure cleanup notes",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T13:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47d95fd139affcae71510969c7dfc26c91eba5b9",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.14.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T13:05:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eda16bd5851ef4c14c47d2a3cd0242be6e22ca2a",
          "body": "…x typo (#138 #139 #140)\n\n- Split Marketing API/schemas into campaigns/ads/promotions/reports (+ facade/barrel)\n- Split Inventory API into items/offers/locations (+ facade)\n- Re-home setup wizard/validator/security/scope helpers into scripts/; oauthHelper into auth/\n- Rename generated markeitng-and-promotions → marketing-and-promotions (sync maps already correct)\n\nPublic MCP tool names and api.marketing.*/api.inventory.* method names stay stable.",
          "is_bot": false,
          "headline": "chore: close structure backlog — split god modules, re-home setup, fi…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T12:54:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f5f1af7479e805d99b248a43b1ef92a335a9252",
          "body": "…locales\n\nCollapse definitions/tool-handlers husks into tools/types.ts, archive stale\narchitecture notes and plans, drop the one-off trading smoke script, document\nfamily/schema ownership, and align locale READMEs with Compliance decommission\nclaims. Large module splits tracked in #138–#140.",
          "is_bot": false,
          "headline": "chore: structure cleanup — collocate tool types, truth-up docs, sync …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T12:37:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "653718a8f1be7f8172045b01ea90ee4f4251d364",
          "body": "Ship unreleased work since v1.13.3: fork-inspired deploy/read-only/finding/CS\nfeatures, Effect schema migration, and dead Negotiation/Compliance tool fixes.",
          "is_bot": false,
          "headline": "chore(release): v1.14.0",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T11:56:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f38980616ff29fbd5cb6b05a5728d4bb56d332e",
          "body": "Confirm ebay_get_offers_to_buyers stays off the registry (nonexistent\nNegotiation endpoint) and make Compliance listing-violation tools fail\nfast with a clear decommission message instead of a bare eBay 404.",
          "is_bot": false,
          "headline": "fix: handle dead Negotiation and Compliance tools (#136, #137)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T11:56:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f4627d0957c2a5d5deae3b520dc930fdca03b29",
          "body": "Adopt high-value patterns from community forks without taking their\nproduct-specific shortcuts: container-friendly HTTP (PORT, 0.0.0.0,\nMCP_AUTH_TOKEN), Accept-Language + richer eBay error bodies, EBAY_READ_ONLY\ntool filtering, Basic-auth token introspection, Finding sold comps via\nbrowse, and Fulfillment cancellation/refund scans for seller CS.\n\nVerified locally with act (biome, typecheck, unit+integration, build).",
          "is_bot": false,
          "headline": "feat: fork-inspired deploy, locale, read-only, finding, and CS tools",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-18T18:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bbcdc7c7c5b44401933b6bf0113ea20d86c07a6",
          "body": null,
          "is_bot": false,
          "headline": "refactor: migrate tool schemas to effect adapter",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T05:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "884e108d4b3cafb9637a8f9b37e9c1738bc64148",
          "body": null,
          "is_bot": false,
          "headline": "refactor: align code with style guide",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T04:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecb39f1b8ce34c0aa8a872e44d3b3c4d7d0f76de",
          "body": null,
          "is_bot": false,
          "headline": "refactor: extract eBay rate limit tracker",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:22:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e859a6ddd897b2cac9b937ef04b1f5b8b6c19bea",
          "body": null,
          "is_bot": false,
          "headline": "fix: wire typed API error modules",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c4b129557b28d418bcde19120b466236160d27d",
          "body": null,
          "is_bot": false,
          "headline": "fix: add typed API error modules",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:20:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb09d0560d7f472e41f76f44e5d13fe959217ed6",
          "body": null,
          "is_bot": false,
          "headline": "docs: clarify trading schema docs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3824fa487543abb96ae0588c87f044bc26d0491",
          "body": null,
          "is_bot": false,
          "headline": "fix: align eBay API Effect call sites",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd9280d522fb0b3d75c075c59cf6ba83bbd7554a",
          "body": null,
          "is_bot": false,
          "headline": "fix: align auth and trading tests",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:14:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "147edbda4910898ce067db6fd2e7575982ed9960",
          "body": null,
          "is_bot": false,
          "headline": "fix: type eBay API auth failures",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:11:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27e0d8feb905945a411d1f43ee35080bf348149d",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README hero and polish structure",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:07:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94c1ab69c0f0b0940366d81415abaaa87561a631",
          "body": null,
          "is_bot": false,
          "headline": "fix: correct ppnpm typo in CI workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T21:07:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3aef79c50f75cdb6faf7acfe553ad6c9796a06c",
          "body": "- Replace npm/package-lock.json with pnpm/pnpm-lock.yaml\n- Add packageManager field to package.json\n- Update scripts: npm run → pnpm, npx → pnpm exec\n- Workflows: add pnpm/action-setup@v4, cache: pnpm, pnpm install --frozen-lockfile",
          "is_bot": false,
          "headline": "chore: migrate to pnpm, update CI workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T21:01:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f2fc1f1cc97d1de9660f2b76da5fd0bc38f3ee7",
          "body": "…k, report-failure, ci)\n\nSynced from the canonical dufflebag/alg workflow set. Each workflow is\nsingle-purpose and reusable (workflow_call). ci.yml orchestrates them and\ngates merges via the CI Gate job.",
          "is_bot": false,
          "headline": "ci: add missing workflow templates (biome, build, e2e, test, typechec…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T19:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1c633da2d21ac8adfff8e7b403de86f197722fd",
          "body": "- Document scripts/dev/ convention in CODE-STYLE.md\n- Add scripts/dev/ to .gitignore so local dev scripts stay local",
          "is_bot": false,
          "headline": "chore: organize dev scripts into scripts/dev/ (gitignored)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T14:00:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e2d600cfefd8b8f262b297e14af4b581042be1d",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-04T01:26:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aaf9c269985e2141e44dd5382a99df3fd834e17",
          "body": "…d code (#133)\n\n* chore: close the style backlog — @/ imports, ui in the gate, drop dead code\n\nFollow-up burndown of the backlog #132 deferred (recorded in ADR 0006):\n\n- Codemod all 66 `../` parent imports to the `@/` alias, path-resolved and\n  typecheck-verified (Rule 1 → 0 violations)\n- Delete orp\n[…]\n\ntests pass, build ok (emits build/ui/stat.html).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: close the style backlog — @/ imports, ui in the gate, drop dea…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T01:25:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a6a1f380ad2d24f4017b90af71ddb212db4e317",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add verify script chaining the full check + build gate",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-02T20:47:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "18ca39ed6dde17e38050d8d698a413f97e3bbbd4",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T23:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "296fe19d0b43033d6a0b06a11740c04ecde99859",
          "body": "…as a reusable gate (#132)\n\nCodifies how the repo is built (docs + config) and replaces the ad-hoc GitHub\nActions with a reusable single-purpose gate. Docs record the desired end-state;\nexisting code is evidence. No runtime code moves.\n\nDocs\n- Add CODE-STYLE.md (style SSOT), CONTEXT.md, LANGUAGE.md,\n[…]\nte weekly-unit-tests.yml.\n\nValidated green: typecheck, biome ci (0 errors / ~1226 warnings), unit (1120),\nintegration (33), build.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add code-style + structure docs, fix Biome config, rebuild CI …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-01T23:57:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "741517fdf75e714dd40e9e600d9eb79a530f2c9b",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: apply biome format and lint fixes",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-27T21:29:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "92c8fc81d7cb44b6beec5f107258a2a1a2cc475c",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-25T18:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e969e0a93aec811a4161659a71607be9f60a7d09",
          "body": "@redocly/openapi-core (transitive via openapi-typescript, dev-scope) pinned\njs-yaml 4.1.1, vulnerable to a quadratic-complexity DoS in merge-key handling\nvia repeated aliases (GHSA-h67p-54hq-rp68, Dependabot alert #171). Adds a pnpm\noverride forcing js-yaml >=4.2.0, matching the existing esbuild/yaml override\npattern, and extends the supply-chain guard test to pin it.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): force js-yaml >=4.2.0 to patch GHSA-h67p-54hq-rp68 DoS (#131)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-25T18:23:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2583be9eb0e3ebbcaee8714fb3cf670763cbd1cd",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-25T18:12:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f26464ffc37e1305323a27202ff33bfbcfac972e",
          "body": "…ontext (#130)\n\n* feat(tools): gate tool exposure via EBAY_MCP_TOOLS to control agent context\n\nPreviously all ~187 tools were advertised in a single tools/list on every\nconnect, loading the full catalogue (descriptions + Zod schemas) into every\nagent's context window. This adds an opt-in EBAY_MCP_TO\n[…]\n rather than hard-coding its opaque '2' encoding.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(tools): gate tool exposure via EBAY_MCP_TOOLS to control agent c…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-25T18:11:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2da9b717f766368df0bbeb908c7fdc71bbad0b61",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.12.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-16T16:56:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dc5619240903d08928ecbf33acdcb75504ea586",
          "body": "… (#129)\n\n* feat(ui): add opt-in interactive MCP Apps UI layer\n\nRender 13 core read tools as interactive table / card / chart views via\nself-contained `ui://` HTML resources, gated by host capability and an\n`EBAY_MCP_UI=off` kill-switch. Hosts without MCP Apps support (e.g. Cursor)\nfall back to the \n[…]\nnt the EBAY_MCP_UI on/off toggle in .env.example.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ui): opt-in interactive MCP Apps UI layer (table / card / chart)…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-16T16:54:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c4fafd1b567a3d2bf85a2d4758a6d608586810a",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.11.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T18:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01377bdb6237c2fb61ce2dce1befe0908282ec9e",
          "body": "…8n (#128)\n\nRestructure the English README into a launch-style landing page: centered\nhero banner, drift-free shields badges (npm version/downloads, CI, MIT,\nNode, TypeScript + 322-tools / 100%-coverage / MCP stat badges), feature\nlist, an \"eBay MCP vs. raw eBay REST API\" comparison table, an anchor\n[…]\nhe real\nsrc/tools/categories/* paths, and add comparison/translation context.\n\nAdd public/ebay-mcp-hero.png (optimized to 1400px).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): overhaul landing docs with hero, badges, and tracked i1…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T18:20:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eff2b8575809ba240138d64b3639cbbff83b1e7e",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.11.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T16:03:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "810e3c79af8cdc31ac70329638f9a2dac8a8151a",
          "body": "…Cursor (#125)\n\nGenerate 'using' (drive-the-tools) and 'contributing' (work-on-the-repo)\nskills from one canonical source into each tool's native format — Claude\nCode SKILL.md, Cursor .cursor/rules/*.mdc, and a Codex AGENTS.md managed\nblock — with the live tool registry (322 tools, 13 families) inje\n[…]\nion, registry snapshot, and\n  the write-safety invariants (idempotency, preservation, foreign-skip,\n  dry-run, two-layer compose).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skills): add agent-skills installer for Codex, Claude Code, and …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T16:02:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df868268770e7c96eac69342f1e069ae8e971310",
          "body": "GitHub will force Node 24 on Actions runners starting 2026-06-16 and\nwarns that the Node 20-based actions may stop working. Bump every\naffected action to its current Node 24-based major across all workflows:\n\n- actions/checkout            v4 -> v6\n- pnpm/action-setup           v4 -> v6  (version sti\n[…]\nnput changes are required — all `with:` keys used here are still\nsupported. checkout@v6 was already in use by weekly-api-sync.yml.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: upgrade GitHub Actions to Node 24 runtimes (#127)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:50:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25d23191df7fab06e386ff32abe241e468665048",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.10.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T15:35:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e65e984e72417d959bcbd8355d62a18e7816e4",
          "body": "The update-notifier dependency was wired but dormant: notices never\nappeared because the check was silenced in npm-script contexts (the\ncommon launch path for the CLIs), getUpdateInfo() was unused, and the\nserver has no TTY for a box.\n\n- version.ts: opt into npm-script contexts via shouldNotifyInNpm\n[…]\n  registry check (installed vs latest), failing soft when offline.\n- tests: cover the notifier wiring with update-notifier mocked.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): surface available update notices to users (#126)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:34:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c46f4c0ccb8c808e750e00a42696de9beef8c924",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.9.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T15:03:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e9d04da2544a66a8bfc39b8b188a0fd25ed0f4",
          "body": "…ardening (#124)\n\nMerge dev → main: authenticating-proxy support (#122) + API/tooling hardening",
          "is_bot": false,
          "headline": "Merge dev → main: authenticating-proxy support (#122) + API/tooling h…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:02:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69291af718fe8ef7c09904acb9cea912e8d8aab4",
          "body": "…ted XSS\n\nThe auto-capture callback page (renderCallbackPage in oauth-helper.ts) wrote\neBay's `error` / `error_description` query params straight into HTML, so a\ncrafted `…/oauth/callback?error=<script>…` reflected unescaped into the\nresponse — CodeQL js/reflected-xss (high), new in PR #124's feat(s\n[…]\n payload in error_description is encoded, not reflected.\n\nnpm run check: 0 errors · npm test: 1035 passing · npm run build: clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): HTML-escape OAuth callback error detail to stop reflec…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:53:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f29ea5de48fe9f4341906add0acd8eed674516f5",
          "body": "Root cause of \"the provided authorization refresh token is invalid or was\nissued to another client\" at server start: the wizard's saveConfig wrote tokens\nunquoted (EBAY_USER_REFRESH_TOKEN=v^1.1#i^1#...). eBay tokens contain '#', which\ndotenv treats as the start of an inline comment for UNQUOTED valu\n[…]\n;\ncredit the developer in eBay-blue bold with a LinkedIn contact line. Both banner\nsites now share one printWizardBanner() helper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): quote .env values so #-bearing OAuth tokens survive dotenv",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:44:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2886acf962283153529f8c3f640a4fdadd501021",
          "body": "Auto-capture only works when the RuName redirect points at the local callback\nserver (via an HTTPS tunnel). Defaulting to it lured users into a dead end: eBay\nredirects to the RuName's real accepted URL (a hosted app, the old redirect,\netc.), so localhost never receives the code and nothing is captu\n[…]\ns a public HTTPS tunnel)\" so its\nprerequisite is explicit. No behavior change; the switch handles every value\nregardless of order.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): default to paste-code OAuth, demote auto-capture to advanced",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:26:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c827c369804cda9bcc48a306928e672da4f1a5c2",
          "body": "eBay rejects http:// and localhost as a RuName auth-accepted URL (HTTPS is\nmandatory, confirmed in eBay's OAuth docs and developer console). The shipped\nwizard note and .env.example wrongly framed an HTTPS tunnel as an optional\nfallback \"if it rejects this URL\"; in reality the loopback port must alw\n[…]\n registered on the RuName.\n\nBehavior unchanged — only on-screen guidance, the .env.example comment, and the\ngetCallbackPort JSDoc.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): correct OAuth auto-capture guidance — eBay requires HTTPS",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:16:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5f67997c80e45ebff1f2fa0870b26c0f6fd2301",
          "body": "Replace the copy-paste step in `npm run setup` with a one-click\n\"Auto-capture\" option: a loopback server catches eBay's redirect,\nvalidates a CSRF `state`, and exchanges the code automatically — the\nmanual paste flow stays as a fallback.\n\n- Harden src/utils/oauth-helper.ts startCallbackServer: CSRF \n[…]\n\n- 9 new tests: code capture, URL-decoding, error redirect, state\n  match/mismatch, stray path, custom path, timeout, port-in-use.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(setup): add OAuth auto-capture via local callback server",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:04:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c0a937bde5df179b976519912a936e33f228b9b2",
          "body": "…s → 0)\n\nBring the dependency tree to a clean security baseline. `pnpm audit` now\nreports no known vulnerabilities, including the lone critical (Vitest UI\nserver arbitrary file read/exec) and all runtime advisories.\n\nStructural\n- Delete the stale, committed package-lock.json. It was unused (all CI u\n[…]\n 0 errors / 593 warnings · `npm test` 1019 passing\n· `npm run build` clean · `pnpm audit` 0 vulnerabilities · 322 tools unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): remediate all Dependabot advisories (61 unique / 117 alert…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T13:35:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e98eb3016f06641b8abd77da858a150e75f99e7",
          "body": "Add two optional, independent EBAY_MCP_* environment variables so the server\ncan run behind a proxy that injects eBay authentication. Both default off, so\nexisting behavior is unchanged.\n\n- EBAY_MCP_DISABLE_AUTH_HEADER=true enables credential-less \"proxy auth\" mode:\n  the client attaches no eBay aut\n[…]\ng/normalizing/validating); getBaseUrl and\ngetIdentityBaseUrl gain an optional override parameter. Adds 19 unit tests.\n\nCloses #122\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): support running behind an authenticating proxy (#122)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T12:59:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0979da1528594193f70655ed14e4d441162d5b49",
          "body": "The negative-keyword API methods built paths eBay does not expose\n(`/ad_campaign/{id}/negative_keyword*`, `/ad_group/{id}/negative_keyword*`),\nso all ~24 negative-keyword tools would 404. eBay's spec exposes a single\nflat resource: GET/POST `/negative_keyword`, GET/PUT `/negative_keyword/{id}`,\nand \n[…]\n Advertised tool count 332 → 322 (README, AGENTS.md, llms.txt).\n\nnpm run check: 0 errors; npm test: 997 passed; npm run build: OK.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(marketing): map negative-keyword tools to eBay's real flat API",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T15:46:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0b5d21e5d1a09f3f4f5be046f1a948401430f434",
          "body": "Several tools advertised an inputSchema that did not match what their\nhandler actually accepts, making them effectively uncallable by MCP\nclients (rawTool / array-paired tools self-validate, so the advertised\nschema is the only contract a client sees but it was never enforced or\nkept in sync).\n\nComm\n[…]\n 8 ad-group negative-keyword defs (handlers use only adGroupId).\n\nnpm run check: 0 errors. npm test: 1006/1006. npm run build: OK.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tools): align advertised tool schemas with their real contracts",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T15:14:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a05163f7249b70985e9e8c74a636d188eeaa353f",
          "body": "This commit refactors several API methods across the AccountApi, InventoryApi, and DisputeApi classes to utilize generic Record types for request bodies instead of specific schema types. This change enhances flexibility and reduces the need for strict type definitions, allowing for a broader range o\n[…]\ne`, and `uploadEvidenceFile` methods in DisputeApi to accept Record types for their request bodies.\n\nThese adjustments aim to simplify method signatures and improve the adaptability of the API client.",
          "is_bot": false,
          "headline": "refactor(api): update API method signatures to use generic Record types",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T14:23:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b345d7424c56faa6e8a59feec5abac8f9d8bbfb",
          "body": "This commit introduces a consistent error handling mechanism across multiple API classes by utilizing the `withApiError` utility. This change improves the robustness of error reporting for API calls, ensuring that users receive clear and descriptive error messages when requests fail.\n\nKey updates in\n[…]\ni`.\n- Removed redundant try-catch blocks, simplifying the code and enhancing readability.\n\nThese enhancements aim to provide better user feedback and streamline error management across the API client.",
          "is_bot": false,
          "headline": "feat(api): enhance error handling across various APIs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T11:07:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "163eab7f4fb857b827ed9db3e0523835425bcaea",
          "body": "This commit introduces a check in the EbayApiClient to throw an error if the access token is missing, providing a clear message to the user about the required credentials. Additionally, it refactors imports across various files to streamline the codebase, including the reorganization of tool definit\n[…]\ns to use the new `types.ts`.\n- Consolidated tool definitions into a new `connector.ts` file for better organization.\n\nThese changes aim to enhance the robustness and maintainability of the API client.",
          "is_bot": false,
          "headline": "fix(api): add error handling for missing access token in EbayApiClient",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T10:25:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b73ff0b219a69db7450c19a3e0762aeb9182945",
          "body": "This commit replaces all instances of axios with a custom HTTP client built on the native fetch API. The new implementation centralizes error handling, request/response parsing, and timeout management, reducing dependencies and improving performance. Key changes include:\n\n- Introduced `httpRequest` \n[…]\nutility functions to use the new HTTP client.\n- Removed axios from dependencies in package.json and updated related tests.\n\nThis transition aims to streamline the codebase and enhance maintainability.",
          "is_bot": false,
          "headline": "refactor: migrate from axios to native fetch for HTTP requests",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T10:18:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59fc60da5529d7e5539c6d4abeca87ba15a75aed",
          "body": "The registry exposes 332 tools (getToolEntries().length) and the suite has\n1005 tests, but the docs still advertised 325 tools / 958 tests. Sync up\nREADME, package.json, llms.txt, and AGENTS.md.\n\nVerified against a spec diff with the public eBay OAS mirror (hendt/ebay-api):\nour committed specs are a\n[…]\n eBay reorganizations (location endpoints live under\nthe Inventory API, already covered) — i.e. no new eBay endpoints are missing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: correct advertised tool/test counts to match reality",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T09:51:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e011771d09b7ace3ca71ab59042a3baafc9d9a1d",
          "body": "The sync scraper has been blind since the spec-URL manifest\n(docs/sell-apps/README.md) was deleted in 41c5d1a: downloadSpecs() returns\n0 and the run still prints \"100% coverage\", so eBay API changes have gone\nundetected for ~6 months.\n\n- Restore docs/sell-apps/README.md (Sell-scoped spec URLs); Buy \n[…]\nreturns HTTP 403 to scripted spec fetches, so a\nreal spec refresh still needs a browser/authenticated source — tracked\nseparately.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sync): restore spec manifest and stop silent stale-coverage reports",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T09:11:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ec8f5e2c12514a343cae8f134914405bc80c7741",
          "body": "Redistribute depth without losing content:\n- README 661 -> 245 lines: collapse disclaimer wall, drop manual TOC,\n  table-ize rate limits, fix broken BUG_REPORT.md link\n- AGENTS.md: real agent guide (entry points, validation commands,\n  module map, add-an-endpoint workflow, conventions)\n- CLAUDE.md: \n[…]\nort AGENTS.md to keep a single source of truth\n- Move Logging + Troubleshooting into docs/logging.md and\n  docs/troubleshooting.md\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: trim README to a landing page, build out AGENTS.md",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T08:52:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a7b04816e574561958d28da0a97aa4db4d872b9",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.10",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-23T10:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "414642c1a4e0bd5a8a4cd0b04f3bb8d453b8e30c",
          "body": "fix(packaging): include build/mcp/**/*.js in published tarball",
          "is_bot": false,
          "headline": "Merge pull request #121 from YosefHayim/dev",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-23T10:52:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78804b01c08ab4d87d6a298127e28dde8fe3e957",
          "body": "The architecture refactor in v1.8.9 introduced src/mcp/runtime.ts and\nsrc/mcp/http-transport.ts, but the files whitelist in package.json was\nnot updated. As a result, npm install -g ebay-mcp@1.8.9 produced\nERR_MODULE_NOT_FOUND for build/mcp/runtime.js at startup.\n\nFixes #120\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(packaging): include build/mcp/**/*.js in published tarball",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-23T10:51:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0549b754a829e792817782739c1e4bb041eae9ea",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.9",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-09T17:51:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "296fc960faffb4077beca5b06b4bd1abe5312549",
          "body": "Improve architecture and add JSDoc coverage",
          "is_bot": false,
          "headline": "Merge pull request #119 from YosefHayim/architecture-deepening",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-09T17:50:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8b8aceb9318699522a24d9ce913b5e166c63593",
          "body": null,
          "is_bot": false,
          "headline": "Improve architecture and add JSDoc coverage",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-09T17:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a22d1cc21e9329a27cae6f30eef38b8da0988ad",
          "body": "Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: improve package.json description and keywords",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-03T00:16:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bd8e085f5520fdb8900bb63eaffd1aaeb8db64c8",
          "body": "The npm Trusted Publisher configuration for ebay-mcp is bound to\nworkflow filename `publish.yml` (matching the OIDC `job_workflow_ref`\nclaim). Commit 24b17b3 (\"unify release and publish workflows\") moved\npublishing into release.yml, which broke the match — npm rejected the\nPUT with 404 once OIDC aut\n[…]\n user-controlled inputs.\n- release.yml: drops the inline `Publish to npm` and verify-npm steps;\n  pushing the tag now hands off to publish.yml.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: split publish into publish.yml to fix OIDC trusted publisher match",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T10:06:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e2048d999fa4ad1285ddd18c85bca4406ef4ac8",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.8",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-26T10:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5e501df6587278dcd181a122e8557c0c71ecc63",
          "body": "Node 22 ships with npm 10.x, and `npm install -g npm@latest` to upgrade\nin-place fails on the runner with `Cannot find module 'promise-retry'`\n(known npm CLI issue when upgrading 10→11 over an in-place install).\n\nNode 24 ships with npm 11.5+ pre-installed, so trusted publishing works\nwithout an upgr\n[…]\n publish.yml. The verify step is kept as a\nguard so future Node downgrades fail loudly instead of silently\nfalling back to anonymous publishes.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: bump runner to Node 24 for OIDC trusted publishing",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:59:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e0656b93c31e63825a4ad71bc58af3f2a9c6909e",
          "body": "Releases since 1.8.5 (2026-03-21) silently failed at the npm publish\nstep because commit 24b17b3 (\"ci: unify release and publish workflows\")\ndropped the `npm install -g npm@latest` step that the previous\npublish.yml had. Node 22 ships with npm 10.x, which signs the\nprovenance statement but cannot co\n[…]\nestores the working configuration used before\nthe unification, plus a guard that fails fast if the runner ever ends\nup with npm < 11.5.1 again.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: restore npm upgrade step for OIDC trusted publishing",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:57:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d73fe07fdb47b764d599575eb612063901dbff04",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.7",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-26T09:51:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "578743db172d04287837b44e9c47b551c8127396",
          "body": "Closes #113 and #114.\n\n- exchangeCodeForToken now writes EBAY_USER_ACCESS_TOKEN and\n  EBAY_USER_REFRESH_TOKEN to .env immediately after a successful\n  authorization-code exchange (#113). The misleading JSDoc and\n  comment claiming automatic persistence are corrected; persistence\n  is now actually pe\n[…]\nin tests/unit/auth/oauth.test.ts covering both\n  bugs, including the no-rotation case and the matching-env case to\n  guard against regressions.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(auth): persist OAuth tokens to .env on code exchange and refresh",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:24:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5685c32ab003b0d9d5305fabdd55d71df2be4f2",
          "body": "…tion and update dependencies\n\n- Removed grimoire-wizard dependency from package.json and pnpm-lock.yaml.\n- Introduced a new setup-wizard module utilizing prompts for interactive setup.\n- Updated README to reflect changes in the setup wizard branding and description.\n- Adjusted setup script to integrate the new wizard implementation.",
          "is_bot": false,
          "headline": "refactor: replace grimoire-wizard with custom setup-wizard implementa…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T16:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b4bcbbed354d679dd3ce5902a42e2ca381d0770",
          "body": "…time",
          "is_bot": false,
          "headline": "refactor(setup): replace grimoire-wizard with prompts-based setup run…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T15:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24b17b3f03b83673d66c5966acbe07daf4564853",
          "body": null,
          "is_bot": false,
          "headline": "ci: unify release and publish workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T15:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca5cb551a863e7f1b53f6b7a751a505cc16662fd",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.6",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-23T14:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "182673717b5858fc47fe89e3e5104cae6fbbc571",
          "body": "refactor: continue dedup cleanup and enforce pre-push checks",
          "is_bot": false,
          "headline": "Merge pull request #110 from YosefHayim/cloud/main",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:39:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61ab3dfba7324bf2c052d3b03b2321d995baeaa3",
          "body": "…ck, test, and build steps",
          "is_bot": false,
          "headline": "chore(husky): update pre-push script to include installation, typeche…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:36:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff04ed390f6c0d47d738ba4fb3a642eda89dcb8e",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): sync pnpm lockfile for husky dependency",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:20:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43fbe1cb8d63b3761ce94640647e4144224b47a8",
          "body": null,
          "is_bot": false,
          "headline": "refactor: continue dedup cleanup and enforce pre-push checks",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T13:56:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26708a2398b2184450c2e9de7e094d61c443f244",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-22T09:12:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66427cfc4d61d8659e15c0b1d0731a8e7834771d",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-13T18:38:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79d1f967bda9be5bdb8b8208288ba539a7999de5",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-01T08:55:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f21b32e3fb00d08531a0ddb56ceb2693babc0927",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-22T08:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea38d20b590f704c36692d9f8208b57ff31ba51f",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-21T16:53:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8cfd7da377d8dd14ecaf2297f4f06a055b17723",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.5",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-21T02:43:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "839bd793eb7fed890c00f07539eb72c3a4bef29d",
          "body": "…d_yarn-e78c89ff38\n\nchore(deps): bump fast-xml-parser from 5.4.2 to 5.5.6 in the npm_and_yarn group across 1 directory",
          "is_bot": false,
          "headline": "Merge pull request #95 from YosefHayim/dependabot/npm_and_yarn/npm_an…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-21T02:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f09148d510cd0b6ff78fba198e9aad80769a1a1",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser).\n\n\nUpdates `fast-xml-parser` from 5.4.2 to 5.5.6\n- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)\n- [Changelog](https://github.co\n[…]\nendencies:\n- dependency-name: fast-xml-parser\n  dependency-version: 5.5.6\n  dependency-type: direct:production\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump fast-xml-parser",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-18T02:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "819c8f7e689ac21d8e847ea8cf68fcb5c96c2a5b",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.4",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T15:36:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e885a1aedfb67bb6007444ffe6c5938016114ef",
          "body": "…d_yarn-926779f9d1\n\nchore(deps): bump the npm_and_yarn group across 1 directory with 2 updates",
          "is_bot": false,
          "headline": "Merge pull request #93 from YosefHayim/dependabot/npm_and_yarn/npm_an…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T15:35:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c28a91e6cdae33e959556795ee3193323ffa9d0",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:59:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e8fbe4afbcf1f95be1651aab48921cb70bd6a25",
          "body": null,
          "is_bot": false,
          "headline": "ci: skip CI on dependabot PRs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:58:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25ee0f45fe9fe979671933b0a081e64df6a2c797",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:45:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db972ee001a7084e2757d8f311f3cda8cb7e7907",
          "body": "Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>",
          "is_bot": false,
          "headline": "fix: update pnpm-lock.yaml for grimoire-wizard dep (replaces prompts)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:44:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "442f35d30b742cc09d7f2b7e0205d8003c953c47",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "155f29d97b78333516cc8df74379dd78ff573b0f",
          "body": "…integration)\n\nCo-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>",
          "is_bot": false,
          "headline": "ci: add automated release workflow + bump to v1.8.0 (grimoire wizard …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:41:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "376f71dd950147a93a53d61573a7ec96612df497",
          "body": null,
          "is_bot": false,
          "headline": "feat: add 'Powered by grimoire-wizard' subtitle in eBay blue",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:37:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3be0e9c4ab98cddd85735639efc0b36b440b6f25",
          "body": "…l back to existingConfig when password left empty",
          "is_bot": false,
          "headline": "fix: spinner no longer spams inside clack frame; credential hooks fal…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9c035243c2c8303ce25c78c948266f011606fde",
          "body": "…mode, completion summary",
          "is_bot": false,
          "headline": "fix: restore full original UI — logo, welcome screen, showBox, quick …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:22:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fad4ffcaab48246b80b5ecffe3a3800af1ec69d",
          "body": "…dates\n\nBumps the npm_and_yarn group with 2 updates in the / directory: [flatted](https://github.com/WebReflection/flatted) and [hono](https://github.com/honojs/hono).\n\n\nUpdates `flatted` from 3.3.4 to 3.4.1\n- [Commits](https://github.com/WebReflection/flatted/compare/v3.3.4...v3.4.1)\n\nUpdates `hono\n[…]\nependency-group: npm_and_yarn\n- dependency-name: hono\n  dependency-version: 4.12.8\n  dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the npm_and_yarn group across 1 directory with 2 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-16T13:11:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "781cc467497b75f6297148e48e66d19058d27631",
          "body": "- Replace prompts library with grimoire-wizard for the full setup flow\n- Wizard uses ClackRenderer for polished framed terminal UI\n- eBay brand theme (red/blue/yellow/green) via grimoire theme tokens\n- All 6 steps mapped: environment, marketplace, language, credentials, OAuth, MCP clients\n- OAuth fl\n[…]\ned\n- asyncValidate enforces v^1.1# format for refresh tokens\n- Reduces setup.ts from 1858 to ~560 lines while preserving all behavior\n- README: grimoire-wizard badge in header and setup wizard section",
          "is_bot": false,
          "headline": "feat: replace setup wizard with grimoire-wizard v0.6.0",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:09:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 51,
      "commits_last_year": 697,
      "latest_release_at": "2026-07-19T13:07:45Z",
      "latest_release_tag": "v1.14.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 32,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 3.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "ebay-mcp",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "ebay",
            "ebay-api",
            "model-context-protocol",
            "ai-tools",
            "ai",
            "llm",
            "documentation",
            "api",
            "server",
            "backend"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/ebay-mcp",
          "is_deprecated": false,
          "latest_version": "1.14.1",
          "repository_url": "https://github.com/YosefHayim/ebay-mcp",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2316,
          "first_published_at": "2025-11-16T23:59:14.059000Z",
          "latest_published_at": "2026-07-19T13:10:06.025000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 48,
      "stars": 105,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-11-12",
            "count": 1
          },
          {
            "date": "2025-11-14",
            "count": 1
          },
          {
            "date": "2025-12-05",
            "count": 1
          },
          {
            "date": "2025-12-07",
            "count": 1
          },
          {
            "date": "2025-12-28",
            "count": 1
          },
          {
            "date": "2025-12-31",
            "count": 1
          },
          {
            "date": "2026-01-23",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-01-30",
            "count": 1
          },
          {
            "date": "2026-02-05",
            "count": 1
          },
          {
            "date": "2026-02-14",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-18",
            "count": 1
          },
          {
            "date": "2026-02-22",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 2
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 2
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-13",
            "count": 1
          },
          {
            "date": "2026-04-15",
            "count": 1
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-05-10",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-17",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          },
          {
            "date": "2026-07-05",
            "count": 2
          },
          {
            "date": "2026-07-09",
            "count": 1
          },
          {
            "date": "2026-07-10",
            "count": 1
          },
          {
            "date": "2026-07-12",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 1
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 2
          },
          {
            "date": "2026-07-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 47,
        "total_forks": 48
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json",
        "ui/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 507840,
      "source_files_sampled": 245,
      "oversized_source_files": 8,
      "agent_instruction_files": [
        ".github/copilot-instructions.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 12152
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 194,
        "malicious_count": 0,
        "assessed_package": "npm:ebay-mcp@1.14.1",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/ext-apps",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.7.4"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.29.0"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.6.2"
        },
        {
          "name": "cors",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.6"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "dotenv-stringify",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.1"
        },
        {
          "name": "effect",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.21.4"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "fast-xml-builder",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.2.0"
        },
        {
          "name": "fast-xml-parser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.9.0"
        },
        {
          "name": "helmet",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.2.0"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.2"
        },
        {
          "name": "update-notifier",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.3.1"
        },
        {
          "name": "winston",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.19.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "zod-to-json-schema",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@modelcontextprotocol/ext-apps",
            "direct": true,
            "version": "1.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": true,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": true,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "17.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv-stringify",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "effect",
            "direct": true,
            "version": "3.21.4",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-builder",
            "direct": true,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": true,
            "version": "5.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "helmet",
            "direct": true,
            "version": "8.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "prompts",
            "direct": true,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "update-notifier",
            "direct": true,
            "version": "7.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "winston",
            "direct": true,
            "version": "3.19.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "3.25.76",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": true,
            "version": "3.25.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-darwin-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-darwin-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-arm64-musl",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-x64-musl",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-win32-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-win32-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@colors/colors",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@dabh/diagnostics",
            "direct": false,
            "version": "2.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@mswjs/interceptors",
            "direct": false,
            "version": "0.41.9",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@nodable/entities",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.scandir",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.stat",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.walk",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/deferred-promise",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/logger",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/until",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@paralleldrive/cuid2",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/config.env-replace",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/network.ca-file",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/npm-conf",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@polka/url",
            "direct": false,
            "version": "1.0.0-next.29",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/ajv",
            "direct": false,
            "version": "8.11.2",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/config",
            "direct": false,
            "version": "0.22.0",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/openapi-core",
            "direct": false,
            "version": "1.34.15",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm-eabi",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-musleabihf",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-s390x-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openbsd-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openharmony-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-arm64-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-ia32-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@so-ric/colorspace",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/body-parser",
            "direct": false,
            "version": "1.19.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/configstore",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/connect",
            "direct": false,
            "version": "3.4.38",
            "ecosystem": "npm"
          },
          {
            "name": "@types/cookiejar",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/cors",
            "direct": false,
            "version": "2.8.19",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express-serve-static-core",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/http-errors",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/methods",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prompts",
            "direct": false,
            "version": "2.4.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/qs",
            "direct": false,
            "version": "6.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/range-parser",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "19.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "19.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/serve-static",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/superagent",
            "direct": false,
            "version": "8.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/supertest",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/triple-beam",
            "direct": false,
            "version": "1.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/update-notifier",
            "direct": false,
            "version": "6.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/ui",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-align",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-colors",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "anynum",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-union",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "asap",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "async",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "asynckit",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "atomically",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "binary-extensions",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "boxen",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "boxen",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "change-case",
            "direct": false,
            "version": "5.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-boxes",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "color",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "color-string",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "colorette",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "combined-stream",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "9.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "component-emitter",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "config-chain",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "configstore",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookiejar",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-extend",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "delayed-stream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dezalgo",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "dir-glob",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "dot-prop",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "enabled",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-goat",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "3.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-glob",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-safe-stringify",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "fastq",
            "direct": false,
            "version": "1.20.1",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fecha",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "fflate",
            "direct": false,
            "version": "0.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "fn.name",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "form-data",
            "direct": false,
            "version": "4.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "formidable",
            "direct": false,
            "version": "3.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-tsconfig",
            "direct": false,
            "version": "4.14.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "global-directory",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "globby",
            "direct": false,
            "version": "11.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.25",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "index-to-position",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-binary-path",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-in-ci",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-installed-globally",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-node-process",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-npm",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unsafe",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-levenshtein",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json-stringify-safe",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "kleur",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "kuler",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ky",
            "direct": false,
            "version": "1.14.3",
            "ecosystem": "npm"
          },
          {
            "name": "latest-version",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "logform",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge2",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "methods",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "mime",
            "direct": false,
            "version": "2.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "2.1.35",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "5.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "mrmime",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mylas",
            "direct": false,
            "version": "2.1.14",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nock",
            "direct": false,
            "version": "14.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "one-time",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "openapi-typescript",
            "direct": false,
            "version": "7.13.0",
            "ecosystem": "npm"
          },
          {
            "name": "outvariant",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "package-json",
            "direct": false,
            "version": "10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-expression-matcher",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "plimit-lit",
            "direct": false,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "pluralize",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "propagate",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "proto-list",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pupa",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "queue-lit",
            "direct": false,
            "version": "1.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "queue-microtask",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rc",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "registry-auth-token",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "registry-url",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-pkg-maps",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "reusify",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "run-parallel",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "safe-stable-stringify",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "sirv",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stack-trace",
            "direct": false,
            "version": "0.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "strict-event-emitter",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string_decoder",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strnum",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "stubborn-fs",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "stubborn-utils",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "superagent",
            "direct": false,
            "version": "10.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "supertest",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "10.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "text-hex",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "totalist",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "triple-beam",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "1.8.17",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.22.4",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "2.19.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "4.41.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js-replace",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "util-deprecate",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "7.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "vite-plugin-singlefile",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "when-exit",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "widest-line",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "widest-line",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "winston-transport",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "xdg-basedir",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "xml-naming",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml-ast-parser",
            "direct": false,
            "version": "0.0.43",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 442,
        "direct_count": 17,
        "indirect_count": 425
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 85,
        "open_issues": 1,
        "closed_ratio": 0.941,
        "closed_issues": 16,
        "closed_unmerged_prs": 39
      },
      "bus_factor": 1,
      "bot_contributors": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "YosefHayim",
          "commits": 536,
          "avatar_url": "https://avatars.githubusercontent.com/u/179159376?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "longrackslabs",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/1175466?v=4"
        },
        {
          "type": "User",
          "login": "nedlir",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/66902031?v=4"
        },
        {
          "type": "User",
          "login": "jdbhartley",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/24490599?v=4"
        },
        {
          "type": "User",
          "login": "lwsinclair",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/2829939?v=4"
        },
        {
          "type": "User",
          "login": "michelbragaguimaraes",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/8365866?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.892
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "api-sync.yml",
        "biome.yml",
        "build.yml",
        "ci.yml",
        "e2e.yml",
        "publish.yml",
        "release.yml",
        "report-failure.yml",
        "test.yml",
        "typecheck.yml",
        "weekly-cleanup.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "10 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0a23f966e50695e7bb1087ee4e71ae9a03a85da5",
        "ran_at": "2026-07-25T10:39:56Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T05:25:19Z",
      "oldest_open_prs": [
        {
          "number": 141,
          "created_at": "2026-07-20T19:40:26Z",
          "last_comment_at": "2026-07-20T19:40:52Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-04T01:25:04Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 142,
          "created_at": "2026-07-22T10:27:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/YosefHayim/ebay-mcp",
    "host": "github.com",
    "name": "ebay-mcp",
    "owner": "YosefHayim"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 70,
      "inputs": {
        "security": 56,
        "vitality": 92,
        "community": 65,
        "governance": 54,
        "engineering": 82
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "commits_last_year": 697,
              "human_commit_share": 0.73,
              "days_since_last_push": 5,
              "active_weeks_last_year": 32
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "32/52 weeks with commits",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 32
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "697 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 697
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 51,
              "latest_release_tag": "v1.14.1",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 3.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "51 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 65,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 48,
              "stars": 105,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "105 stars",
                "points": 32.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 105
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "48 forks",
                "points": 13.9,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "ebay-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2316
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,316 downloads/month across npm",
                "points": 44.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2316,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.892
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 89% of commits",
                "points": 2.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "merged_prs": 85,
              "open_issues": 1,
              "closed_issues": 16,
              "issue_closed_ratio": 0.941,
              "closed_unmerged_prs": 39
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "94% of issues closed",
                "points": 44,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "85/124 decided PRs merged",
                "points": 26.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 85,
                      "decided": 124
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "followers": 16,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "YosefHayim",
              "public_repos": 12,
              "account_age_days": 701
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "16 followers of YosefHayim",
                "points": 8.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 16,
                      "login": "YosefHayim"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~1 yr old",
                "points": 11.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "ebay-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 82,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "11 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "chatgpt",
                "claude",
                "ebay",
                "mcp-server",
                "typescript",
                "api-wrapper",
                "ebay-api",
                "mcp",
                "model-context-protocol",
                "npm",
                "oauth2",
                "ai-agents",
                "cursor",
                "local-first",
                "nodejs",
                "tool-gating"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/ebay-mcp",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/ebay-mcp",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "16 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "10 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:ebay-mcp@1.14.1 runtime dependency closure — what installing the published package pulls in — 194 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:ebay-mcp@1.14.1",
                  "assessed": 194
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 194,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 194,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.986,
              "agent_instruction_files": [
                ".github/copilot-instructions.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 12152
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "72 of 73 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 72,
                      "sampled": 73
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json",
                "ui/tsconfig.json"
              ],
              "agent_commit_share": 0.29,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json, ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json, ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "29 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 29,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 507840,
              "source_files_sampled": 245,
              "oversized_source_files": 8
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "8/245 source files over 60KB",
                "points": 53.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 245,
                      "oversized": 8
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T10:40:08.372521Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/y/YosefHayim/ebay-mcp.svg",
  "full_name": "YosefHayim/ebay-mcp",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.