原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 4659,
"has_wiki": false,
"homepage": null,
"languages": {
"HTML": 3162,
"Python": 611039
},
"pushed_at": "2026-08-02T04:07:33Z",
"created_at": "2026-06-03T19:32:24Z",
"owner_type": "Organization",
"updated_at": "2026-08-02T04:07:11Z",
"description": "Agent Manifest SDK. Hardware-anchors all 10 artifacts defining an agent at deployment. Python and TypeScript.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": "AgentTrust",
"type": "Organization",
"login": "agentrust-io",
"company": null,
"location": null,
"followers": 49,
"avatar_url": "https://avatars.githubusercontent.com/u/290505154?v=4",
"created_at": "2026-06-03T19:31:09Z",
"is_verified": null,
"public_repos": 11,
"account_age_days": 59
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "python-v0.10.0",
"kind": "other",
"published_at": "2026-08-02T04:07:00Z"
},
{
"tag": "python-v0.9.0",
"kind": "other",
"published_at": "2026-08-02T04:01:07Z"
},
{
"tag": "python-v0.8.0",
"kind": "other",
"published_at": "2026-08-01T21:14:06Z"
},
{
"tag": "python-v0.7.0",
"kind": "other",
"published_at": "2026-07-27T23:51:25Z"
},
{
"tag": "python-v0.6.1",
"kind": "other",
"published_at": "2026-07-27T17:00:03Z"
},
{
"tag": "python-v0.6.0",
"kind": "other",
"published_at": "2026-07-27T01:37:09Z"
},
{
"tag": "python-v0.5.0",
"kind": "other",
"published_at": "2026-07-21T22:59:05Z"
},
{
"tag": "python-v0.4.0",
"kind": "other",
"published_at": "2026-07-21T22:24:35Z"
},
{
"tag": "python-v0.3.0",
"kind": "other",
"published_at": "2026-07-15T23:11:39Z"
},
{
"tag": "python-v0.1.1",
"kind": "other",
"published_at": "2026-06-21T21:05:49Z"
},
{
"tag": "python-v0.1.0",
"kind": "other",
"published_at": "2026-06-15T23:45:02Z"
},
{
"tag": "python-v0.1.0a1",
"kind": "other",
"published_at": "2026-06-04T17:49:13Z"
}
],
"recent_commits": [
{
"oid": "53800042ac0370a13c7262b0dbc5243b63135281",
"body": "Downstreams kept a ctypes mirror of the SNP layout partly to parse and partly to\nread offsets off it. cmcp uses it as an offset oracle across seven test files,\nso sharing parse_snp_report without sharing the table would have moved the\nduplication into test scaffolding rather than removing it, and of\n[…]\nt the genuine Azure capture\nrather than against themselves.\n\nCut as 0.10.0 in the same change: purely additive, no behaviour change.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tee): export the SEV-SNP ABI offset table (#262)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-02T04:06:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cfdebcc7ff019f27e6109172391fb22040475eb4",
"body": "Ships the SEV-SNP report union (guest_svn, vmpl, signature_algo) and\nload_snp_cert_chain() so cmcp and ca2a can delete four copies of the layout\nbetween them, two of which live inside cmcp alone.\n\nAlso restores a check that existed only in the copies being deleted:\nverify_snp_signature() now confirm\n[…]\nthout this would have\nsilently dropped a check both downstreams already performed.\n\nPhase A2 of consolidating TEE verification here.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 0.9.0 (#261)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-02T04:00:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ab72cfebbcd27373fba830ec8626aa7a6a056975",
"body": "…e algorithm (#260)\n\nPhase A2 of consolidating the TEE verification stack. cmcp and ca2a carried\nfour copies of the SEV-SNP report layout between them, two of them inside cmcp\nalone. All four agree on every offset, so this is a union rather than a\nreconciliation, but four copies is four chances to d\n[…]\ncted rather than worked around,\nthe same shape of defect as the cmcp TPM fixture found in 0.8.0.\n\n648 passed, 16 skipped.\n\nRefs #204\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tee): share the SNP report union and check the declared signatur…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-02T03:58:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e037f5249b5f327a1fbf57ce7a2b9487dbfbfc11",
"body": "The contributor-check workflow runs on pull_request_target holding\nissues: write and pull-requests: write, and checked out\nagentrust-io/.github at `ref: main`. Anyone able to land a commit on\nthat repo's main therefore got a write-capable token in this repo. The\norg action's own template comment say\n[…]\nmutable.\n\nPinned to 0fe4520 (main as of 2026-08-01), which also carries the AGT\nbump to 359a6b8 and its fail-closed UNKNOWN risk ordering, so errored\nor rate-limited checks stop being scored as clean.",
"is_bot": false,
"headline": "chore(ci): pin agentrust-io/.github checkout to an immutable SHA (#257)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-01T21:13:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8845d7bf0511b7397fd2c94e9a85ef6cb925c663",
"body": "Ships parse_tpmt_signature() / ParsedSignature and both TPMS_ATTEST framings so\ncmcp and ca2a can delete their copies instead of keeping three implementations\nof the same wire formats in step by hand.\n\nBoth downstreams carried a byte-identical TPMT_SIGNATURE unwrap; the framing gap\nwas one-sided, si\n[…]\nthird hand-rolled parser.\n\nPhase A1 of consolidating TEE verification here. No change to manifest signing\nor verification behaviour.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 0.8.0 (#259)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-01T21:13:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "102881eb67a593c698102ecdc6768d7a62a755cb",
"body": "…ngs (#258)\n\nPhase A1 of consolidating the TEE verification stack into agent-manifest so\ncmcp and ca2a can consume it from PyPI instead of each carrying a copy.\n\nTwo capabilities move in:\n\nparse_tpmt_signature() / ParsedSignature become public. cmcp and ca2a had\nbyte-identical implementations of the\n[…]\n verifier had never met a real TPM was stale:\ncmcp validated the delegated path on 2026-07-31 and recorded it. Corrected.\n\nRefs #431\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tee): share the TPMT_SIGNATURE parse and accept both quote frami…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-08-01T21:09:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a58837729cef02af8b370502af7ea00f620fbc28",
"body": "…y-cosai\n\ndocs: retarget the standards body from AAIF to CoSAI WS4",
"is_bot": false,
"headline": "Merge pull request #253 from agentrust-io/docs/retarget-standards-bod…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-31T19:09:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d58b311f683c6cb2337727f0d5a8fc195fdedac1",
"body": "The v1.0 standards path now runs through CoSAI Working Stream 4 (Secure\nDesign Patterns for Agentic Systems), an OASIS Open Project, following the\nPhase 1 RFC in cosai-oasis/ws4-secure-design-agentic-systems#149. The repo\npreviously named AAIF as the donation target in the spec header, section 3.1,\n\n[…]\nirst.\n Trademark transfer is marked to be determined rather than asserted.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>",
"is_bot": false,
"headline": "docs: retarget the standards body from AAIF to CoSAI WS4",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-31T18:33:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "941ff4e7532766adc3811cb4579e6751fde9e131",
"body": null,
"is_bot": false,
"headline": "Merge pull request #252 from agentrust-io/docs/strip-em-dashes",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-30T15:20:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e668fa676351ed93d89f61a588ca5a9f530d9d37",
"body": null,
"is_bot": false,
"headline": "docs: strip em dashes from the README; correct the launch tense",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-29T22:58:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3daf9efcbd5573813d098b5c3a8146d457a5a24a",
"body": "The tutorial showed a TRACE record carrying\ntag:agentrust.io,2026:trace-v0.1. That identifier named a domain the\nproject never controlled and has been corrected upstream to\ntag:agentrust-io.com,2026:trace-v0.2 (agentrust-io/trace-spec#107). A\ntutorial that hands a reader an invalid identifier to copy is the worst\nplace to leave one.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: update the TRACE profile URI in the attestation tutorial (#251)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-28T04:48:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3979299ea3b5588c5bfeadc4f5bdfafb2af9aae9",
"body": "Four lengths in the signature section come from the quote, which is\nuntrusted input: the signature-data size, cert_size, qe_auth_size and\npck_size. Python slicing clamps instead of overreading, so an inflated\nlength yielded a short slice and parsing continued against whatever fit.\n\nNo read was ever \n[…]\n failure hides the real cause.\n\nFound while reviewing the same parse in cmcp#420, which shares this\nderivation and has the same gap.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tdx): reject declared lengths that overrun the quote buffer (#250)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-28T00:14:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "679b14719db93e6df60b34425ebc7fafaa7ce123",
"body": "Ships parse_tdx_quote_signature() and TdxQuoteSignature so cmcp and ca2a\ncan delegate the DCAP v4 layout instead of each carrying its own copy of\nthe offsets. Both currently have the flat-parse bug that reads the QE\nreport six bytes early and rejects every genuine quote, so this release\nis what unbl\n[…]\nparser.\n\nAlso carries the v0.2 COSE envelope specification (#243 phase 1).\n\nNo change to manifest signing or verification behaviour.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 0.7.0 (#249)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T23:49:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5daff094a6b4fbb2b0e2a3d3d4ea3ce3d5f2392d",
"body": "Phase 1 of the ADR-0011 migration: the envelope specification, no code.\n\nCOSE_Sign1 (tag 18), or COSE_Sign (tag 98) with two signers when the\nissuer signs with both Ed25519 and ML-DSA-65. Hybrid as one object with\ntwo signature entries rather than two COSE_Sign1 means \"both signatures\ncover the same\n[…]\n RFC 9942 for receipts, which I had only seen second-hand\nthrough the SCITT terminology section.\n\nManifest version 0.1 is untouched.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "spec(cose): specify the v0.2 COSE envelope (#243 phase 1) (#248)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T21:02:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "43a0e354e81999846910bb6e1e13cf64c2550955",
"body": "Expose parse_tdx_quote_signature() and TdxQuoteSignature so cmcp and ca2a can\ndelegate the TDX quote layout instead of carrying their own copy of the offsets.\n\nReal DCAP v4 quotes nest the Quoting Enclave material: the bytes after the\nattestation key are a type-6 QE_REPORT_CERTIFICATION_DATA header,\n[…]\nuote() now calls the shared parse, so the layout has one copy, and\ntwo regression tests pin the nested structure and the type check.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tee): share the validated DCAP v4 signature-section parse (#247)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T20:46:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7661a7739f6167385001c3f44b160d7e08621f2e",
"body": "Closes a crash in verify_manifest() reachable from untrusted input on a\ndefault install: a manifest declaring ML-DSA-65 or hybrid crashed the\nengine with an uncaught RuntimeError because pyoqs is an optional extra.\nIt now returns UNVERIFIABLE with the reason recorded.\n\nAlso carries the ADR-0005 amen\n[…]\nfest onto SCITT terms, and the missing-algorithm fix.\n\nNo change to how manifests are signed or to any existing verification\nresult.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 0.6.1 (#246)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T16:58:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "90cb08bb3e95c3a3b3f944f6fa1b89ea3c9883c5",
"body": "pyoqs is an optional extra, so on a default install any manifest\ndeclaring ML-DSA-65 or hybrid reached _require_oqs() and crashed\nverify_manifest() with an uncaught RuntimeError. A manifest is untrusted\ninput, so a verification endpoint answered 500 to anything an attacker\nsent rather than returning\n[…]\n this normatively, including that INCOMPATIBLE_VERSION is\nreserved for unsupported specification versions and must not be used\nhere.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(verify): return UNVERIFIABLE when an algorithm is unavailable (#245)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T16:45:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9bb965d3a9b71235ec1e169521d66ff85fde39de",
"body": "\"Agent-layer profile of SCITT\" was a slogan with nothing behind it. This\nmaps every structural piece of the spec to its RFC 9943 term: the agent\nis the Artifact, agent_id the Subject, the manifest the Statement, the\nsigned manifest the Signed Statement, transparency_log_entry the Receipt,\nand a mani\n[…]\n in model_identity, so a\nverifier can follow the chain from agent to model publisher rather than\ntrusting an operator-asserted hash.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(spec): map Agent Manifest onto SCITT terms (section 10.5) (#244)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T15:52:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b7d6b7f047e5279723cbe951e359836c4841e371",
"body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-python\n dependency-\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-python from 6 to 7 (#240)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T05:02:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "023a3496f63db9fd4e4c42ddb40726ce73c1894b",
"body": "Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.3 to 2.4.4.\n- [Release notes](https://github.com/ossf/scorecard-action/releases)\n- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)\n- [Commits](https://github.com/ossf/scorecard-action/compare/\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#239)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T05:02:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7ce708eea89839c7784cad1c42eb3410921b37aa",
"body": "Records the decision on part 2 and the sequence for getting there.\n\nThe main technical risk when the migration was first written up was the\npost-quantum profile, and it has since cleared: RFC 9964 (Standards\nTrack, May 2026) gives ML-DSA final IANA code points in COSE, with\nML-DSA-65 as alg -49 and \n[…]\na flag, so v0.1 records keep verifying exactly as they\ndo today. Spec 10.2 gains the v0.2 line item and 3.6 says what happens to\nit.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): accept ADR-0011; envelope moves to COSE_Sign1 in v0.2 (#242)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T04:53:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "84eb8231cfe86324b5cc0517718f264edbe2f084",
"body": "… profile (#241)\n\n* fix(verify): treat a missing signature.algorithm as a mismatch\n\nThe field is REQUIRED by spec 3.6 but sits outside the signing pre-image,\nand the verifier defaulted an absent identifier to Ed25519. A manifest\nwhose signature block carries no algorithm therefore verified as\nclassi\n[…]\n checked against rfc-editor.org rather than\nrecalled.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0011, the manifest is a signed document not a JWT/JOSE…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T04:33:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5bf5009b81ef50460199af67d36fae192dd12651",
"body": "… reference; release 0.6.0 (#238)\n\n* fix(cli): make the documented invocation the real one\n\nEvery command was attached to a redundant second `manifest` group, so the\nreal invocation was `manifest manifest verify signed.json` while the\nREADME, the docs site, the PyPI description, and this module's ow\n[…]\n executed against a clean\ninstall of the 0.6.0 wheel.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): make the documented invocation the real one; regenerate CLI…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T01:34:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a6fda8027f989114aec51c42b0840aa5172f0ffe",
"body": "…ng in getting-started (#237)\n\n* fix(verify): reject crypto_profile downgrade to a weaker signature\n\ncrypto_profile is inside the signing pre-image, but spec 3.6 excludes the\nwhole signature block from it, so signature.algorithm could be rewritten\nwithout disturbing the signed bytes. A manifest decl\n[…]\nthe comments match what the\nsnippets actually output.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(verify): reject crypto_profile downgrade; show verification faili…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-27T00:23:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "083ddb8575fbc487764de3738e2c2673ed23a82a",
"body": "…ce-vectors",
"is_bot": false,
"headline": "Merge pull request #199 from aditisingh02/feat/verification-conforman…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-25T00:55:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2abf3389c8b5175963b4366598c0f9b135c33733",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' into feat/verification-conformance-vectors",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-24T23:52:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af527a62c2c3d6c19779d59703acdd36b5ca8981",
"body": "docs: document Azure TDX offline-attestation limitation (MAA-required)",
"is_bot": false,
"headline": "Merge pull request #235 from agentrust-io/docs/azure-tdx-limitation",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-22T16:48:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "649c373e5f700fde060f73fbfaa85a224f650f21",
"body": "Confirmed on real Azure TDX hardware: TDX runs behind the Hyper-V paravisor,\nso there is no /dev/tdx-guest and the configfs-TSM tdx_guest provider does not\nregister (the guest driver cannot bind). The guest gets no signed DCAP quote,\nonly a MAC'd TDREPORT via the vTPM, which needs a networked servic\n[…]\ny on\nnon-paravisor guests (e.g. GCP C3); on Azure use SEV-SNP (AzureCVMProvider).\nAzure-MAA TDX support is tracked as a follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: document Azure TDX offline-attestation limitation (MAA-required)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-22T16:06:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "19621f4f3d2ff9453c75477f0198ae3e06e0d288",
"body": "feat(verify): generalized cert-chain verifier + lenient TDX parse (0.5.0)",
"is_bot": false,
"headline": "Merge pull request #234 from agentrust-io/feat/generalized-verifier-api",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T22:54:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b0defd76aa95bc5b5cf4c4d7c0b7471a1e742c0",
"body": "…5.0)\n\nGeneralizes agent-manifest's verification API so cmcp and ca2a can delegate\ntheir full SNP/TDX/TPM crypto here (via PyPI) instead of duplicating it, without\nchanging behavior or rewriting their fixtures. Backward compatible.\n\n- Add verify_cert_chain(chain, trusted_roots, *, root_fingerprint_h\n[…]\np's\n PKCS1v15 SNP chain + TPM parse-only and ca2a's EC chain are all now\n expressible via the public API.\n- Bump 0.4.0 -> 0.5.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(verify): generalized cert-chain verifier + lenient TDX parse (0.…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T22:52:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7cba6583186c9f8f6478a4cdd40ec6796fd9269e",
"body": "feat(tee): shared TPM 2.0 quote verifier + agent-manifest 0.4.0",
"is_bot": false,
"headline": "Merge pull request #233 from agentrust-io/feat/shared-tpm-verifier",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T22:22:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6054733a1d7071bf6c13f4d757aba7372b0381d1",
"body": "Adds `agent_manifest._tpm_verify` (parse_tpm_quote / verify_tpm_quote), the TPM\nanalogue of the SEV-SNP and TDX verifiers, so agent-manifest is the single\ncanonical hardware-verification library the org consolidates onto (cmcp and\nca2a will consume it via PyPI instead of carrying their own copies). \n[…]\nised\nwith synthetic vectors and not yet validated against a real TPM quote (unlike\nSEV-SNP/TDX) — noted in the module + CHANGELOG.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tee): add shared TPM 2.0 quote verifier; release 0.4.0",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T22:19:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5c2594335bbf5fd30b6748295a3952a8f2d7e6e1",
"body": "fix(tee): mark OPAQUE managed attestation explicitly not implemented",
"is_bot": false,
"headline": "Merge pull request #232 from agentrust-io/fix/opaque-not-implemented",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T21:50:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7aa7938f2c98941806929a038f1d7addf3df14df",
"body": "The OPAQUE managed attestation service is not generally available, and the SDK\nnever verified the TRACE claim it would return (no claim-signature check, no\nservice_measurement verification — issue #201 §5). Shipping a path that looks\nverified but is not is worse than none, so OPAQUEProvider now fail\n[…]\nQUE unit\ntests replaced with a fail-closed assertion.\n\nUse a locally-verifiable provider (SEV-SNP / TDX / Azure CVM) for Level 1+.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tee): mark OPAQUE managed attestation explicitly not implemented",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T21:45:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ad13dff69e495db6dcf8ebaaa6e52f85d9b39881",
"body": "feat(hw): Intel TDX DCAP quote verification (hardware-validated on GCP C3)",
"is_bot": false,
"headline": "Merge pull request #231 from agentrust-io/feat/tdx-quote-verification",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T21:36:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b996a079a3e72d36f5e108b2535110b34cbfb70",
"body": "…P C3\n\nCloses the TDX half of the \"shipped the binding without verification\" gap\n(#204/#228, from QinyuanWu's #201 review). Validated end to end on a real\nnon-paravisor Intel TDX guest (GCP C3, kernel 6.17): the configfs-TSM tdx_guest\nprovider returns a full DCAP quote (v4, ECDSA-P256), the guest co\n[…]\np + env-gated real vector); LIMITATIONS/CHANGELOG updated.\n\nAzure TDX (paravisor/vTPM-rooted, like Azure SNP) remains a follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(hw): Intel TDX DCAP quote verification, hardware-validated on GC…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T21:33:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c4aac0e51a1aeec52b97559889cb5d4e3bde2ea8",
"body": "…idated\n\ndocs: record bare-metal SEVSNPProvider hardware validation (GCP N2D)",
"is_bot": false,
"headline": "Merge pull request #230 from agentrust-io/docs/bare-metal-snp-gcp-val…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T19:53:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04f70abed667400ea1cf093e889503b60235ceaa",
"body": "The configfs-TSM SEVSNPProvider is now hardware-validated end to end on a\nnon-paravisor SEV-SNP guest (GCP N2D, AMD Milan): the manifest digest lands in\nthe guest-controlled REPORT_DATA and the report verifies against the AMD VCEK\nchain. Lifts the \"not yet validated on non-Azure SNP hardware\" caveat in the\nprovider docstrings and CHANGELOG. Docs only; no code change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: record bare-metal SEVSNPProvider hardware validation (GCP N2D)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T19:51:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d59b0b244643a85d92be37cad0580f29eea648c4",
"body": "docs(spec): house-style cleanup (de-bold, remove dashes; no normative changes)",
"is_bot": false,
"headline": "Merge pull request #229 from agentrust-io/docs/house-style-cleanup",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T19:24:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0e7897df1d713a26d6ffa3e8e9bbc1233199015",
"body": "Formatting and voice pass only. No normative changes: code blocks, tables,\nschema field names, RFC-2119 keywords, and all values are preserved.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(spec): house-style cleanup, remove bold emphasis and dashes",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T18:56:48Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0fc1f75ba27193545148c9a585da19e42d4c46d6",
"body": "…ypa/gh-action-pypi-publish-1.14.1",
"is_bot": false,
"headline": "Merge pull request #226 from agentrust-io/dependabot/github_actions/p…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T07:03:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e0e44d007ea8bca376c2ba9a016464cc2809e7e",
"body": null,
"is_bot": false,
"headline": "Merge pull request #227 from agentrust-io/feat/azure-cvm-hw-attestation",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T01:16:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b271fbdaad5c0a12469a5e14396a9b2d8904e87",
"body": "The configfs-TSM report dir (/sys/kernel/config/tsm/report) exists whenever\ntsm.ko is present, including on ordinary CI runners with no SNP provider\nregistered, so dir-existence alone wrongly selected SEVSNPProvider and fired\nthe hardware-integration test. Gate both the auto-selection and the\nNEEDS_SEV_SNP marker on /sys/module/sev_guest (the loaded driver), a specific\nnon-mutating signal of a real SNP guest.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(hw): gate SNP auto-detection on the loaded sev-guest driver",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T00:07:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7045cfe8f7d1cbd999b749f4cd053322bcd8b23c",
"body": "…ature backend\n\nValidated on a live Azure SEV-SNP confidential VM (DCasv5). Findings drove\nthe design: Azure runs SNP behind a Hyper-V paravisor, so there is no\n/dev/sev-guest and the guest cannot control REPORT_DATA (the paravisor binds\nthe vTPM AK there). The prior SEVSNPProvider ioctl path could \n[…]\nid-redacted) report vectors for parsing/binding; synthetic\n self-consistent crypto for signature/chain round-trips. Docs updated.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(hw): hardware-validated Azure CVM SEV-SNP attestation + SNP sign…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-21T00:03:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c8b7ea9f844202882480fc3473ed9b2c841bf934",
"body": "Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...ba38be9e\n[…]\n-name: pypa/gh-action-pypi-publish\n dependency-version: 1.14.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T02:25:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4650a58204e4791f706a7df5ce64d1d2ed66896f",
"body": "…(#225)",
"is_bot": false,
"headline": "ci(codeql): exclude deterministic test-vector fixtures from analysis …",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-20T01:05:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f841794982e15b7b2f2e32e2e0a0d3c1bf06186c",
"body": null,
"is_bot": false,
"headline": "docs: add PRIVACY.md (no data collected; local processing) (#224)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-16T23:40:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76b58915933d23b41e4d247778cc43dc27e7a06d",
"body": null,
"is_bot": false,
"headline": "Bind hybrid verification to combined key id (#221)",
"author_name": "Carlos Hernandez",
"author_login": "carloshvp",
"committed_at": "2026-07-16T03:20:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "188edab432bb91773b52ee84b5e29df8e0916a52",
"body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: upgrade setuptools before pip-audit (clears PYSEC-2026-3447) (#223)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-16T03:14:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e95ef8e2958753b0a692be14b21865ce0850747a",
"body": "Cuts the release of commits since python-v0.2.0: #220 (trusted_key_issuers verification binding, fail-closed) and #218 (delegation verifier public API). Minor bump; build + twine check pass; 0.3.0 wheel smoke-tested.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): agent-manifest python v0.3.0 (#222)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-15T23:07:34Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "192473f2d27c40fb5193c3b76fc1626afee6a972",
"body": null,
"is_bot": false,
"headline": "Bind trusted keys to manifest issuers (#220)",
"author_name": "Carlos Hernandez",
"author_login": "carloshvp",
"committed_at": "2026-07-07T20:45:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78fb58be680fd6893526c1dc388d38503599a974",
"body": null,
"is_bot": false,
"headline": "ci: pin gh-action-pypi-publish to commit SHA (v1.14.0) (#219)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-05T04:44:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bd4344bd99394c6178c5e8338fddcf1b33b73c5",
"body": "Export verify_delegation_chain, verify_hitl_approval, delegation_depth_exceeded,\nDelegationHopSigner, and HitlApprovalSigner from `agent_manifest`. These were\npreviously reachable only through the private `_delegation` module. Downstream\nprojects (agentrust-io/cA2A) call verify_delegation_chain to v\n[…]\nupported implementation is shared rather\nthan duplicated. No behavior change. Full suite: 538 passed.\n\nCloses agentrust-io/ca2a#16\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(sdk): expose the delegation verifier in the public API (#218)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-01T21:08:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "67c21dbf6cc04439f81df6d3e38088637c799968",
"body": "* feat(docs): SEO and AEO optimization\n\nMake the docs discoverable by search engines and answer engines (LLMs).\n\nAEO:\n- Generate /llms.txt and /llms-full.txt via mkdocs-llmstxt so LLMs and\n answer engines can ingest a curated, structured view of the docs.\n- Add robots.txt that explicitly welcomes G\n[…]\nher\nname in JSON-LD from AgentTrust to AgenTrust.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(docs): SEO and AEO optimization (#217)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-07-01T02:00:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9c7d9c1d14db38b0e4d17515c9e744ffd4bb295a",
"body": "Add a portable, signed test-vector suite (AM-VEC-001..019) for the verification engine, plus a Python test asserting the reference SDK reproduces every vector\n\nSigned-off-by: Aditi Singh <aditi.singh0205@gmail.com>",
"is_bot": false,
"headline": "test(verify): language-neutral verification conformance vectors",
"author_name": "Aditi Singh",
"author_login": "aditisingh02",
"committed_at": "2026-06-30T20:42:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63d5f8471734073aa3a5e9defd961006ca056dc6",
"body": "…ase governance step (#214)\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): install agent-governance-toolkit so agt CLI resolves in rele…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-30T20:16:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "47355f3a437e4eb86ee1774ef38bf6bfb519105c",
"body": "Bump version 0.1.1 -> 0.2.0 and record the 0.2.0 changelog (security\nhardening for delegation chains and scope-narrowing, fail-closed\nverification, SNP/TDX attestation corrections, PrincipalType fix).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): agent-manifest 0.2.0 (#213)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-30T20:11:44Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a496938411d15754e7b8b6b87979d18062a48715",
"body": "… (#212)\n\nThe delegation validator's VALID_PRINCIPAL_TYPES literal ({human, agent,\nservice}) disagreed with the canonical PrincipalType enum ({human, system,\nagent}): \"service\" existed only in the validator, \"system\" only in the enum.\nThe schema gate merged in #211 exposed this inconsistency.\n\nPrinc\n[…]\ndelegation cycle, exposed through module __getattr__) so\nthe two sets can never drift again. Add a test asserting they stay equal.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(delegation): reconcile principal-type set with PrincipalType enum…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-30T19:45:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5627d3a9aa60c2e2c5c03a5c5cc854ef0e037c74",
"body": "… schema-validate, honest CLI (#211)\n\nHardens the verification and delegation paths to fail closed in four places:\n\n1. Bind the delegation chain root to the manifest signing identity.\n verify_delegation_chain now takes an optional manifest_issuer; when the\n caller supplies it (verify_manifest pa\n[…]\nch fix. The kid->issuer authorization model and the hybrid\nper-component key_id selection are out of scope and tracked for Wave 2.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(verify): bind delegation root to issuer, enforce scope-narrowing,…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-30T19:25:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "207357602647589c469bcf7674c13b9bc24cae9d",
"body": "Adds _attestation.py with verify_attestation_chain(), which checks the\nsoftware-verifiable steps of boot-time attestation: the manifest-hash binding\nin REPORT_DATA and an optional launch-measurement allow-list. The hardware\nsignature / quote-chain step (VCEK, Intel QVL, TPM AK) is not implemented an\n[…]\ning work is a drop-in. Tests cover the software paths\nand the fail-closed behavior.\n\nAdvances #204 (does not close it). Refs #201.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(verify): attestation-chain verifier scaffold (#204 phase 1) (#210)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-30T03:47:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c0d1c01cc556637b3bb0668d6121eb88377d4582",
"body": "…(#209)\n\nSNP: the guest-supplied value lives in REPORT_DATA (offset 0x50, 64 bytes),\nnot the field the code read at 0x140 (which is REPORT_ID, and HOST_DATA is\nhost-set anyway). Read 0x50 for the boot and runtime reports, rename the\nraw key host_data -> report_data, and update the mocked tests + tut\n[…]\nP response-header wrapping, VCEK chain, and TDX Quote\nconversion remain hardware-validated work tracked in #204.\n\nRefs #201, #205.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(hw): read SNP REPORT_DATA at 0x50; correct TDX RTMR/Quote claims …",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-29T22:10:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0e9a8631bf121d8b2db91580525346fed8a41606",
"body": "…ides (#208)\n\nRewrite the 1.2 'Anthropic Design Test' box to drop 'impossible controls'\nand state precisely what hardware does (launch measurement in silicon, key\nsealed to measurement) versus what it does not (measure files/in-memory\nobjects after boot; a guest-supplied report field is an assertion\n[…]\nel 3 (OPAQUE) is the managed option,\nnot inherently higher assurance, and still requires claim-signature checks.\n\nRefs #201, #206.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: scope threat-model claims to what TEE attestation actually prov…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-29T21:58:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "85a688b6fdcfa0eefcdb01a3978b7eb15733b803",
"body": "…mark providers experimental (#207)\n\n* fix(attestation): correct SNP REPORT_DATA vs HOST_DATA in spec/docs; mark providers experimental\n\nThe guest-controlled SNP field is REPORT_DATA (64 bytes, via user_data), not\nHOST_DATA (host-set at launch, 32 bytes). Correct the runtime freshness path\n(spec 3.3\n[…]\nernance gate is red again. Re-apply on main here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(attestation): correct SNP REPORT_DATA vs HOST_DATA in spec/docs; …",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-29T19:19:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "46ca5625ac90bf62238c942ea3e10dc0bd0ae9a0",
"body": null,
"is_bot": false,
"headline": "docs: standardize OPAQUE brand capitalization (#200)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-29T13:32:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8ad1f9186f79ce264b36c6ce7095064c413a13d",
"body": "…tion and require_delegation (#197)\n\n* feat(verify): A2A delegation chain verification — closes #196\n\nThree changes:\n\n1. **require_delegation in VerifyRequest** — `VerificationContext` already had\n `require_delegation` but it was not exposed via the HTTP POST body. Callers\n can now pass `require\n[…]\nnt): remove unused InvalidSignature and verify_delegation_chain imports\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(verify): A2A delegation chain verification via structural valida…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-25T21:14:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "be2c5eb58855d8496288bcff882c7e89d2f5402e",
"body": "…95 (#198)\n\n* feat(governance): add agt verify CI step and release evidence artifacts\n\nCloses #195.\n\n- governance/manifest-enforcement.yaml: YAML policy descriptor with\n deny_by_default: true. Documents agent-manifest's default-deny identity\n governance: agents without a valid signed manifest are \n[…]\nt-core\n- F541: remove f prefix from string literal with no placeholders\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(governance): agt verify CI step and release evidence — closes #1…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-25T21:14:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b048cc33e62e860f5ba10c71f177250d426e08ca",
"body": "…) (#194)\n\n* feat: memory checkpoint/delta binding protocol (v0.2)\n\nImplement v0.2 incremental memory binding (spec §3.2.6.2): an append-only\noperation-log (RFC 9162 merkle-log) model that lets persistent memory evolve\nacross a session and proves the evolution was governed, without re-approving\nthe \n[…]\naude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nSigned-off-by: WulfForge <krknapp@gmail.com>\nCo-authored-by: WulfForge <krknapp@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(attestation): runtime freshness proofs via attest_runtime_state(…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-24T23:30:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e48cb94f92de998142430c23d49a044fb6b803f8",
"body": "* feat: memory checkpoint/delta binding protocol (v0.2)\n\nImplement v0.2 incremental memory binding (spec §3.2.6.2): an append-only\noperation-log (RFC 9162 merkle-log) model that lets persistent memory evolve\nacross a session and proves the evolution was governed, without re-approving\nthe whole store\n[…]\nt without re-approving the whole store.\n\n---------\n\nSigned-off-by: WulfForge <krknapp@gmail.com>\nCo-authored-by: WulfForge <krknapp@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: v0.2 memory checkpoint/delta binding protocol (§3.2.6.2) (#193)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-23T00:30:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4505dceb90ed4c8d0e53a545fb0e3732c6047196",
"body": "* feat: allow cli verify with public key\n\nSigned-off-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\n\n* fix(docs): correct tutorial hallucinations\n\n- Remove calls to ManifestId.generate() which does not exist; replace\n with uuid_utils.uuid7() across your-first-manifest, delegation-cha\n[…]\ned-off-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\nCo-authored-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(docs): correct tutorial hallucinations (#192)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-22T20:57:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "738207d7152410ad22d0972bac0213237730a95d",
"body": "* feat: allow cli verify with public key\n\nSigned-off-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\n\n* fix(docs): correct tutorial hallucinations\n\n- Remove calls to ManifestId.generate() which does not exist; replace\n with uuid_utils.uuid7() across your-first-manifest, delegation-cha\n[…]\ned-off-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\nCo-authored-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(docs): correct tutorial hallucinations (#191)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-22T20:14:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "22a6e437f39b022cd6761334e414e415487468c6",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v4...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n dependency-version: '7'\n depen\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 4 to 7 (#189)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T16:53:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0fe6db1ce8ef6fb347132179282ae08f03b76ce2",
"body": "Signed-off-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>\nCo-authored-by: Miracle778 <37257176+Miracle778@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(cli): allow CLI verify to accept a trusted public key",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-22T00:35:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ba76d62d0bfa8ea9dd6aacd1c547baf06287238",
"body": "- spec/agent-manifest-spec-v0.1.md: remove ServiceNow, JPMC, and\n Across AI from the v0.2 roadmap section; replace with generic\n community feedback framing\n- ADOPTERS.md: rename \"Design partners (v0.1 preview)\" section to\n \"Founding contributors\" to avoid implying a closed commercial program\n- ROADMAP.md: replace \"design-partner feedback\" with \"community and\n early adopter feedback\" in both roadmap entries\n\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>",
"is_bot": false,
"headline": "fix: remove partner names and commercial-program language (#187)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-22T00:21:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e6eb074513a80148c01fbec8a9fe10a5a08d940c",
"body": null,
"is_bot": false,
"headline": "release: bump version to 0.1.1",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T21:02:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be1a2c41e41eb105ef64cec3a2bb2a0342cd89d0",
"body": "…#186)\n\n- tutorials/index.md: fix hitl-approvals.md → hitl-approval-workflows.md,\n revocation.md → revocation-and-key-rotation.md,\n deploy-verifier.md → deploying-the-verification-endpoint.md;\n add Getting Started group with three new tutorials\n- integrations/langchain.md, agt.md, autogen-crewai.\n[…]\ntion.md link\n- operations/index.md: fix deploy-verifier.md link\n- cmcp-session-binding.md: remove stale PR #323 references, use version number\n\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>",
"is_bot": false,
"headline": "docs: fix dead links across tutorials, integrations, and operations (…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T20:56:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a61a0bf19100148f7a7604359ec7c39c55f2ad17",
"body": null,
"is_bot": false,
"headline": "docs: add supernav extra_javascript",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T20:53:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c02dcbc97e37a996bdd4fb2968e4b0416dd9de73",
"body": "…er) (#185)\n\nReplace AGT purple (#8251EE) with cmcp violet (#7c3aed), update dark mode\nbg to #0f0a1e, swap light header + accent strip for dark gradient header,\nremove supernav.js external script.\n\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>",
"is_bot": false,
"headline": "style: align docs theme with cmcp (violet palette, dark gradient head…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T17:50:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ae3a0fd452ab7c8a6398ea6d8c5d9737912fe41",
"body": "Remove hitl-approvals.md, revocation.md, and deploy-verifier.md (content merged\ninto their counterparts). Add your-first-manifest.md, ci-cd-signing.md, and\ncmcp-session-binding.md.\n\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(tutorials): dedup tutorial pairs and add three new tutorials (#184)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T17:14:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6f4ce6b70de585e4a0fad2b3d2e93ab6c1032cb2",
"body": "…penSSF badge, shorten to hub",
"is_bot": false,
"headline": "docs: clean landing page README — fix Discord badge, remove invalid O…",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T17:11:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "edfb185d18d030c10508cff27df04e7cb58d7950",
"body": null,
"is_bot": false,
"headline": "Create CNAME",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T04:53:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e087364090caa5ac469df7a050891b5bfec158c9",
"body": null,
"is_bot": false,
"headline": "Delete CNAME",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-21T04:53:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bef95fdc0ea38397835742fa7accc69a62abb4c8",
"body": null,
"is_bot": false,
"headline": "docs: add agentrust super-navigation bar to all pages",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-20T21:27:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5c71a284b839b85243ef617ec6a3af91170f4152",
"body": null,
"is_bot": false,
"headline": "Create CNAME",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-20T02:01:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4401971a69117efa1ff3590efad0818582e5d4c6",
"body": null,
"is_bot": false,
"headline": "Delete CNAME",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-20T02:01:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "81e177641754af7a7b123fc1d3a1734070175bdd",
"body": null,
"is_bot": false,
"headline": "Create CNAME",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-20T01:54:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "66f295d6619cf5b34d1a54cdcdd8176565382ca6",
"body": "…or workload measurement. (#179)\n\nSigned-off-by: Qiang Xu <qiang@opaque.co>",
"is_bot": false,
"headline": "fix: HostData in AMD-SNP has 32 bytes; RTMR3 in TDX is usually used f…",
"author_name": "Qiang Xu",
"author_login": "Qiang-Xu",
"committed_at": "2026-06-18T19:06:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e240265a4f28d0be434076c1addbe0d3b287a71",
"body": "- Primary color → #8251EE (AGT NextGen Purple), system font stack\n- Teal→purple→violet gradient accent strip in header (matches AGT)\n- Dark mode bg → #0d1117 (GitHub-neutral), plain header canvas\n- Icon.svg gradient updated to teal→#8251EE→#C661F7\n- Primer-style h2 border-bottom, tables, code, admon\n[…]\nrl: https://manifest.agentrust-io.com\n- README badge updated to manifest.agentrust-io.com\n- docs.yml: add concurrency block + git config step\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "style: align visual theme with AGT + enable custom domain (#180)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-18T18:35:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4fd945cdafb6df6e91d7f20927b3d5a00a8511e7",
"body": "- add root .gitignore (block .claude/ and temp dirs from accidental commit)\n- enable CodeQL SARIF upload (was upload: never)\n- replace spiffe://example.opaque.co with spiffe://trust.example in spec\n- fix spec footer: Opaque Systems → AgentTrust\n- replace hardcoded attest.opaque.co URL with placeholder in tutorial\n- warn when SEVSNPProvider runs without VCEK verification\n\nSigned-off-by: Imran Siddique <imran.siddique@opaque.co>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "security: pre-launch hardening fixes (#181)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-18T18:30:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1297c223d68fdaf95ac9438d9de844597281a3c2",
"body": "Add normative runtime-session binding guidance to the spec for gateways such as\ncMCP: the signed fields that bind agent_id and artifact hashes, validity-window\nchecks, delegation handling, and the attestation separation. The package-root\nexport of the verification API is handled separately in #176.\n\nCloses #175.\n\nSigned-off-by: Carlos Hernandez <carloshvp@gmail.com>\nCo-authored-by: Carlos Hernandez <carloshvp@gmail.com>",
"is_bot": false,
"headline": "docs: define runtime manifest binding contract (spec) (#178)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-18T16:47:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ab24ac779fa203b7fe69d70195863a8ae87b5646",
"body": "… root (#176)\n\n* feat(sdk): export the relying-party verification API from the package root\n\nThe verification engine (verify_manifest and its result/context types) lives in\nthe private agent_manifest._verify module and is documented in\ndocs/api-reference/verification.md, but it is not exported from \n[…]\n from the review. The cMCP migration to call this export\nis tracked separately.\n\nSigned-off-by: Carlos Hernandez <carloshvp@gmail.com>\n\n---------\n\nSigned-off-by: Carlos Hernandez <carloshvp@gmail.com>",
"is_bot": false,
"headline": "feat(sdk): export the relying-party verification API from the package…",
"author_name": "Carlos Hernandez",
"author_login": "carloshvp",
"committed_at": "2026-06-18T16:36:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4a5a2f26fef558c8417d3c7faf51978b7387fb6e",
"body": "Bumps python/pyproject.toml version 0.1.0a1 → 0.1.0.\nAdds stable [0.1.0] CHANGELOG entry covering the three fixes shipped\nsince alpha: poisoning_scan verifier enforcement, model/signing alignment,\nand transparency log error path coverage.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: promote to v0.1.0 stable for CC Summit launch (#170)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-15T22:09:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a4b4fb02fb87727982de736fbaf01ac80bd5b0f8",
"body": null,
"is_bot": true,
"headline": "chore(deps): update cryptography requirement in /python (#169)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T17:58:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d050b37a9eab8c17906dbd331bb4f87926187a34",
"body": "Add test_transparency.py (14 tests) covering publish_to_rekor and\nverify_transparency_log_entry via unittest.mock.patch on httpx — success\npaths, non-2xx errors, network errors, hash mismatch, and URL routing.\nAppend 17 tests to test_signing.py covering Ed25519KeyPair repr/str/\nprivate_b64url, ed255\n[…]\n\nwrong-length key rejection, and signed_at ISO 8601 regression guard for\n#165. Coverage: _transparency.py 38% -> 94%, _signing.py 67% -> 71%.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: mock transparency log and signing error path coverage (#168)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-13T04:35:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f8362df833cebfec174c490b072f24e7398e8886",
"body": "Add `warnings` field to `VerificationResult` and `conformance_level` to\n`VerificationContext`. In `verify_manifest`, after the RAG corpus Merkle\nroot check: `flagged` appends a mismatch (non-VALID at any level);\n`not-scanned` at Level 1+ appends a mismatch; `not-scanned` at Level 0\nappends a warning (VALID). `clean` and absent rag_corpus are unaffected.\nNine new tests cover all five spec 3.2.5.1 cases plus regressions.",
"is_bot": false,
"headline": "fix: enforce poisoning_scan.result rules in verifier (#153) (#167)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T23:10:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21b0e236886374dfe7ac2ef677f6bb239c7c66cc",
"body": "GitHub Advanced Security is not enabled on private repos.\nSARIF upload will be re-enabled on June 23 when the repo goes public.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: skip SARIF upload while repo is private (#166)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T22:55:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "94a3e50eca58b9d7257bc207b31b2213777e1450",
"body": "Model alignment (spec is normative):\n- ToolEntry: name/server_id renamed to tool_name/endpoint_id; tool_id,\n schema_hash, description_hash required (spec 3.2.3)\n- ModelIdentityBinding: add model_attestation_type with hash-bound /\n provider-asserted conditionality on deployment_type (spec 3.2.4)\n- \n[…]\n approval_required,\n risk_classification/hitl_approval, scope_grant classifications\n- tutorials show fail-closed verification with trusted_keys\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: align models, examples, and signing to the spec (#165)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T22:53:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8832dd64123c6d6082107aa105cc17206f4fc5a4",
"body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add community Discord invite (#164)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T20:51:31Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "996ad18f6b9148c4fbe7df40d6d71fc045d11090",
"body": null,
"is_bot": false,
"headline": "fix: restore fail-closed verifier lost in the stacked-PR merge (#163)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T16:12:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b02496f0bc8415b4055cab49b779f9957f2f0de",
"body": null,
"is_bot": false,
"headline": "fix(workflows): skip maintainer gate for maintainer-authored PRs (#162)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T02:31:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3beb82ccdd3642edfc46f6312cefd94e10fac032",
"body": null,
"is_bot": false,
"headline": "fix(ci): repair Scorecard workflow for private repo (#161)",
"author_name": "Imran Siddique",
"author_login": "imran-siddique",
"committed_at": "2026-06-12T02:30:36Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 12,
"commits_last_year": 263,
"latest_release_at": "2026-08-02T04:07:00Z",
"latest_release_tag": "python-v0.10.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 9,
"days_since_latest_release": 0,
"mean_days_between_releases": 4.6
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "agent-manifest",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"agent-manifest",
"ai-agents",
"attestation",
"confidential-computing",
"governance",
"hardware-attestation",
"mcp",
"pydantic",
"tee",
"trust",
"Development Status :: 3 - Alpha",
"Intended Audience :: Developers",
"License :: OSI Approved :: Apache Software License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Topic :: Security :: Cryptography",
"Topic :: Software Development :: Libraries :: Python Modules",
"Topic :: System :: Monitoring",
"Typing :: Typed"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/agent-manifest/",
"is_deprecated": false,
"latest_version": "0.10.0",
"repository_url": "https://github.com/agentrust-io/agent-manifest",
"versions_count": 13,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 4734,
"first_published_at": "2026-06-04T17:48:57.111673Z",
"latest_published_at": "2026-08-02T04:07:52.533059Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 5,
"stars": 11,
"watchers": 2,
"fork_history": {
"days": [
{
"date": "2026-06-21",
"count": 1
},
{
"date": "2026-06-22",
"count": 1
},
{
"date": "2026-06-27",
"count": 1
},
{
"date": "2026-07-06",
"count": 1
},
{
"date": "2026-07-31",
"count": 1
}
],
"complete": true,
"collected": 5,
"total_forks": 5
},
"star_history": null,
"open_issues_and_prs": 6
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 40078,
"source_files_sampled": 54,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"python/pyproject.toml",
"requirements-docs.txt"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 21,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "pydantic",
"manifest": "python/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.7,<3"
},
{
"name": "cryptography",
"manifest": "python/pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=42,<50"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "cryptography",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "bandit",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "click",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "fastapi",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "griffe",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jcs",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mkdocs",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mkdocs-llmstxt",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mkdocs-material",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mkdocs-minify-plugin",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mkdocstrings",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pip-audit",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pymdown-extensions",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyoqs",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-asyncio",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "uvicorn",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 21,
"direct_count": 2,
"indirect_count": 19
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 121,
"open_issues": 6,
"closed_ratio": 0.955,
"closed_issues": 128,
"closed_unmerged_prs": 7
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "imran-siddique",
"commits": 243,
"avatar_url": "https://avatars.githubusercontent.com/u/45405841?v=4"
},
{
"type": "User",
"login": "carloshvp",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/14369242?v=4"
},
{
"type": "User",
"login": "AaronRoeF",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/45860746?v=4"
},
{
"type": "User",
"login": "aditisingh02",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/140513260?v=4"
},
{
"type": "User",
"login": "Qiang-Xu",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/29718352?v=4"
}
],
"contributors_sampled": 5,
"top_contributor_share": 0.976
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"contributor-check.yml",
"docs.yml",
"publish.yml",
"require-maintainer-approval.yml",
"sbom.yml",
"scorecard.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 6,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 1/23 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 8,
"reason": "SAST tool detected but not run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 7,
"reason": "3 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "53800042ac0370a13c7262b0dbc5243b63135281",
"ran_at": "2026-08-02T04:11:50Z",
"aggregate_score": 5.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-08-02T04:07:38Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-08-02T04:06:58Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 204,
"created_at": "2026-06-29T17:19:54Z",
"last_comment_at": "2026-06-30T03:47:46Z",
"last_comment_author": "imran-siddique"
},
{
"number": 236,
"created_at": "2026-07-22T16:07:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 243,
"created_at": "2026-07-27T04:53:53Z",
"last_comment_at": "2026-07-27T21:03:12Z",
"last_comment_author": "imran-siddique"
},
{
"number": 254,
"created_at": "2026-07-31T18:57:23Z",
"last_comment_at": "2026-07-31T18:57:50Z",
"last_comment_author": "github-actions"
},
{
"number": 255,
"created_at": "2026-08-01T02:20:52Z",
"last_comment_at": "2026-08-01T20:47:17Z",
"last_comment_author": "imran-siddique"
},
{
"number": 256,
"created_at": "2026-08-01T02:30:21Z",
"last_comment_at": "2026-08-01T17:47:37Z",
"last_comment_author": "imran-siddique"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/agentrust-io/agent-manifest",
"host": "github.com",
"name": "agent-manifest",
"owner": "agentrust-io"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"security": 52,
"vitality": 72,
"community": 54,
"governance": 58,
"engineering": 67
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 72,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"commits_last_year": 263,
"human_commit_share": 0.95,
"days_since_last_push": 0,
"active_weeks_last_year": 9
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "9/52 weeks with commits",
"points": 6.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 9
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "263 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 263
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 12,
"latest_release_tag": "python-v0.10.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 4.6
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "12 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 12
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~4.6 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 4.6
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 54,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 21,
"inputs": {
"forks": 5,
"stars": 11,
"watchers": 2,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "11 stars",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 11
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "5 forks",
"points": 5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 5
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "2 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 2
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 86,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 61,
"inputs": {
"packages": [
"agent-manifest"
],
"dependents": null,
"ecosystems": "pypi",
"total_downloads": null,
"monthly_downloads": 4734
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "4,734 downloads/month across pypi",
"points": 49,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 4734,
"ecosystems": "pypi"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 58,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 5,
"top_contributor_share": 0.976
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 98% of commits",
"points": 0.5,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 98
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "5 contributors",
"points": 6.8,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 5
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"merged_prs": 121,
"open_issues": 6,
"closed_issues": 128,
"issue_closed_ratio": 0.955,
"closed_unmerged_prs": 7
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "96% of issues closed",
"points": 44.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 96
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "121/128 decided PRs merged",
"points": 36.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 121,
"decided": 128
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 1/23 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"followers": 49,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "agentrust-io",
"public_repos": 11,
"account_age_days": 59
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "49 followers of agentrust-io",
"points": 12.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 49,
"login": "agentrust-io"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "11 public repos, account ~0 yr old",
"points": 8.2,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 11
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"agent-manifest"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "13 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 13
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 67,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "8 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 8
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 52,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 5.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 1/23 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool detected but not run on all commits",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "3 existing vulnerabilities detected",
"points": 5.2,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 6
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 42,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.937,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "89 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 89,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.53,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "53 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 53,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 40078,
"source_files_sampled": 54,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/54 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 54,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.14.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index pypi:agent-manifest@0.10.0; advisories assessed against the repository dependency graph instead",
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-08-02T04:12:07.732481Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agentrust-io/agent-manifest.svg",
"full_name": "agentrust-io/agent-manifest",
"license_state": "custom",
"license_spdx": null
}