公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 08:57 UTC

aminazar / slowcook

TypeScriptMIT★ 2 星标⑂ 0 复刻始于 2026年4月在 GitHub 上查看 ↗

aminazar/slowcook 的健康指数为 100 分中的 56 分,处于「中等」区间。 其得分最高的类别是AI Readiness(76/100),最低的是Community & Adoption(40/100)。 最近一次更新在 2 天前。 近期的大部分工作由 1 位贡献者完成。

56
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

56
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

aminazar个人账户
5 关注者5 个公开仓库始于 2016年2月@bentoaksystems

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

73良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 2 天前
9.7/36提交节奏 — 52 周中有 14 周有提交
18/18提交量 — 最近一年 605 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year605
human_commit_share0.97
days_since_last_push2
active_weeks_last_year14

发布纪律

72良好
评分方式
16.2/27有发布版本 — 1 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 88 天前
12.6/27发布节奏 — 节奏未知(仅一次发布)
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count1
latest_release_tag0.13.0
releases_from_tags
days_since_latest_release88
mean_days_between_releases
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

40存在风险 · 占总体的 18%
评分方式
0/60星标 — 2 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
49.4/80月度下载量 — npm 合计每月 5,078 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@slowcook-ai/cli, @slowcook-ai/core, @slowcook-ai/gates, @slowcook-ai/observe, @slowcook-ai/recorder, @slowcook-ai/stack-ts, @slowcook-ai/forge-github, @slowcook-ai/mock-runtime
dependents
ecosystemsnpm
total_downloads
monthly_downloads5,078
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

47存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
6/10OpenSSF Scorecard:Contributors — project has 2 contributing companies or organizations -- score normalized to 6
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
11.7/46.8议题解决 — 25% 的议题已关闭
36.8/38.3PR 接受 — 已裁定的 PR 中 224/233 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/29 approved changesets -- score normalized to 0
所用输入
merged_prs224
open_issues45
closed_issues15
issue_closed_ratio0.25
closed_unmerged_prs9
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
5.6/25所有者影响力 — aminazar 有 5 位关注者
17.7/25既往记录 — 5 个公开仓库,账户约 10 年
所用输入
followers5
owner_typeUser
is_verified
owner_loginaminazar
public_repos5
account_age_days3,797
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 8 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 143 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@slowcook-ai/cli, @slowcook-ai/core, @slowcook-ai/gates, @slowcook-ai/observe, @slowcook-ai/recorder, @slowcook-ai/stack-ts, @slowcook-ai/forge-github, @slowcook-ai/mock-runtime
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

63中等 · 占总体的 20%

工程实践

62中等
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
14/20OpenSSF Scorecard:CI-Tests — 20 out of 28 merged PRs checked by a CI test -- score normalized to 7
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

65中等
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

56中等 · 占总体的 16%

安全态势

45存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
1.8/2.5CI-Tests — 20 out of 28 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 24 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4.5
已排除计分(无数据或不适用):branch_protection, packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories24
affected_packages8
assessed_packages224
unassessed_packages15
affected_by_severitycritical 1, high 5, moderate 2
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 224 个已解析依赖与 OSV 比对。 有 15 项无法评估——没有已解析的版本、生态系统不受支持,或超出所报告的软件包清单。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

76良好 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 97 次人类提交中有 94 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.969
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes14,021
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/forge-github/tsconfig.json, packages/gates/tsconfig.json, packages/llm-anthropic/tsconfig.json, packages/mock-runtime/tsconfig.json, packages/observe/tsconfig.json, packages/recorder/tsconfig.json, packages/review-overlay/tsconfig.json, packages/stack-ts/tsconfig.json, tsconfig.json
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 56 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 3 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configspackages/cli/tsconfig.json, packages/core/tsconfig.json, packages/forge-github/tsconfig.json, packages/gates/tsconfig.json, packages/llm-anthropic/tsconfig.json, packages/mock-runtime/tsconfig.json, packages/observe/tsconfig.json, packages/recorder/tsconfig.json, packages/review-overlay/tsconfig.json, packages/stack-ts/tsconfig.json, tsconfig.json
agent_commit_share0.56
toolchain_manifests
dependency_bot_commit_share0.03
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
54.3/55可控的文件大小 — 采样的 401 个源文件中有 5 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes149,716
source_files_sampled401
oversized_source_files5

关键数据

2GitHub 星标
1贡献者
605最近 12 个月提交数
2距最近推送天数
1发布版本数
1巴士系数(bus factor)
45开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index npm:@slowcook-ai/cli@0.28.0; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 4.5 / 10
4.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 08:57 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
7CI-Tests20 out of 28 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities24 existing vulnerabilities detected
直接依赖 19
注册表软件包版本约束清单文件
npm@slowcook-ai/coreworkspace:^packages/cli/package.json
npm@slowcook-ai/stack-tsworkspace:^packages/cli/package.json
npm@slowcook-ai/forge-githubworkspace:^packages/cli/package.json
npm@slowcook-ai/llm-anthropicworkspace:^packages/cli/package.json
npm@slowcook-ai/recorderworkspace:^packages/cli/package.json
npm@slowcook-ai/review-overlayworkspace:^packages/cli/package.json
npm@slowcook-ai/gatesworkspace:^packages/cli/package.json
npm@anthropic-ai/sdk^0.106.0packages/cli/package.json
npm@octokit/rest^22.0.1packages/cli/package.json
npm@playwright/test^1.61.0packages/cli/package.json
npmts-morph^28.0.0packages/cli/package.json
npmyaml^2.9.0packages/cli/package.json
npmzod^4.4.3packages/cli/package.json
npm@slowcook-ai/coreworkspace:^packages/forge-github/package.json
npm@octokit/rest^22.0.1packages/forge-github/package.json
npm@slowcook-ai/coreworkspace:^packages/llm-anthropic/package.json
npm@anthropic-ai/sdk^0.106.0packages/llm-anthropic/package.json
npm@slowcook-ai/coreworkspace:^packages/mock-runtime/package.json
npm@slowcook-ai/coreworkspace:^packages/stack-ts/package.json
全部依赖 239

来自 GitHub 依赖图的完整解析依赖集合:12 个直接依赖与 227 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@anthropic-ai/sdk0.106.0直接
npm@anthropic-ai/sdk^0.106.0直接
npm@octokit/rest22.0.1直接
npm@octokit/rest^22.0.1直接
npm@playwright/test1.61.1直接
npm@playwright/test^1.61.0直接
npmts-morph28.0.0直接
npmts-morph^28.0.0直接
npmyaml2.9.0直接
npmyaml^2.9.0直接
npmzod4.4.3直接
npmzod^4.4.3直接
npm@asamuzakjp/css-color5.1.11间接
npm@asamuzakjp/dom-selector7.1.1间接
npm@asamuzakjp/generational-cache1.0.1间接
npm@asamuzakjp/nwsapi2.3.9间接
npm@babel/runtime7.29.7间接
npm@bramus/specificity2.4.2间接
npm@csstools/color-helpers6.0.2间接
npm@csstools/css-calc3.2.0间接
npm@csstools/css-color-parser4.1.0间接
npm@csstools/css-parser-algorithms4.0.0间接
npm@csstools/css-syntax-patches-for-csstree1.1.3间接
npm@csstools/css-tokenizer4.0.0间接
npm@emnapi/runtime1.11.1间接
npm@esbuild/aix-ppc640.21.5间接
npm@esbuild/android-arm0.21.5间接
npm@esbuild/android-arm640.21.5间接
npm@esbuild/android-x640.21.5间接
npm@esbuild/darwin-arm640.21.5间接
npm@esbuild/darwin-x640.21.5间接
npm@esbuild/freebsd-arm640.21.5间接
npm@esbuild/freebsd-x640.21.5间接
npm@esbuild/linux-arm0.21.5间接
npm@esbuild/linux-arm640.21.5间接
npm@esbuild/linux-ia320.21.5间接
npm@esbuild/linux-loong640.21.5间接
npm@esbuild/linux-mips64el0.21.5间接
npm@esbuild/linux-ppc640.21.5间接
npm@esbuild/linux-riscv640.21.5间接
npm@esbuild/linux-s390x0.21.5间接
npm@esbuild/linux-x640.21.5间接
npm@esbuild/netbsd-x640.21.5间接
npm@esbuild/openbsd-x640.21.5间接
npm@esbuild/sunos-x640.21.5间接
npm@esbuild/win32-arm640.21.5间接
npm@esbuild/win32-ia320.21.5间接
npm@esbuild/win32-x640.21.5间接
npm@exodus/bytes1.15.0间接
npm@img/colour1.1.0间接
npm@img/sharp-darwin-arm640.34.5间接
npm@img/sharp-darwin-x640.34.5间接
npm@img/sharp-libvips-darwin-arm641.2.4间接
npm@img/sharp-libvips-darwin-x641.2.4间接
npm@img/sharp-libvips-linux-arm1.2.4间接
npm@img/sharp-libvips-linux-arm641.2.4间接
npm@img/sharp-libvips-linux-ppc641.2.4间接
npm@img/sharp-libvips-linux-riscv641.2.4间接
npm@img/sharp-libvips-linux-s390x1.2.4间接
npm@img/sharp-libvips-linux-x641.2.4间接
npm@img/sharp-libvips-linuxmusl-arm641.2.4间接
npm@img/sharp-libvips-linuxmusl-x641.2.4间接
npm@img/sharp-linux-arm0.34.5间接
npm@img/sharp-linux-arm640.34.5间接
npm@img/sharp-linux-ppc640.34.5间接
npm@img/sharp-linux-riscv640.34.5间接
npm@img/sharp-linux-s390x0.34.5间接
npm@img/sharp-linux-x640.34.5间接
npm@img/sharp-linuxmusl-arm640.34.5间接
npm@img/sharp-linuxmusl-x640.34.5间接
npm@img/sharp-wasm320.34.5间接
npm@img/sharp-win32-arm640.34.5间接
npm@img/sharp-win32-ia320.34.5间接
npm@img/sharp-win32-x640.34.5间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@next/env16.2.9间接
npm@next/swc-darwin-arm6416.2.9间接
npm@next/swc-darwin-x6416.2.9间接
npm@next/swc-linux-arm64-gnu16.2.9间接
npm@next/swc-linux-arm64-musl16.2.9间接
npm@next/swc-linux-x64-gnu16.2.9间接
npm@next/swc-linux-x64-musl16.2.9间接
npm@next/swc-win32-arm64-msvc16.2.9间接
npm@next/swc-win32-x64-msvc16.2.9间接
npm@octokit/auth-token6.0.0间接
npm@octokit/core7.0.6间接
npm@octokit/endpoint11.0.3间接
npm@octokit/graphql9.0.3间接
npm@octokit/openapi-types27.0.0间接
npm@octokit/plugin-paginate-rest14.0.0间接
npm@octokit/plugin-request-log6.0.0间接
npm@octokit/plugin-rest-endpoint-methods17.0.0间接
npm@octokit/request10.0.9间接
npm@octokit/request-error7.1.0间接
npm@octokit/types16.0.0间接
npm@rollup/rollup-android-arm-eabi4.60.2间接
npm@rollup/rollup-android-arm644.60.2间接
npm@rollup/rollup-darwin-arm644.60.2间接
npm@rollup/rollup-darwin-x644.60.2间接
npm@rollup/rollup-freebsd-arm644.60.2间接
npm@rollup/rollup-freebsd-x644.60.2间接
npm@rollup/rollup-linux-arm-gnueabihf4.60.2间接
npm@rollup/rollup-linux-arm-musleabihf4.60.2间接
npm@rollup/rollup-linux-arm64-gnu4.60.2间接
npm@rollup/rollup-linux-arm64-musl4.60.2间接
npm@rollup/rollup-linux-loong64-gnu4.60.2间接
npm@rollup/rollup-linux-loong64-musl4.60.2间接
npm@rollup/rollup-linux-ppc64-gnu4.60.2间接
npm@rollup/rollup-linux-ppc64-musl4.60.2间接
npm@rollup/rollup-linux-riscv64-gnu4.60.2间接
npm@rollup/rollup-linux-riscv64-musl4.60.2间接
npm@rollup/rollup-linux-s390x-gnu4.60.2间接
npm@rollup/rollup-linux-x64-gnu4.60.2间接
npm@rollup/rollup-linux-x64-musl4.60.2间接
npm@rollup/rollup-openbsd-x644.60.2间接
npm@rollup/rollup-openharmony-arm644.60.2间接
npm@rollup/rollup-win32-arm64-msvc4.60.2间接
npm@rollup/rollup-win32-ia32-msvc4.60.2间接
npm@rollup/rollup-win32-x64-gnu4.60.2间接
npm@rollup/rollup-win32-x64-msvc4.60.2间接
npm@stablelib/base641.0.1间接
npm@swc/helpers0.5.15间接
npm@ts-morph/common0.29.0间接
npm@types/estree1.0.8间接
npm@types/node26.0.1间接
npm@types/node^26.0.1间接
npm@types/react19.2.15间接
npm@types/react^19.2.15间接
npm@types/react-dom19.2.3间接
npm@types/react-dom^19间接
npm@vitest/expect2.1.9间接
npm@vitest/mocker2.1.9间接
npm@vitest/pretty-format2.1.9间接
npm@vitest/runner2.1.9间接
npm@vitest/snapshot2.1.9间接
npm@vitest/spy2.1.9间接
npm@vitest/utils2.1.9间接
npmassertion-error2.0.1间接
npmbalanced-match4.0.4间接
npmbaseline-browser-mapping2.10.37间接
npmbefore-after-hook4.0.0间接
npmbidi-js1.0.3间接
npmbrace-expansion5.0.6间接
npmcac6.7.14间接
npmcaniuse-lite1.0.30001799间接
npmchai5.3.3间接
npmcheck-error2.1.3间接
npmclient-only0.0.1间接
npmcode-block-writer13.0.3间接
npmcontent-type2.0.0间接
npmcss-tree3.2.1间接
npmcsstype3.2.3间接
npmdata-urls7.0.0间接
npmdebug4.4.3间接
npmdecimal.js10.6.0间接
npmdeep-eql5.0.2间接
npmdetect-libc2.1.2间接
npmentities8.0.0间接
npmes-module-lexer1.7.0间接
npmesbuild0.21.5间接
npmestree-walker3.0.3间接
npmexpect-type1.3.0间接
npmfast-content-type-parse3.0.0间接
npmfast-sha2561.3.0间接
npmfdir6.5.0间接
npmfsevents2.3.2间接
npmfsevents2.3.3间接
npmhtml-encoding-sniffer6.0.0间接
npmis-potential-custom-element-name1.0.1间接
npmjsdom29.1.1间接
npmjsdom^29.1.1间接
npmjson-schema-to-ts3.1.1间接
npmjson-with-bigint3.5.8间接
npmloupe3.2.1间接
npmlru-cache11.3.6间接
npmmagic-string0.30.21间接
npmmdn-data2.27.1间接
npmminimatch10.2.5间接
npmms2.1.3间接
npmnanoid3.3.12间接
npmnext16.2.9间接
npmnext^16.2.9间接
npmparse58.0.1间接
npmpath-browserify1.0.1间接
npmpathe1.1.2间接
npmpathval2.0.1间接
npmpicocolors1.1.1间接
npmpicomatch4.0.4间接
npmplaywright1.61.1间接
npmplaywright-core1.61.1间接
npmpostcss8.4.31间接
npmpostcss8.5.15间接
npmpunycode2.3.1间接
npmreact19.2.6间接
npmreact19.2.7间接
npmreact^19.2.6间接
npmreact^19.2.7间接
npmreact-dom19.2.7间接
npmreact-dom^19.2.7间接
npmrequire-from-string2.0.2间接
npmrollup4.60.2间接
npmrustwright^0.1.1间接
npmsaxes6.0.0间接
npmscheduler0.27.0间接
npmsemver7.8.4间接
npmsharp0.34.5间接
npmsiginfo2.0.0间接
npmsource-map-js1.2.1间接
npmstackback0.0.2间接
npmstandardwebhooks1.0.0间接
npmstd-env3.10.0间接
npmstyled-jsx5.1.6间接
npmsymbol-tree3.2.4间接
npmtinybench2.9.0间接
npmtinyexec0.3.2间接
npmtinyglobby0.2.16间接
npmtinypool1.1.1间接
npmtinyrainbow1.2.0间接
npmtinyspy3.0.2间接
npmtldts7.0.30间接
npmtldts-core7.0.30间接
npmtough-cookie6.0.1间接
npmtr466.0.0间接
npmts-algebra2.0.0间接
npmtslib2.8.1间接
npmtypescript6.0.3间接
npmundici7.25.0间接
npmundici-types8.3.0间接
npmuniversal-user-agent7.0.3间接
npmvite5.4.21间接
npmvite-node2.1.9间接
npmvitest2.1.9间接
npmw3c-xmlserializer5.0.0间接
npmwebidl-conversions8.0.1间接
npmwhatwg-mimetype5.0.0间接
npmwhatwg-url16.0.1间接
npmwhy-is-node-running2.3.0间接
npmxml-name-validator5.0.0间接
npmxmlchars2.2.0间接
依赖安全公告 8

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 224 个包,其中也包含从不交付的开发与测试版本固定:8 个存在已知公告,0 个为直接依赖。 有 15 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。

软件包版本关系严重程度公告数修复版本
vitest2.1.9间接严重14.1.0
brace-expansion5.0.6间接15.0.7
next16.2.9间接916.2.11
sharp0.34.5间接10.35.0
undici7.25.0间接78.5.0
vite5.4.21间接38.0.16
esbuild0.21.5间接10.25.0
postcss8.4.31间接18.5.10

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 4788,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 14670,
        "JavaScript": 18399,
        "TypeScript": 3526764
      },
      "pushed_at": "2026-07-20T10:45:45Z",
      "created_at": "2026-04-20T00:00:39Z",
      "owner_type": "User",
      "updated_at": "2026-07-16T08:42:40Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://bentoak.systems",
      "name": null,
      "type": "User",
      "login": "aminazar",
      "company": "@bentoaksystems ",
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/17534630?v=4",
      "created_at": "2016-02-28T22:31:35Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 3797
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "0.13.0",
          "kind": "minor",
          "published_at": "2026-04-25T22:59:11Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "82a5321b6087b93b03522031b0f82a9725f9acaf",
          "body": "- cli 0.28.0 — browser-driver seam (Playwright default + rustwright option,\n  bench-browser, QA replay) + style-drift geometry reclassification + guard\n  --override reason + amend backprop.\n- review-overlay 0.14.0 — anchorFallback: the QA/bug-reporter shell never refuses\n  a target (comment on any e\n[…]\nserve 0.1.1 — pino optional (console-JSON fallback), zero runtime deps.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "release: cli 0.28.0 · review-overlay 0.14.0 · observe 0.1.1",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-16T08:42:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d4a49506a2549bed05c1bb0216bfea1c2d50d91",
          "body": "…enchmarked\n\nAdds a browser-driver seam so slowcook can use rustwright (native Rust CDP engine,\nPlaywright-shaped Node binding) as an OPTION alongside Playwright — Playwright stays\ndefault + failover + oracle. Nothing removed.\n\n seam — one BrowserDriver interface, two engines (playwright-driver full\n[…]\nrge memory (NOT the vendor's Python 2.55×);\nmemory is decisive for a QA-replay fleet.\n\n15 unit tests (caps/select/failover/replay/agreement) + full cli suite 1453 green.\nSee src/lib/browser/README.md.",
          "is_bot": false,
          "headline": "cli(browser): driver seam — Playwright default + rustwright option, b…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-15T23:37:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae31c7e932c176f91a7e9b6a2766fda379fd9753",
          "body": "… target\n\nAmin (QA pill): 'I cannot put a comment on the box on top.' Comment mode\nsilently ignored clicks on elements without a data-review-node ancestor —\ncorrect for the Refine pill (requirement-bearing spine only), wrong for a QA\nshell whose contract is 'report a bug ANYWHERE'.\n\nanchorFallback p\n[…]\nrkers/goto resolve dom: nodes by path. Semantic\nanchors still win when present. 5 tests (refusal without flag preserved,\nfallback composer opens, semantic precedence, path round-trip, container lift).",
          "is_bot": false,
          "headline": "review-shell(0.14.0): anchorFallback — a bug-reporter never refuses a…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-13T20:57:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d661b0f2ec9211bed10b503466ad6fed40e424d4",
          "body": "…try, not skin\n\nSame class as letterSpacing/lineHeight (already reclassified): theme-invariant\ntypographic layout that doesn't drift with the palette. New code kept hitting\nfalse drift on textTransform:capitalize / textDecoration:line-through and having\nto route through Tailwind utilities for no real benefit. 3 dash files improved.",
          "is_bot": false,
          "headline": "check(style-drift): textTransform/textDecoration/textIndent are geome…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-13T19:34:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78623718459c237f76994550d390e5eb2fb9b3df",
          "body": "…n's follow-up to #289)\n\nAmin: 'should not our reason-for-change backpropagate to stories or even PRD?'\nHonest audit: spec-level lineage existed (supersedes/superseded_by) but a\ntest-level amendment left the story yaml describing the OLD contract — the\nexact doc-vs-code drift class the brownfield in\n[…]\n coverage guard\n  caught the omission — the repo's own ratchet working).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "amend: frozen-contract reasons BACKPROPAGATE to the owning story (Ami…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-11T09:56:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "755b05274ec8c2be8c211d388c2552e267a056a7",
          "body": "…dback)\n\nFirst public post drew exactly the right critique: 'some deliberate, logged way\nfor a human to amend a frozen test WITH THE REASON ATTACHED keeps the ratchet\nhonest without turning it into a straitjacket.' The escape hatch existed from\nday one (override-freeze label → guard advisory + CODEO\n[…]\nitual). extractReason unit-tested incl. the\nbody-without-marker refusal.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "guard: the ratchet's escape hatch must carry its reason (LinkedIn fee…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-10T22:14:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c60e5edf4a9a4b773f48f067c0b828c2fa5721e",
          "body": "The file: workspace dep + pino broke plain deploys (pnpm add chokes on the\nunresolvable file: link on the box). observe now ships zero runtime deps: a\nconsole-JSON sink always works, pino upgrades it in-place when installed.\nDeploys anywhere by vendoring the built dist alone.",
          "is_bot": false,
          "headline": "observe: pino optional (console-JSON fallback) — zero runtime deps",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-09T12:41:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4838452dca804283bce5a12f646e92b507f82896",
          "body": "…QA-diagnosis substrate\n\nAmin's QA-pill loop needs the backend to be diagnosable from a report without\na repro. Two OSS pieces:\n\n@slowcook-ai/observe (new, 0.1.0) — observability + live-debugging substrate:\n- AsyncLocalStorage request context (the correlation spine): requestId +\n  optional qaSession\n[…]\nonstructs the\nincident custody-free. observe 4 tests, overlay 109 green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat: @slowcook-ai/observe + review-overlay 0.13.0 breadcrumbs — the …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-09T12:30:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c48716a023ca9c61ac44b85b9f126f5d2cf6c8f6",
          "body": "…tack\n\nAmin's scenario as the centerpiece: a QA-pill reviewer reports a bug live on\na BUILT QA deployment; the investigate agent must diagnose without guessing.\nTwo capabilities: (A) observe the FIRST occurrence — QA-session correlation\nheaders, client breadcrumbs attached to the LCR issue, server r\n[…]\n Tiered adoption + build order coupled\nto the QA pill. Sources included.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "docs: live backend debugging practice — researched for the slowcook s…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-09T12:16:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6980ac9649755c8acf4df41fea5dcdef202e75f8",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove stray empty test file from #284",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-09T11:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f559a2956ef22aba17ef5beedbd608e576e3334",
          "body": "…ill + a deliberate meteor strike\n\nAmin: the Refine pill's FIRST appearance should be impossible to miss. New\nReviewShell intro prop: the pill is born at viewport CENTER (scaled 1.25x);\nexactly 1s later a METEOR streaks in from the upper-left sky along a gentle\narc AIMED at the pill (deterministic —\n[…]\nps\nstraight to the corner), and any pointer interaction cuts to settled.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat(review-overlay): 0.12.1 — first-appearance intro: center-stage p…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-09T11:57:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ae8155210ee151ca5328d87c0a32a5fc0273c72",
          "body": "…aused it\n\ndash post-mortem: a real design system (Tailwind @theme + .sc-*) shipped\nand 1,937 inline style blocks grew around it. Root causes: (a) vibe's own\nprompts PRESCRIBED 'design tokens via inline styles' (as-built), (b) the\napp-gen scaffold seeded inline-styled primitives that set the idiom e\n[…]\n-card classes instead of inline skin — the seed idiom is now\n  classes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(style-drift): the inline-style ratchet + fix the prompts that c…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-08T20:09:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a15d64fc33ddca8e4be003ec38eea321c90fb90",
          "body": "…ling (0.12.0)\n\nAmin's condition for dash consuming the shell: a correct, explicit\nabstraction FIRST. The cut:\n\n- NEW ./primitives entrypoint: ReviewShell — the generic review surface\n  (pill, mode toggle, anchor picking, hover highlight, markers,\n  composer, sidebar threads). Knows NOTHING about Gi\n[…]\n ReviewWidget, dash's RefinePill (pm-/brand-assistant\ndoc-review loop).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "refactor(review-overlay): shell primitives — clean OSS/generic decoup…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-08T10:54:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b95ffde7ca19ee126a968598e12eed031f1f11e8",
          "body": "…+ slots\n\nThe Refine widget's comments died in localStorage. For dash's doc-review\nLCR loop the host needs to own transport and thread rendering:\n- onComment(c) → post to a backend (return {url, remoteId} to merge a\n  remote ref, e.g. a GitHub issue, into the stored comment)\n- meta[commentId] → agen\n[…]\nffort transport: a failed post keeps the comment local. 14 tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat(review-overlay): 0.12.0 — ReviewWidget transport + thread state …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-08T10:17:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "44881e4a0f639881c169c163a818f64a418f9222",
          "body": "…E + manifest\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "docs: recall + extract tiers (--survey/--as-built/--history) in READM…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-07T22:23:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "875a797a457d6f694c6c8f2a4dd97f2cca552caa",
          "body": "Tier 1.5 of brownfield extraction. The code shows what IS; the coding-\nagent sessions that built the product hold the WHY — design decisions,\nREJECTED approaches (\"tried X, deadlocked, so Y\"), known issues, and\nconstraints. No other intake source carries this.\n\n  slowcook extract --history [--cwd <p\n[…]\n workspace mapping, probe dedup,\ncitation enforcement, survey shaping).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat(extract): --history — mine the agent sessions that BUILT the repo",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-07T22:11:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63c7fc907c27c26c5c419b624f1b2c454989071c",
          "body": "The next step past the `slowcook recall` primitive: the chef-orchestrate\nagent — which decides what to do with a HALTED PR based on \"what's\nalready been tried\" — now prepends a ctx recall brief scoped to the\nstory to its user prompt. The on-disk chef-drift ledger only sees\nchef-drift's own moves; re\n[…]\nctx\nindex lives; degrades to no-op in CI runners without a local index.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat(cli): wire recall into chef-orchestrate (loop memory, live)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-07T20:28:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "19687f4746721a2e3f955f14e62682ff80151ede",
          "body": "slowcook's brew/chef/refine agents start context-blind: each run\nre-investigates what a prior session already decided or tried, and\npays to re-include fat transcripts. `slowcook recall` wraps the\nctxrs/ctx CLI (Apache-2.0) — which indexes local coding-agent session\nhistories into a private SQLite st\n[…]\n\nhandle, instead of re-deriving it. 8 unit tests (injected ctx runner).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "feat(cli): slowcook recall — agent loop-memory via ctxrs/ctx",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-07T20:28:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1533e2bf4305a04a79747a81c7f3bfeaa03b6760",
          "body": "…ent syntax (css /* */ — caught by the landing dogfood)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "vibe(as-built): provenance stamp accepts each file type's native comm…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T23:20:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f4daae2109c603e7bb1ba7aeedb3b603a314b3b",
          "body": "0.26.0 (unpublished, folded in): slowcook check surface-parity (#261) —\nmock/prod drift ratchet w/ flag-completeness, node parity, per-profile\nforbid markers, baseline with reasons/direction.\n0.27.0: slowcook extract --survey (#262 tier 0, deterministic dated\nintake survey → knowledge-claim-shaped J\n[…]\nlish (Amin, OTP): pnpm --filter @slowcook-ai/cli publish --no-git-checks\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "release: cli 0.27.0 — surface-parity + brownfield extract/as-built",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T23:12:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82a225ce394f5ebaa6d4f5b3a851b83b21099669",
          "body": "#262 tier 0: deterministic survey — dated doc catalog (git, stale-honest),\nstory-spec aggregate w/ _index statuses, commit/branch evidence, issues/PRs\nvia gh when available; emits knowledge-claim-shaped .brewing/extract-survey.json\nfor direct §7.18 intake ingestion.\n#262 tier 1: LLM as-built pass (k\n[…]\nle output rejected on any violation.\n\n11 new tests; package suite green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "extract --survey / --as-built (#262) + vibe --as-built (#263)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T23:11:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c175032afb86215a17bce0f33a589ac8ece370c0",
          "body": "…se (test-only ids are permanent dead-node noise)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(surface-parity): exclude .test/.spec files from the node univer…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:41:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1712b13701073e91e5da4bfffa352edcecb19ec5",
          "body": "profiles.<name>.forbid: [strings] that must NOT survive into that profile's\nbundle (fixture emails, preview gates, review tooling in real builds).\nBorn from the delgoosh dogfood: the real SPA build shipped the ENTIRE\npreview machinery runtime-gated only; after fixing the sever, forbid\nmarkers make the regression impossible to reintroduce silently.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(surface-parity): per-profile forbidden markers — the sever guard",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:40:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a999e3c49336677e07043c2db9d361c14f58e480",
          "body": "…onent package scan both)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(surface-parity): src accepts multiple dirs (apps sharing a comp…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:28:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "286c0da9f47a1e5a899904f43162b602d3b2fb4c",
          "body": "…seline paths (multi-app repos)\n\nDelgoosh dogfood needs: markers: [data-testid] (no rn() there — 145 testids\nare the stable spine) and per-app configs (spa-patient + spa-therapist each\nget a parity.yaml + baseline). Dash regression-checked: 7 waived, no new drift.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(surface-parity): configurable marker attributes + --config/--ba…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:27:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de8eec4bf60cde8546c66b9e66d1b11df392d76f",
          "body": "…ratchet)\n\nNew: `slowcook check surface-parity` (#261) — builds each profile in\n.slowcook/parity.yaml, verifies review-node ids survive into every profile's\nbundle, verifies every import.meta.env flag read is DECLARED in prod-like\nprofiles, and ratchets via .slowcook/parity-baseline.yaml (reason/own\n[…]\nlish (Amin, OTP): pnpm --filter @slowcook-ai/cli publish --no-git-checks\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "release: cli 0.26.0 — slowcook check surface-parity (mock/prod drift …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:20:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73dc48b59b950e5c49450b827e9f899ab67f4690",
          "body": "…r props (dash RateInput pattern); slashed-shape guard rejects mode=/path= look-alikes\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check(surface-parity): also harvest node ids passed via *node= wrappe…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:18:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "055cc01850e6ebe22e0bd1c02bbf60536edac76c",
          "body": "Two static sub-checks over the profiles in .slowcook/parity.yaml:\n(1) flag completeness — every import.meta.env.<prefix> read in src must be\nDECLARED in prod-like profiles (value may be empty = deliberately off);\nan undeclared flag silently DCEs its live branch (the dash wallet lesson).\n(2) node par\n[…]\n DCE — rendered-profile pass is v2 (#261).\n\n8 tests; package 1407 green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016AS6N1GvgL9QU5fLaq51Wk",
          "is_bot": false,
          "headline": "check: slowcook check surface-parity — mock/prod drift detector (#261)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-05T01:14:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12dfa77dc64a9938edd2b8f3e7e9f8b635a8256a",
          "body": "Ships PR #259: the check no longer lets a fake-success button escape via\na conditional `disabled={...}`, and honors @slowcook-honest as a leading\ncomment. 0.24.0's check missed exactly this (the common case, since real\nbuttons are usually conditionally disabled). cli-only; core 0.17.0 and\nllm-anthropic 0.21.0 unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "release: cli 0.25.0 — prod-honesty catches conditional-disabled fakes",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T18:23:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a837f179bda8bd2abcd774baf74c9589fea44389",
          "body": "…eading @slowcook-honest\n\nTwo fixes from dogfooding on a consumer that shipped 0.24.0:\n- The 'acknowledged' heuristic treated ANY `disabled` on the handler\n  line as honest — so a fake-success button with `disabled={!ok||done}`\n  (live whenever the condition is false) slipped through. Now only a\n  B\n[…]\n in the dash\nconsumer that 0.24.0's check had missed. Warrants a 0.25.0.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "check(prod-honesty): a conditional disabled is not an excuse; honor l…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T18:18:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f5755e6e13f9cbf22194a7741b29b8529b885b0",
          "body": "…honesty\n\n- core 0.17.0: spec surfaces gain `access` (public|authed|role) +\n  `ctas[].effect` (navigate|mutate|deferred) — the mock→prod honesty\n  declarations.\n- llm-anthropic 0.21.0: refine prompt elicits surface access + cta\n  effects (+ backtick-clause fix).\n- cli 0.24.0: two new deterministic c\n[…]\nans/mock-to-prod-honesty.md.\n\nPublish order: core → llm-anthropic → cli.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "release: cli 0.24.0 · llm-anthropic 0.21.0 · core 0.17.0 — mock→prod …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T18:03:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e3d42e569d5691dca35e6e280c1bca970bb660b",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/checkout from 6 to 7",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T18:02:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d7dd82868588f2d12bd03ed084aafc345c54ed8",
          "body": "…undle (+ fix refine clause)\n\nprod-honesty checks whether fixture data RENDERS; prod-bundle checks\nthe deeper directive: the mock's data ENGINE (sql.js / SQLite WASM /\nslowcook mock-runtime) must not be PRESENT in the shipped bundle. A\nruntime flag that bypasses the engine is not a sever — if the en\n[…]\nesbuild had tolerated it). The new check's build surfaced it.\n\ncli 1396.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "check: slowcook check prod-bundle — no mock-data engine in the prod b…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T17:40:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3fdd2dd919d645ac6b5f65d019057ba99152bb1c",
          "body": "…eclaration layer)\n\nMakes refine populate the new surfaces.access / surfaces.ctas[].effect\nfields so port emits guards and brew wires real effects — the\nprevention layer that makes 'slowcook check prod-honesty' pass by\nconstruction rather than by catching leaks after the fact.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: elicit surfaces access + cta effects (completes the honesty d…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T17:26:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c01e3b3065322ec6da17e8b6bbcb09b4292ebe94",
          "body": "…prod honesty backbone\n\nA consumer found three prod defects the mock review never surfaced:\nfixture data in prod, ungated internal pages, and CTAs that fake\nsuccess. Root cause (docs/plans/mock-to-prod-honesty.md): the mock is\nproduct behavior + review scaffolding superimposed; the port→brew\npipelin\n[…]\nned operator-admin pages a manual\naudit had missed.\n\ncli 1392 · core 35.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "check: slowcook check prod-honesty + surfaces access/ctas — the mock→…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T17:24:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a09db3b0d662318e7bed3f57e9148f3a1fcacdd3",
          "body": "…ests as exemplars (closes sc#240)\n\nWhen .brewing/context.md is absent, buildProjectContext now mines the\ntwo newest story-test files from the (workspace-aware) history index\nand injects 60-line excerpts with a MATCH-THIS-STYLE instruction. The\ndash A/B/C proved prose loses to few-shot — so the few-\n[…]\n245),\nstack-precedence clause, split-lineage guard, and now auto-mining.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "testgen: convention-mining — repos without context.md get their own t…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T10:53:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "829b7e88701633fa009f3bb26e0668ae26d7c05a",
          "body": "Seventeen changes from the dash full-pipeline dogfood (2026-07-02/03):\n\nllm-anthropic 0.20.0\n- ClaudeCliClient: key-less runtime on the claude CLI's subscription\n  auth (--disallowedTools '*', pure text model) + createLlmClient(env)\n  factory (SLOWCOOK_LLM=claude-cli)\n- stream-json parsing: long mul\n[…]\n--no-git-checks\n  pnpm --filter @slowcook-ai/cli publish --no-git-checks\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "release: cli 0.23.0 · llm-anthropic 0.20.0 — the dash-dogfood harvest",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T10:50:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "333225324544a10278379a3a699b099d9b2ac12b",
          "body": "First real reconcile dogfood stopped at the hard key check — the #233\norder listed reconcile next after refine/testgen. Same swap as PR #234.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "reconcile adopts createLlmClient (sc#233, third adoption)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T09:54:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc6e5adbc679a2946ed81b90485698890d35ecd1",
          "body": "…cit anchors\n\nFirst reconcile dogfood on dash died instantly: 'PRD has no section\n§surface-timesheet' — the anchor exists, but as a bold LIST ITEM\n(dash's PRD anchors all surface sections that way) and\nparsePrdInitiatives only recognized ATX headings. Two tools, two anchor\ngrammars (pm-lint accepts \n[…]\ncitly\nanchored bullets become initiatives, plain bullets stay body text.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "menu/reconcile: PRD parser accepts bold list-item sections with expli…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T09:53:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6393b3d770102d82fe4dea8c4ba12fb3bb65d872",
          "body": "The last recurring spec nit on dash: models emit plausible-but-\nnonexistent prd_ref anchors (surface-intake-assist, brownfield-intake,\n7.1-project-onboarding — three shapes in three stories). The project\ncontext now lists every {#anchor} in docs/PRD.md with a MUST-use-one\ninstruction.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: PRD-anchor digest in project context — anchors can't be invented",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T09:48:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "290949fee6ac576a01400822de91defdbefd3426",
          "body": "…ause\n\n#248 made fields SURVIVE; the amendment prompt asks for them; the\nFIRST-ROUND emit prompt never did — so specs from issues that don't\nexplicitly ask still arrive without epic/prd_ref (dash story-074 vs\nstory-073). The emit-format section now instructs emitting repo-local\nfields in the context-documented shapes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: first-round emit prompt also carries the repo-local-fields cl…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T09:07:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3da02f62a7a1891656a31b5ddc2e739b8a32b9a6",
          "body": "…ot cause\n\n#239's passthrough fixed the zod layer, but parseAgentOutput then\nhand-reconstructs the Spec as an enumerated object literal — repo-local\nfields (prd_ref, epic, surfaces) survived the parse and died in the\nrebuild, which is why every dash resubmit still dropped them. The\nrebuild now start\n[…]\nlds win.\nRegression test emits prd_ref/epic through the full parse path.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: repo-local fields survive the Spec REBUILD — the real #236 ro…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T08:43:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "77f7c092e2c5e0fb62081773730ee6c6234e2b86",
          "body": "Three dogfood occurrences of re-multifurcating issues born from accepted\nsplits, zero true positives. Code: assessment is skipped entirely when\nthe body carries 'Split from #N' in any phrasing. Prompt: the existing\nfooter-format-keyed 'lean toward one' clause becomes phrasing-agnostic\nand decisive.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: deterministic split-lineage guard + hardened prompt (sc#240)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T07:33:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3d3d8d50fc232f0cb75d7c9277a080f88b57a4d",
          "body": "…truncate\n\nThree dash testgen runs died with replies starting MID-WORD: the CLI's\naggregate json 'result' field carries only the LAST text block of a\nlong multi-block reply. The adapter now drives --output-format\nstream-json and concatenates all assistant text blocks; usage still\ncomes from the result event; single-block behavior unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "llm-anthropic: claude-cli reads stream-json — long replies no longer …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T06:28:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8d7363a9076a6adb55797e366de2cfe002a7978b",
          "body": "… roots (sc#240 round C)\n\nRound C emitted repo-conventional imports (../src/pages/X.js) that were\nCORRECT for the package the test belongs in — the validator rejected\nthem because (a) it never mapped .js→.ts/.tsx (nodenext) and (b) it only\nresolved from the hardcoded root emit location. Both fixed; brewing\nrelocates the test into the owning package as it already does.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "testgen: import validator maps nodenext .js and falls back to package…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T05:56:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "41c6644d577ee77b478ab72812b2afdc6d099360",
          "body": "The A/B on dash was decisive: with .brewing/context.md present and\nverified in the prompt ('No Supabase' included), the scaffold STILL\narrived Supabase-flavored — the system prompt's worked examples\n(Next route files + Supabase mocks) out-pull project-context prose.\nAn explicit precedence clause now\n[…]\nds introducing dependencies/paths the project\ncontext doesn't establish.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "testgen prompt: project context beats the examples' stack (sc#240)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T05:28:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9abaeb2e041c34ea827be2190812240ad0f3a623",
          "body": "…ormal exit\n\nTwo long testgen generations died in-flight on dash (one reply truncated\nmid-word, one abnormal process exit) with no diagnostics — the runner\ndiscarded stderr. Errors now carry the stderr tail; one automatic retry\nabsorbs the transient class, a second failure surfaces loudly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "llm-anthropic: claude-cli runner carries stderr + retries once on abn…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T04:05:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "685df335abaadcaed08faffaf899eae9cd4e90b4",
          "body": "…eam (fixes #238)\n\nThe mockup-first emitter hardcoded repo-root src/lib/data — on dash it\ndropped stray broken stubs into a src/ tree that doesn't exist (removed\ntwice in dash PM fixups). resolveDataSeamRoot picks an existing populated\nseam dir across discovered package roots (mock/src/data on dash)\n[…]\ncy path for greenfield scaffolds. Regression tests both\nways. 1375/1375.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: fixture/stub emitter targets the package that owns the data s…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T03:27:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "671ff51b9fb3052858d7f61f3f62c8a1c61a0ce4",
          "body": "Route-file conventions miss code-routed frameworks entirely — dash's 30\nHono routes indexed as zero, so testgen forked an existing webhook\nhandler it couldn't see and refine invented error codes for shipped\nendpoints (aminazar/slowcook#240 context). scanCodeRoutes greps literal\napp.get/post/put/patc\n[…]\n dep; a missed route degrades to old\nbehavior). dash: 0 → 30 api routes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: index code-routed APIs (Hono/Express app.<method> literals)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T02:45:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c61f9f1049ef6900b31af28210a0c1c18dcf604",
          "body": "Root cause of the silent feedback-drop: zod strips unknown keys by\ndefault, so a PM-requested repo-local field (dash's prd_ref/epic) was\nremoved by SpecSchema/EmittedSpecSchema parsing even when the model\nemitted it — and the amendment prompt's output-format allowlist told the\nmodel not to emit it i\n[…]\npping unrecognized ones\n- regression test: prd_ref/epic survive readSpec\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: repo-local spec fields survive round-trips (fixes #236)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T01:48:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1dbb03891d0d35a9bbbbe34da0885a28a10cd49",
          "body": "…re no longer invisible\n\nDogfooding on dash showed every agent run printing 'history-index: 0\ncomponents · 0 api routes · 0 test helpers · 0 test files' — the repo\nkeeps components under mock/src and 60+ tests under server/test, but the\nindex only scanned root-level Next.js-convention paths. Blind a\n[…]\nPIs (Hono/Express)\nstill aren't discoverable via route-file conventions.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: history-index discovers package roots — multi-package repos a…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T01:06:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a34ae46cf2da23ddac6f76afcbfe2656f96039b4",
          "body": "…ld collision)\n\nDogfooding on dash (58 specs, no _index.yaml — written by other tooling)\nrefine allocated story id 001 and OVERWROTE the live story-001.yaml in\nits spec PR. The index and in-flight spec branches were the only id\nsources; brownfield repos' files are ground truth. nextStoryId now\nunions specs/story-*.yaml ids with index + branch ids.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "refine: nextStoryId scans story FILES, not just _index.yaml (brownfie…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T00:28:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ccd6e956292f330b1512b31dee26fbf2fe3170c4",
          "body": "…me works\n\nThe two highest-value agents from the sc#233 adoption order now select\ntheir LLM runtime from the environment: ANTHROPIC_API_KEY (API) or\nSLOWCOOK_LLM=claude-cli (the local claude CLI's subscription auth, no\nkey). The refine/llm.js shim re-exports the factory so the 0.8-refactor\nimport pa\n[…]\nes both options; the old hard\nkey-check and its dead-end error are gone.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "cli: refine + testgen adopt createLlmClient (sc#233) — key-less runti…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-03T00:13:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "350946725b9c2f2269650c9acc0d024db303bf97",
          "body": "…tory\n\nDrives the claude CLI's headless print mode (subscription auth, no\nANTHROPIC_API_KEY) behind the same LlmClient contract as AnthropicClient:\npure text model (--system-prompt replaces Claude Code's, --disallowedTools\n'*'), usage incl. cache tokens mapped to LlmUsage, costUsd via the\nadapter's \n[…]\nng BOTH options. Pattern proven in\nthe dash dogfood (2026-07, rewo box).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01CPGf6FhFcKcZDdhhVwwdnF",
          "is_bot": false,
          "headline": "llm-anthropic: key-less ClaudeCliClient adapter + createLlmClient fac…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-02T22:50:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21e65ec6c426905492e3fc89b8d956b2c95a17b7",
          "body": "… (#231)\n\nReviewWidget gains requireTargets (default true): hides where there's no\nreviewable context, so combined with enabled (persona capability) the pill only\nshows when both hold. Both pills now reflect a shared invisible comet that\nstreaks across the viewport on a random path every few seconds\n[…]\nborder as it passes.\nprefers-reduced-motion disables it.\n\n\nClaude-Session: https://claude.ai/code/session_01VVrtdHXn5cj1pvdWZTqc4t\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "review-overlay 0.11.0 — context-gated Refine pill + comet-light glint…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-07-02T10:22:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ca697370ae836e7e83fcd14fc5f9ca0c05275d00",
          "body": "A persisted or dragged pill position could land outside the viewport; since\nthe pill is fixed/absolute chrome you can't scroll to it, so the widget looked\ngone. Snap stranded pills back to top-left on mount + resize, clamp the drag\ninto the viewport (drop the -2000 left floor), and add tested pure helpers\nisPillOffViewport / clampPillPosition.\n\n\nClaude-Session: https://claude.ai/code/session_01VVrtdHXn5cj1pvdWZTqc4t\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "review-overlay 0.10.1 — keep the floating pill on-screen (#229)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-30T20:11:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "272fca17d853492e5f471f0912d799cb67296b5d",
          "body": "…dget (#226)\n\n* review-overlay 0.9.10 — Docs studio handles an expired reviewer session\n\nThe Docs studio reads docs with the signed-in reviewer's device-flow token.\nThose tokens expire, so a 2-day-old session hit a dead-end error:\n\"Couldn't load docs/PRD.md: Bad credentials (401)\" despite being \"log\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01FnnabjXjCfSkHeYTPcunQD\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "review-overlay 0.10.0 — semantic (a11y) anchoring + reusable ReviewWi…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-30T08:18:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ce4832ea442ad94b3e4bb7da2962e1eef324218",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.1 to 26.0.1.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump @types/node from 25.9.1 to 26.0.1 (#228)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T08:16:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a78ea17b2ff9d2db61c0d589d4ab3a1f0df395f8",
          "body": "Bumps the anthropic group with 1 update: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript).\n\n\nUpdates `@anthropic-ai/sdk` from 0.104.1 to 0.106.0\n- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)\n- [Changelog](https://github.com/anthropics/a\n[…]\n: version-update:semver-minor\n  dependency-group: anthropic\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump @anthropic-ai/sdk in the anthropic group (#227)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T08:16:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30ba47bdb74559742597d7927254cd3c0ff720be",
          "body": "…dget (#226)\n\n* review-overlay 0.9.10 — Docs studio handles an expired reviewer session\n\nThe Docs studio reads docs with the signed-in reviewer's device-flow token.\nThose tokens expire, so a 2-day-old session hit a dead-end error:\n\"Couldn't load docs/PRD.md: Bad credentials (401)\" despite being \"log\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01FnnabjXjCfSkHeYTPcunQD\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "review-overlay 0.10.0 — semantic (a11y) anchoring + reusable ReviewWi…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-30T08:15:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1520b8a1886076200e2c03207338b0480c5c552",
          "body": "docs(EPSS): an affordance's interaction is part of the requirement",
          "is_bot": false,
          "headline": "Merge pull request #225 from aminazar/docs/affordance-behaviour",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-27T23:14:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc5f55c330b2419d935216198d104fca828ab1c8",
          "body": "Follow-up to #224 (design is a state source). Extends\naffordances→requirements from presence + appearance + data-variant to\nINTERACTION: what an affordance does when activated is spec too. A\ncontrol reproduced to look right but wired to a stub (navigate instead\nof opening the design's confirm modal)\n[…]\nurfaces the >=24h-refund / <24h-charge\ncancellation model.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_012ng8nkdyTxCiLQZJgnFv3Y",
          "is_bot": false,
          "headline": "docs(EPSS): an affordance's interaction is part of the requirement",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-27T23:04:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b1e39dd994c00e57bae31821eab316e94c4ee551",
          "body": "docs(EPSS): design is a state source — affordances are requirements, variants are states",
          "is_bot": false,
          "headline": "Merge pull request #224 from aminazar/docs/affordances-are-requirements",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T18:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b32bdac7344342c4cf12d0f1cdc83afc8f57f9b",
          "body": "…variants are states\n\nThe inverse of 'state drives the data': the mock IS the spec, so every affordance is\na requirement and every variant of an affordance is a State. A rich component is a\nstate-discovery surface — read it backwards into the matrix. A 'drifted from design'\nreview is a dropped requirement, not a cosmetic nit. EPSS.md section + AGENTS.md\ndirective. Provenance: a chosen-therapist card whose dropped affordances encoded the\none-therapist-per-care-profile rule.",
          "is_bot": false,
          "headline": "docs(EPSS): design is a state source — affordances are requirements, …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T18:09:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e13ae6bbf62b5423fe075ffb3e68e62da4be1a24",
          "body": "review-overlay: generic `accessory` pill slot",
          "is_bot": false,
          "headline": "Merge pull request #223 from aminazar/feat/overlay-accessory-slot",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T14:11:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8019575ce7c6d9f07d8ced1af098ff2a43e6936c",
          "body": "(0.9.8 was claimed by the full-context PR #222; the accessory slot ships as 0.9.9.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01FnnabjXjCfSkHeYTPcunQD",
          "is_bot": false,
          "headline": "review-overlay 0.9.9 — version bump + changelog for the accessory slot",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T14:11:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b72585d628157fc74fe93939b61feda953a2d279",
          "body": "…y-slot",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into feat/overlay-accessor…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T14:10:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7954b82665fadce58f65271656ae324626bd47e5",
          "body": "feat(review-overlay): 0.9.8 — every comment carries full context (EPSS + lang + device)",
          "is_bot": false,
          "headline": "Merge pull request #222 from aminazar/feat/review-overlay-full-context",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T14:09:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7862b59c31228e208302c7c0c29f2c08495c41da",
          "body": "Add an `accessory?: ReactNode` prop that renders consumer-provided content INSIDE\nthe floating pill (always visible, both nav + comment modes), after the surface\nswitcher. The overlay stays generic — it owns the pill chrome; the consumer owns\nwhat goes in the slot.\n\nMotivation: dash wants a single p\n[…]\nerlay just accommodates it. Any consumer can use the slot.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01FnnabjXjCfSkHeYTPcunQD",
          "is_bot": false,
          "headline": "review-overlay: generic `accessory` pill slot",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T12:30:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4c5653034ed46f6f2f0bb845ed7390454dac4a09",
          "body": "…S + lang + device)\n\nLCR review comments now record the FULL context so plate never guesses:\n- EPSS state: active epic ▸ context ▸ scenario ▸ state + crumb (new surface field;\n  the state lives in localStorage not the URL, so route alone couldn't distinguish\n  two comments on different states of the\n[…]\nrtMode().\nOn BOTH element-anchored and general (page-level) comments via collectReviewContext.\nNew SurfaceContext type + optional surface/lang on ReviewCommentPayload (back-compat).\nTests + CHANGELOG.",
          "is_bot": false,
          "headline": "feat(review-overlay): 0.9.8 — every comment carries full context (EPS…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T10:42:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4bbffa7cdfb3c8b8ed2ddbb29a50757114cfe4de",
          "body": "* fix(vibe app): EPSS palette nav (base) + stop declaring loading/error states\n\nTwo dogfood findings:\n\n1. EPSS palette navigation 404'd. The overlay composes the nav URL as\n   base + scenario.route, but the manifest set context.base = the persona HOME\n   while scenarios already carry the FULL route \n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01FnnabjXjCfSkHeYTPcunQD\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "vibe: EPSS test matrix from semantics, not routes (0.22.0) (#220)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T09:15:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63a779f77069ffde8bddbf86976b5279e3d74d68",
          "body": "fix(vibe app): sql.js dev-parity + param route names (dogfood)",
          "is_bot": false,
          "headline": "Merge pull request #219 from aminazar/fix/vibe-app-dev-parity",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T01:09:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "964112ea54040b15b6dc0bba7b63f3472bc9ffbe",
          "body": "Two real bugs surfaced by hand-building data-backed surfaces on the live HMR mock:\n\n1. CRITICAL — vite config excluded sql.js from optimizeDeps, so the data adaptor\n   (import initSqlJs from 'sql.js') threw 'does not provide an export' in `vite dev`\n   (the HMR review deploy) while `vite build` work\n[…]\nlude (pre-bundle) sql.js.\n2. routeToName dropped param segments → `/projects/:projectId` collided into a\n   meaningless `Projects2Page`. Fix: keep params as `By<Param>` →\n   `ProjectsByProjectIdPage`.",
          "is_bot": false,
          "headline": "fix(vibe app): sql.js dev-parity + param route names (dogfood findings)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-26T00:57:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c95f00d4567e60df35c1f9116ea5d782fe0ea525",
          "body": "feat(review-overlay): 0.9.7 — ☰ All lists every EPSS surface",
          "is_bot": false,
          "headline": "Merge pull request #218 from aminazar/feat/overlay-list-all",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T19:23:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "008a0feff52d0bbaa778158cc713549e64d91f2e",
          "body": "The EPSS jump palette only revealed results after ≥3 typed chars (spotlight), so\nbrowsing the full route set meant guessing search terms. Added a ☰ All toggle that\nshows the complete grouped list (epic/persona/scenario/state) — an empty query\nalready matches every row, so it just lifts the char gate. Empty-state hints now\npoint at it.",
          "is_bot": false,
          "headline": "feat(review-overlay): 0.9.7 — '☰ All' lists every EPSS surface",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T19:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "002fed90d1cdec31ed9a88fff011c3e323be73c9",
          "body": "docs(review-overlay): vite dev-server mocks behind a CDN — the ?v= immutable trap",
          "is_bot": false,
          "headline": "Merge pull request #216 from aminazar/docs/vite-dev-cdn-cache",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T19:15:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b88f820ef9722292c958c60cdead3cbab8f8b6c4",
          "body": "fix(vibe app): personas via review-overlay EPSS, not mock chrome",
          "is_bot": false,
          "headline": "Merge pull request #217 from aminazar/feat/lcr-overlay-epss",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T19:11:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74fdc7188789e5e3c30bd0c6f1cb516849a1c892",
          "body": "…s assumption\n\nThe overlay read process.env.NEXT_PUBLIC_* directly (a Next.js convention), which\nthrows 'process is not defined' in Vite/React/plain-browser mocks — the LCR mock's\nactual stack. Props are the primary config; env is only an optional Next fallback,\nso guard it: env(key) = typeof process !== undefined ? process.env[key] : undefined.\n14 unguarded reads → guarded. Bumped 0.9.5 → 0.9.6.\n\nConsequently vibe app no longer needs the `define: { process.env: {} }` shim — removed.",
          "is_bot": false,
          "headline": "fix(review-overlay): framework-agnostic env reads (0.9.6) — no Next.j…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T18:52:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0463c922cfa189a31f3419420283269be3d5b0b",
          "body": "The mock hand-rolled a persona switcher; it belongs to the slowcook review-overlay\n(personas are a REVIEW affordance). vibe app now:\n\n- mounts <SlowcookReviewOverlay reviewMode=lcr enabled surfaces=… testingSurfacesUrl=…>\n  — the persona switcher (surfaces) + EPSS epic/persona/scenario/state router \n[…]\ned (overlay defaults off without it).\n\nDogfood (dash, live at dash_mock.slowcook.dev): overlay pill renders with 'as\nfounder' persona switch + EPSS surface router; no mock chrome switcher. 1363 green.",
          "is_bot": false,
          "headline": "fix(vibe app): personas via the review-overlay EPSS, not the mock chrome",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T18:44:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a569fdb0fd2709a3365215f103b6a727c0ae000",
          "body": "…mutable trap\n\nVite serves optimized dep bundles (/node_modules/.vite/deps/*.js?v=<hash>) as\nimmutable but reuses the ?v across re-optimizes, so a CDN caches a redeployed\nsame-version overlay immutably and serves the stale bundle to reviewers forever\n(cf-cache-status: HIT) while the origin serves the new code. Documents symptom +\nfix (no-store on dev proxy locations + one-time CDN purge). From delgoosh dogfood.",
          "is_bot": false,
          "headline": "docs(review-overlay): vite dev-server mocks behind a CDN — the ?v= im…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T18:42:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2ef0f1c5bd6635cf0010b16484bc5b69bdaf183",
          "body": "feat(review-overlay): 0.9.5 — live EPSS status, login hint, signed-in pill no clip",
          "is_bot": false,
          "headline": "Merge pull request #215 from aminazar/feat/review-overlay-epss",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T18:12:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d845fc497d4cfefcca3ab77240041bb9b8702b89",
          "body": "feat(vibe): runnable LCR scaffold (vibe app) + whole-app greenfield status",
          "is_bot": false,
          "headline": "Merge pull request #214 from aminazar/feat/vibe-app-lcr",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T18:00:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fa969c1691af0571020fa391e9ff7f7064740a9",
          "body": "#178's v6 bump errors when both `version:` and package.json packageManager are\nset (\"Multiple versions of pnpm specified\"). v6 reads the version from\npackageManager (pnpm@9.15.0); remove the redundant input.",
          "is_bot": false,
          "headline": "ci: drop version: 9 from readme-help-sync's pnpm/action-setup@v6",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:58:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0f791fc79c717f95cd21548aa3b97665bfaedcf",
          "body": "…tatus\n\nFixes the remaining gaps to build the whole-app LCR mock:\n\n- vibe/app-gen.ts (pure + 7 tests): `vibe app` scaffolds the runnable, navigable\n  LCR from the plan — Vite + Tailwind v4, App.tsx router (every surface a route,\n  no auth walls), persona shell (chrome-aware nav + persona/theme switc\n[…]\n · 8 personas · 38 files; greenfield →\nLCR (whole-app) ✓ 32/32 surfaces; the mock BUILDS (tsc + vite, 71 modules) and\nRUNS (navigable). Left: LLM page bodies + dense seed (credit-blocked). 1361 green.",
          "is_bot": false,
          "headline": "feat(vibe): vibe app — runnable LCR scaffold + greenfield whole-app s…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:51:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cfabf02957503f3d6f6a495898f32b812400df8",
          "body": "…action-setup-6\n\nci: bump pnpm/action-setup from 3 to 6",
          "is_bot": false,
          "headline": "Merge pull request #178 from aminazar/dependabot/github_actions/pnpm/…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:28:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d07cbae21dc9ce2bd5a227ba988e812a44630b8",
          "body": "feat(vibe): seed + adaptor pass — real SQLite data adaptor",
          "is_bot": false,
          "headline": "Merge pull request #213 from aminazar/feat/vibe-seed-adaptor",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1aa7f2f2c340231697429d0d009b36d9f514186",
          "body": "…ADME",
          "is_bot": false,
          "headline": "merge main into seed-adaptor: resolve llm-anthropic exports + sync RE…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:25:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d107a2e7064a5ba4ecce7d0fcc52bdb6275559c",
          "body": "feat: PRD↔stories interdependency (trace stamp/impact + reconcile)",
          "is_bot": false,
          "headline": "Merge pull request #210 from aminazar/feat/prd-stories-interdependency",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:24:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7db23a688c6a327a637f517a04620ef8aca63488",
          "body": null,
          "is_bot": false,
          "headline": "docs: sync README command catalog with manifest (trace + vibe entries)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:22:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e69f7bf1f54bcfd06beccc2231ad5a57840dfa63",
          "body": null,
          "is_bot": false,
          "headline": "merge main (vibe plan/schema) into interdependency",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T17:21:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e97eaf240acd11f5b5396a0dde8d363d62566cd2",
          "body": "The LCR uses a real in-browser SQLite (sql.js + Drizzle) per the gucdi keystone,\nso the mock's query layer runs real SQL and mock→prod is a data-source swap, not\na rewrite. `slowcook vibe seed`:\n\n- Deterministic runtime (no LLM): schema.ts + ddl.ts (CREATE TABLE w/ enum CHECK +\n  FK REFERENCES) + db\n[…]\n VALIDATED against\nreal sql.js — 37 tables, FK joins, enum CHECK + FK constraints all enforced. LLM\nseed/queries blocked on Anthropic credit (key exhausted); wired + ready on top-up.\n1342 tests green.",
          "is_bot": false,
          "headline": "feat(vibe): seed + adaptor pass — real SQLite (sql.js) data adaptor",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T16:56:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "365182fca48c3d0c520bac9668566d77d6977a37",
          "body": "feat(vibe): deterministic Drizzle schema-gen (LCR data adaptor)",
          "is_bot": false,
          "headline": "Merge pull request #212 from aminazar/feat/vibe-schema-gen",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T16:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0167ba89b5a822e47592a176b5808b5763106493",
          "body": "The first generation pass of the whole-app LCR. Because the plan's data model is\nalready well-typed (menu emits structured data_contract), the schema falls out\nmechanically — no LLM, no drift, testable. Draws the boundary: structure →\ndeterministic; content/judgment (seed, surfaces) → LLM.\n\n- vibe/s\n[…]\nsrc/lib/schema.ts (--stdout / --out).\n\nDogfood (dash): 37 tables · 292 columns, 0 PK-as-FK, no dangling refs, valid\nsyntax. Caught + fixed an inverse-relation bug (project.id → wallet FK). 1341 green.",
          "is_bot": false,
          "headline": "feat(vibe): deterministic Drizzle schema-gen (LCR data adaptor, pass 1)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T16:09:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70a9406d3ceb52749d5fce84db94dcbb170676ee",
          "body": "feat(vibe): whole-app LCR — deterministic plan foundation",
          "is_bot": false,
          "headline": "Merge pull request #211 from aminazar/feat/vibe-whole-mock-lcr",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T15:50:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0834ab4d199905537f9dc68f3e2aa453e0e6c5c6",
          "body": "Begin moving vibe from per-story to one complete, clickable, richly-populated LCR\napp with a shared data adaptor. This slice lands the deterministic spine.\n\n- menu now emits persona + surfaces per UI story (prompt + MenuStoryDraft + spec\n  schema + assemble). Declared provenance (chosen over vibe-in\n[…]\nnu-emits-surfaces → re-run menu). Data-model + conflict detection is the\nschema-pass input.\n\nDesign + next slices (schema/seed/surface LLM passes): docs/plans/vibe-whole-mock-lcr.md.\n1331 tests green.",
          "is_bot": false,
          "headline": "feat(vibe): whole-app LCR plan — deterministic foundation",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T15:41:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ebedc5957585eef7109ed6313c2ca3f5b8cffdb",
          "body": "The LLM half of PRD↔spec interdependency. When a PRD section a spec anchors to\nchanges, `slowcook reconcile --story <id>` proposes a corrected spec — the\nside-effects audit lifted from issue→test to PRD→spec.\n\n- RECONCILE_SYSTEM prompt (llm-anthropic): enumerate contradictions + emit a\n  minimum-dif\n[…]\n(slowcook-dev/dash): PRD §personas-operator gained suspend/decertify →\ntrace impact flagged story-019 → reconcile proposed +1 invariant, +2 scenarios,\n+2 API, with 3 one-hop cross-impact notes. $0.25.",
          "is_bot": false,
          "headline": "feat(reconcile): LLM PRD→spec reconcile (propose-not-apply, one hop)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T13:44:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "95ffd7d45df33cebb52fefea4efe74620460c11b",
          "body": "The deterministic floor under conversational PRD/stories review (OSS half of the\ndash Q13 loop). Every spec anchors to a PRD section; we now fingerprint that\nsection's body so a PRD edit is detectable + attributable — no LLM.\n\n- trace/check.ts (pure): anchorHash (FNV-1a, dependency-free), checkFresh\n[…]\n\nPropose-not-apply + one-hop: impact only flags WHICH stories; reconcile (next,\nLLM) proposes HOW, reviewed before apply. Design: docs/plans/prd-stories-interdependency.md.\n+12 unit tests; 1334 green.",
          "is_bot": false,
          "headline": "feat(trace): PRD↔spec interdependency engine (deterministic)",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-25T13:35:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b077f870c1ff1a95d0cba2ee25c8bf63e715dafa",
          "body": "chore(deps): playwright ^1.61 consistently (supersedes #196)",
          "is_bot": false,
          "headline": "Merge pull request #209 from aminazar/chore/playwright-1.61-consistent",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-24T13:04:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "580035f7c5b1f438ec7e55f26a5c31be0db702fe",
          "body": "…skew)\n\nDependabot #196 bumped @playwright/test in one workspace package only, leaving\nanother at 1.59.1 → two playwright-core versions in the tree → cli/eye/run.ts\npassed a 1.61 Page to a function typed against 1.59 (ElementHandleWaitForSelector\n'detached' state not assignable). Bumped the pin to ^1.61.0 in BOTH cli + gates\nso the lockfile resolves a single playwright-core (1.61.1). Build + cli tests green.",
          "is_bot": false,
          "headline": "chore(deps): bump @playwright/test to ^1.61 consistently (fixes #196 …",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-24T13:03:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9c00c996cc598874e32348a459d9e8322a41cd9",
          "body": "… pill no clip\n\n- EPSS status is LIVE: reflects the surface the reviewer is actually on\n  (reactive to SPA nav via patched pushState/replaceState + popstate +\n  poll). Matches selection → full Context›Scenario›State; navigated away →\n  live Context›Scenario; off-manifest → Identity›/path. New findSu\n[…]\nrfaces. New activeHint.\n- Signed-in pill no longer clips: the 0.9.3 min-content column overflowed the\n  @user chip past the hard 300px cap; cap is now min(560px,94vw).\n\n89 tests (6 new). tsc -b clean.",
          "is_bot": false,
          "headline": "feat(review-overlay): 0.9.5 — live EPSS status, login hint, signed-in…",
          "author_name": "aminazar",
          "author_login": "aminazar",
          "committed_at": "2026-06-24T08:54:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 605,
      "latest_release_at": "2026-04-25T22:59:11Z",
      "latest_release_tag": "0.13.0",
      "releases_from_tags": true,
      "days_since_last_push": 2,
      "active_weeks_last_year": 14,
      "days_since_latest_release": 88,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@slowcook-ai/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "tdd",
            "ai",
            "agents",
            "testing",
            "cli",
            "brewing",
            "slowcook"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/cli",
          "is_deprecated": false,
          "latest_version": "0.28.0",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 143,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2151,
          "first_published_at": "2026-04-20T00:48:29.661000Z",
          "latest_published_at": "2026-07-17T23:13:52.180000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@slowcook-ai/core",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "tdd",
            "ai",
            "agents",
            "testing",
            "brewing",
            "slowcook"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/core",
          "is_deprecated": false,
          "latest_version": "0.17.0",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 19,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1279,
          "first_published_at": "2026-04-20T00:46:48.114000Z",
          "latest_published_at": "2026-07-03T18:12:05.223000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 19
        },
        {
          "name": "@slowcook-ai/gates",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "slowcook",
            "gates",
            "a11y",
            "accessibility",
            "contrast",
            "wcag",
            "playwright",
            "tier-2"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/gates",
          "is_deprecated": false,
          "latest_version": "0.11.0",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 243,
          "first_published_at": "2026-04-23T23:25:03.138000Z",
          "latest_published_at": "2026-06-07T15:23:32.136000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 45
        },
        {
          "name": "@slowcook-ai/observe",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "slowcook",
            "observability",
            "debugging",
            "tracing",
            "pino",
            "asynclocalstorage",
            "request-id"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/observe",
          "is_deprecated": false,
          "latest_version": "0.1.1",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 186,
          "first_published_at": "2026-07-09T13:00:52.330000Z",
          "latest_published_at": "2026-07-17T23:13:29.760000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@slowcook-ai/recorder",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "slowcook",
            "recorder",
            "replay",
            "vcr",
            "fixtures",
            "testing",
            "acceptance"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/recorder",
          "is_deprecated": false,
          "latest_version": "0.9.1",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 231,
          "first_published_at": "2026-04-23T23:24:28.633000Z",
          "latest_published_at": "2026-04-23T23:24:28.958000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 90
        },
        {
          "name": "@slowcook-ai/stack-ts",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "tdd",
            "ai",
            "agents",
            "testing",
            "vitest",
            "playwright",
            "slowcook"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/stack-ts",
          "is_deprecated": false,
          "latest_version": "0.9.9",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 20,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 411,
          "first_published_at": "2026-04-20T10:35:02.006000Z",
          "latest_published_at": "2026-05-27T14:29:26.472000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 56
        },
        {
          "name": "@slowcook-ai/forge-github",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "slowcook",
            "github",
            "forge",
            "adapter",
            "tdd",
            "ai",
            "agents"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/forge-github",
          "is_deprecated": false,
          "latest_version": "0.14.0",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 33,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 427,
          "first_published_at": "2026-04-20T11:34:38.343000Z",
          "latest_published_at": "2026-06-09T21:55:35.987000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 43
        },
        {
          "name": "@slowcook-ai/mock-runtime",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "slowcook",
            "mock",
            "ui",
            "scenarios",
            "design-contract",
            "react",
            "next"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@slowcook-ai/mock-runtime",
          "is_deprecated": false,
          "latest_version": "0.3.4",
          "repository_url": "https://github.com/aminazar/slowcook",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 150,
          "first_published_at": "2026-04-26T23:25:11.342000Z",
          "latest_published_at": "2026-06-01T17:18:17.982000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 51
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 49
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cli/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/forge-github/tsconfig.json",
        "packages/gates/tsconfig.json",
        "packages/llm-anthropic/tsconfig.json",
        "packages/mock-runtime/tsconfig.json",
        "packages/observe/tsconfig.json",
        "packages/recorder/tsconfig.json",
        "packages/review-overlay/tsconfig.json",
        "packages/stack-ts/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 149716,
      "source_files_sampled": 401,
      "oversized_source_files": 5,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 14021
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "vitest",
            "direct": false,
            "version": "2.1.9",
            "severity": "critical",
            "ecosystem": "npm",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-5xrq-8626-4rwp"
            ],
            "fixed_version": "4.1.0",
            "advisory_count": 1,
            "oldest_advisory_days": 51
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 2
          },
          {
            "name": "next",
            "direct": false,
            "version": "16.2.9",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 8.2,
            "advisory_ids": [
              "GHSA-4633-3j49-mh5q",
              "GHSA-4c39-4ccg-62r3",
              "GHSA-68g3-v927-f742",
              "GHSA-6gpp-xcg3-4w24",
              "GHSA-89xv-2m56-2m9x",
              "GHSA-955p-x3mx-jcvp",
              "GHSA-m99w-x7hq-7vfj",
              "GHSA-p9j2-gv94-2wf4",
              "GHSA-q8wf-6r8g-63ch"
            ],
            "fixed_version": "16.2.11",
            "advisory_count": 9,
            "oldest_advisory_days": 0
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.34.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-f88m-g3jw-g9cj"
            ],
            "fixed_version": "0.35.0",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "undici",
            "direct": false,
            "version": "7.25.0",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-35p6-xmwp-9g52",
              "GHSA-g8m3-5g58-fq7m",
              "GHSA-hm92-r4w5-c3mj",
              "GHSA-p88m-4jfj-68fv",
              "GHSA-pr7r-676h-xcf6",
              "GHSA-vmh5-mc38-953g",
              "GHSA-vxpw-j846-p89q"
            ],
            "fixed_version": "8.5.0",
            "advisory_count": 7,
            "oldest_advisory_days": 34
          },
          {
            "name": "vite",
            "direct": false,
            "version": "5.4.21",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-4w7w-66w2-5vf9",
              "GHSA-fx2h-pf6j-xcff",
              "GHSA-v6wh-96g9-6wx3"
            ],
            "fixed_version": "8.0.16",
            "advisory_count": 3,
            "oldest_advisory_days": 107
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.21.5",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-67mh-4wv8-2f99"
            ],
            "fixed_version": "0.25.0",
            "advisory_count": 1,
            "oldest_advisory_days": 527
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.4.31",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 6.1,
            "advisory_ids": [
              "GHSA-qx2v-qp2m-jg93"
            ],
            "fixed_version": "8.5.10",
            "advisory_count": 1,
            "oldest_advisory_days": 89
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 5,
          "critical": 1,
          "moderate": 2
        },
        "advisory_count": 24,
        "affected_count": 8,
        "assessed_count": 224,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 15,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@slowcook-ai/core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/stack-ts",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/forge-github",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/llm-anthropic",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/recorder",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/review-overlay",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/gates",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@anthropic-ai/sdk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.106.0"
        },
        {
          "name": "@octokit/rest",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^22.0.1"
        },
        {
          "name": "@playwright/test",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.61.0"
        },
        {
          "name": "ts-morph",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^28.0.0"
        },
        {
          "name": "yaml",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "zod",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@slowcook-ai/core",
          "manifest": "packages/forge-github/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@octokit/rest",
          "manifest": "packages/forge-github/package.json",
          "ecosystem": "npm",
          "version_constraint": "^22.0.1"
        },
        {
          "name": "@slowcook-ai/core",
          "manifest": "packages/llm-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@anthropic-ai/sdk",
          "manifest": "packages/llm-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.106.0"
        },
        {
          "name": "@slowcook-ai/core",
          "manifest": "packages/mock-runtime/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        },
        {
          "name": "@slowcook-ai/core",
          "manifest": "packages/stack-ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:^"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@anthropic-ai/sdk",
            "direct": true,
            "version": "0.106.0",
            "ecosystem": "npm"
          },
          {
            "name": "@anthropic-ai/sdk",
            "direct": true,
            "version": "^0.106.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/rest",
            "direct": true,
            "version": "22.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/rest",
            "direct": true,
            "version": "^22.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": true,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": true,
            "version": "^1.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-morph",
            "direct": true,
            "version": "28.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-morph",
            "direct": true,
            "version": "^28.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": true,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/css-color",
            "direct": false,
            "version": "5.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/dom-selector",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/generational-cache",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/nwsapi",
            "direct": false,
            "version": "2.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bramus/specificity",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/color-helpers",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-calc",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-color-parser",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-parser-algorithms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-syntax-patches-for-csstree",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-tokenizer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "@exodus/bytes",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@img/colour",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-darwin-arm64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-darwin-x64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-darwin-arm64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-darwin-x64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-arm",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-arm64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-ppc64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-riscv64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-s390x",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-x64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linuxmusl-arm64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linuxmusl-x64",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-arm",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-arm64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-ppc64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-riscv64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-s390x",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-x64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linuxmusl-arm64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linuxmusl-x64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-wasm32",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-arm64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-ia32",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-x64",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@next/env",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-darwin-arm64",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-darwin-x64",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-linux-arm64-gnu",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-linux-arm64-musl",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-linux-x64-gnu",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-linux-x64-musl",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-win32-arm64-msvc",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@next/swc-win32-x64-msvc",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/auth-token",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/core",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/endpoint",
            "direct": false,
            "version": "11.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/graphql",
            "direct": false,
            "version": "9.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/openapi-types",
            "direct": false,
            "version": "27.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/plugin-paginate-rest",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/plugin-request-log",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/plugin-rest-endpoint-methods",
            "direct": false,
            "version": "17.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/request",
            "direct": false,
            "version": "10.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/request-error",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@octokit/types",
            "direct": false,
            "version": "16.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm-eabi",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-arm64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-x64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-arm64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-x64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-musleabihf",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-musl",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-musl",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-musl",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-musl",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-s390x-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openbsd-x64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openharmony-arm64",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-arm64-msvc",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-ia32-msvc",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-gnu",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-msvc",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "@stablelib/base64",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@swc/helpers",
            "direct": false,
            "version": "0.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "@ts-morph/common",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^26.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "19.2.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^19.2.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "19.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "^19",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.37",
            "ecosystem": "npm"
          },
          {
            "name": "before-after-hook",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "bidi-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "cac",
            "direct": false,
            "version": "6.7.14",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001799",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "5.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "check-error",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "client-only",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "code-block-writer",
            "direct": false,
            "version": "13.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "css-tree",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "data-urls",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decimal.js",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-eql",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.21.5",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-content-type-parse",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-sha256",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "html-encoding-sniffer",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-potential-custom-element-name",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "29.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "^29.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-to-ts",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-with-bigint",
            "direct": false,
            "version": "3.5.8",
            "ecosystem": "npm"
          },
          {
            "name": "loupe",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "mdn-data",
            "direct": false,
            "version": "2.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "next",
            "direct": false,
            "version": "16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "next",
            "direct": false,
            "version": "^16.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-browserify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "pathval",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "playwright",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "playwright-core",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.4.31",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "^19.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "^19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "^19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.60.2",
            "ecosystem": "npm"
          },
          {
            "name": "rustwright",
            "direct": false,
            "version": "^0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "saxes",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.34.5",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "standardwebhooks",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "3.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "styled-jsx",
            "direct": false,
            "version": "5.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "symbol-tree",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "tinypool",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyspy",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "tldts",
            "direct": false,
            "version": "7.0.30",
            "ecosystem": "npm"
          },
          {
            "name": "tldts-core",
            "direct": false,
            "version": "7.0.30",
            "ecosystem": "npm"
          },
          {
            "name": "tough-cookie",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-algebra",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": false,
            "version": "7.25.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "universal-user-agent",
            "direct": false,
            "version": "7.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "5.4.21",
            "ecosystem": "npm"
          },
          {
            "name": "vite-node",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "2.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "w3c-xmlserializer",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-mimetype",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "16.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "xml-name-validator",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "xmlchars",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 239,
        "direct_count": 12,
        "indirect_count": 227
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 224,
        "open_issues": 45,
        "closed_ratio": 0.25,
        "closed_issues": 15,
        "closed_unmerged_prs": 9
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "aminazar",
          "commits": 575,
          "avatar_url": "https://avatars.githubusercontent.com/u/17534630?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "eval-gate.yml",
        "readme-help-sync.yml",
        "smoke-install.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "20 out of 28 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "24 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "82a5321b6087b93b03522031b0f82a9725f9acaf",
        "ran_at": "2026-07-23T08:57:15Z",
        "aggregate_score": 4.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T08:30:56Z",
      "oldest_open_prs": [
        {
          "number": 275,
          "created_at": "2026-07-06T10:45:06Z",
          "last_comment_at": "2026-07-06T10:45:07Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 276,
          "created_at": "2026-07-06T10:45:25Z",
          "last_comment_at": "2026-07-06T10:45:25Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 277,
          "created_at": "2026-07-06T10:45:56Z",
          "last_comment_at": "2026-07-06T10:45:56Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 291,
          "created_at": "2026-07-13T10:45:28Z",
          "last_comment_at": "2026-07-13T10:45:29Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-07-16T08:42:24Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-04-24T22:49:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2,
          "created_at": "2026-04-24T23:01:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3,
          "created_at": "2026-04-24T23:02:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4,
          "created_at": "2026-04-24T23:10:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2026-04-24T23:20:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 6,
          "created_at": "2026-04-25T18:25:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 7,
          "created_at": "2026-04-25T18:26:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 8,
          "created_at": "2026-04-25T20:29:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 9,
          "created_at": "2026-04-25T20:48:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 10,
          "created_at": "2026-04-26T09:11:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 20,
          "created_at": "2026-05-12T19:19:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 21,
          "created_at": "2026-05-12T20:42:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 22,
          "created_at": "2026-05-12T20:42:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 34,
          "created_at": "2026-05-13T12:42:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 35,
          "created_at": "2026-05-13T12:47:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 44,
          "created_at": "2026-05-13T18:10:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 45,
          "created_at": "2026-05-13T18:10:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 46,
          "created_at": "2026-05-13T18:10:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 47,
          "created_at": "2026-05-13T18:10:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 54,
          "created_at": "2026-05-14T13:44:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/aminazar/slowcook",
    "host": "github.com",
    "name": "slowcook",
    "owner": "aminazar"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 56,
      "inputs": {
        "security": 56,
        "vitality": 73,
        "community": 40,
        "governance": 47,
        "engineering": 63
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 73,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 605,
              "human_commit_share": 0.97,
              "days_since_last_push": 2,
              "active_weeks_last_year": 14
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "14/52 weeks with commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 14
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "605 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 605
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "0.13.0",
              "releases_from_tags": true,
              "days_since_latest_release": 88,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 88 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 88
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 40,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "@slowcook-ai/cli",
                "@slowcook-ai/core",
                "@slowcook-ai/gates",
                "@slowcook-ai/observe",
                "@slowcook-ai/recorder",
                "@slowcook-ai/stack-ts",
                "@slowcook-ai/forge-github",
                "@slowcook-ai/mock-runtime"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 5078
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,078 downloads/month across npm",
                "points": 49.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5078,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 47,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "merged_prs": 224,
              "open_issues": 45,
              "closed_issues": 15,
              "issue_closed_ratio": 0.25,
              "closed_unmerged_prs": 9
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "25% of issues closed",
                "points": 11.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 25
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "224/233 decided PRs merged",
                "points": 36.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 224,
                      "decided": 233
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "followers": 5,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "aminazar",
              "public_repos": 5,
              "account_age_days": 3797
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of aminazar",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "aminazar"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~10 yr old",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 10
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@slowcook-ai/cli",
                "@slowcook-ai/core",
                "@slowcook-ai/gates",
                "@slowcook-ai/observe",
                "@slowcook-ai/recorder",
                "@slowcook-ai/stack-ts",
                "@slowcook-ai/forge-github",
                "@slowcook-ai/mock-runtime"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "143 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 143
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 63,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "20 out of 28 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 45,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "20 out of 28 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "24 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 224 resolved dependencies against OSV; 15 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 224
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 15
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 24,
              "affected_packages": 8,
              "assessed_packages": 224,
              "unassessed_packages": 15,
              "affected_by_severity": "critical 1, high 5, moderate 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 224,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.969,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 14021
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "94 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 94,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/cli/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/forge-github/tsconfig.json",
                "packages/gates/tsconfig.json",
                "packages/llm-anthropic/tsconfig.json",
                "packages/mock-runtime/tsconfig.json",
                "packages/observe/tsconfig.json",
                "packages/recorder/tsconfig.json",
                "packages/review-overlay/tsconfig.json",
                "packages/stack-ts/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.56,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/forge-github/tsconfig.json, packages/gates/tsconfig.json, packages/llm-anthropic/tsconfig.json, packages/mock-runtime/tsconfig.json, packages/observe/tsconfig.json, packages/recorder/tsconfig.json, packages/review-overlay/tsconfig.json, packages/stack-ts/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/forge-github/tsconfig.json, packages/gates/tsconfig.json, packages/llm-anthropic/tsconfig.json, packages/mock-runtime/tsconfig.json, packages/observe/tsconfig.json, packages/recorder/tsconfig.json, packages/review-overlay/tsconfig.json, packages/stack-ts/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "56 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 56,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 149716,
              "source_files_sampled": 401,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/401 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 401,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index npm:@slowcook-ai/cli@0.28.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T08:57:30.711969Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/aminazar/slowcook.svg",
  "full_name": "aminazar/slowcook",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.